
Staff Cloud Security Engineer
Posted 3 hours ago

Posted 3 hours ago
This is a fully remote position, open to applicants in Maryland.
• Take ownership of the CrowdStrike Falcon configuration, ensuring that policies are properly scoped, tuned, and capable of generating actionable alerts.
• Collaborate with the MDR team to establish alert routing, triage thresholds, and escalation logic, ensuring that the appropriate signals reach the correct team.
• Oversee cloud environments (primarily AWS) to monitor for security posture drift, including misconfigured IAM roles, overly permissive security groups, exposed storage, and non-compliant resource configurations.
• Secure Kubernetes clusters and containerized workloads by managing Network Policies, RBAC, Admission Controllers, and runtime detection for anomalous container behavior.
• Create and enforce cloud security policies and standards for AWS infrastructure, ensuring that secure and scalable deployments align with the organization’s risk posture.
• Assess and lead the implementation of additional detection tools, including cloud SIEM platforms, while designing detection rules and alerting pipelines.
• Manage infrastructure as code (IaC) security using Terraform or OpenTofu, ensuring that IaC definitions comply with security standards prior to deployment.
• Automate security posture checks and detection workflows utilizing Python and shell scripting.
• Remain up-to-date with the evolving landscape of cloud threats and translate emerging threats into detection coverage or posture enhancements.
• A minimum of 8 years of experience in cloud security, security engineering, or a related discipline within infrastructure security.
• Practical experience with a cloud security posture management (CSPM) platform such as CrowdStrike, Wiz, Prisma Cloud, Orca, or equivalent; prior experience with CrowdStrike is beneficial but not mandatory.
• Extensive knowledge of AWS security architecture, including IAM/SCP policy design, VPC networking, security groups, CloudTrail, and cloud-native security controls. Experience with GCP or Azure may be considered in place of AWS for strong candidates willing to transition into AWS.
• Proficient with infrastructure as code (IaC) tools such as Terraform, OpenTofu, or CloudFormation, with a solid understanding of how to enforce security standards within IaC workflows.
• Strong skills in Python and shell scripting for automating security processes, developing detection rules, and integrating tools.
• Must be a US Citizen or legal permanent resident (Xometry manages ITAR-controlled data).
• 401(k) matching
• Medical, dental, and vision insurance
• Life and disability insurance
• Generous paid time off, including vacation, sick leave, floating and fixed holidays, maternity, and bonding leave
• Employee Assistance Program (EAP) and other wellbeing resources
Carrier
Polymarket
Cloud at Work
PROSTAFF Schweiz
Get handpicked remote jobs straight to your inbox weekly.