Role Overview
Join a security team focused on building resilient, secure cloud systems at scale. As a Cloud Security Engineer, you'll work closely with infrastructure and development teams to integrate security into the core of cloud operations. Your efforts will ensure that security is embedded by design across infrastructure, pipelines, and cloud services.
Key Responsibilities
- Collaborate with engineering teams to integrate security practices into development and deployment workflows
- Develop secure Terraform modules with built-in controls for encryption, logging, and threat detection
- Implement and manage cloud-native detection using AWS GuardDuty, Security Hub, and custom rules to identify threats like credential misuse and unauthorized activity
- Support compliance with SOC 2 Type II and ISO 27001 through automated evidence collection and control monitoring
- Perform regular audits of cloud resources using AWS Config and Open Policy Agent, correcting misconfigurations against CIS Benchmarks and internal policies
- Strengthen CI/CD and software supply chain security with artifact signing, secret detection, and dependency tracking
- Enforce zero trust principles through network segmentation, identity verification, and least-privilege access
- Participate in on-call rotations to respond to security incidents and ensure timely resolution
Qualifications
Required
- 8+ years of experience in cloud infrastructure, platform engineering, or related fields
- Proven experience scaling secure infrastructure in fast-growing technology environments
- Familiarity with cloud-native architectures, microservices, and distributed systems
- Hands-on experience securing CI/CD pipelines, automation tools, and deployment systems
- Strong coding skills in Python, Go, or similar languages
Preferred
- Background in AI/ML infrastructure or multi-cloud environments
Technology Environment
Terraform, AWS GuardDuty, AWS Security Hub, AWS Config, Open Policy Agent, Python, Go, SOC 2 Type II, ISO 27001, CI/CD pipelines, artifact signing, secret scanning, dependency monitoring, zero trust frameworks, cloud-native detection, CIS Benchmarks


