Senior Cloud Security Engineer
A cybersecurity company is seeking a Senior Cloud Security Engineer to design and implement secure cloud platforms across Azure and AWS. This engineering role focuses on preventive controls, Kubernetes security, network security, and automation, partnering with platform teams to embed security by default.
Responsibilities
- Own and evolve Cloud Security Posture Management (CSPM) capabilities, including policies, guardrails, and automated remediation.
- Engineer and maintain cloud network security controls, including network segmentation, cloud-native firewalls, security groups, Application Gateway/WAF configurations, and secure ingress/egress patterns.
- Define and enforce security best practices for Kubernetes environments (AKS/EKS), including RBAC, network policies, workload isolation, and cluster hardening.
- Partner with engineering teams on architecture reviews for new services, platforms, and major changes, ensuring secure, compliant, and practical solutions.
- Engineer and maintain identity and access security controls for cloud and production environments, including least privilege, workload identity, service principals, and conditional access.
- Apply a security lens to FinOps, defining guardrails that balance cost optimization with security and compliance.
- Develop tooling, automation, and self-service workflows to reduce manual effort and improve consistency across security programs.
- Communicate complex security risks and technical recommendations clearly to engineering teams, leadership, and cross-functional stakeholders.
- Mentor junior engineers and contribute to raising the overall security maturity of the organization.
Requirements
- 6+ years of experience in cloud security, security engineering, or cloud platform engineering roles.
- Deep hands-on security experience in Azure or AWS; experience across both is strongly preferred.
- Hands-on experience securing production AKS/EKS environments, including RBAC, network policies, workload identity, admission controls, image/runtime controls, and cluster hardening.
- Proven experience with cloud network security, including firewalls, WAFs, network segmentation, and secure connectivity patterns.
- Strong understanding of cloud security architecture, including shared responsibility models, secure service design, and defense-in-depth.
- Experience with preventative security controls, including CSPM, policy enforcement, and secure cloud baselines.
- Cloud automation experience using Infrastructure as Code tools such as Terraform, Bicep, or CloudFormation, plus scripting with Python, PowerShell, Bash, or similar languages.
- Ability to operate independently, own complex problem spaces, and deliver practical, scalable solutions.
- Strong communication skills and comfort providing architecture-level guidance to engineering teams.
- Experience working in regulated environments.
Nice to have
- Experience contributing to or supporting compliance programs such as FedRAMP, SOC 2, ISO 27001, or NIST frameworks.
- Familiarity with CI/CD pipelines and DevSecOps practices.
- Experience with identity and access management in cloud environments (RBAC, workload identity, service principals).