Remote job
Cloud Security Engineer
Job details
About this role
Role overview
A senior-level Cloud Security Engineer is needed to harden and defend a cloud-native platform built primarily on AWS and Kubernetes. The role partners closely with infrastructure and product engineering teams to set security strategy, embed protections into the software delivery lifecycle, and lead response to incidents affecting production environments. The scope spans architecture, implementation, threat modeling, compliance enablement, and mentoring across the engineering organization.
Responsibilities
- Architect, deploy, and operate security controls across AWS accounts and Kubernetes clusters, including isolation and sandboxing strategies for a hosted runtime environment - Build and maintain infrastructure-as-code with Terraform, enforcing security standards through code, review, and policy-as-code - Conduct threat modeling, security assessments, and audits of AWS infrastructure and container deployments - Embed DevSecOps practices into CI/CD pipelines in partnership with development and operations teams - Monitor, triage, and lead response to cloud security incidents, including root-cause analysis and remediation planning - Advise on compliance initiatives spanning frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS - Mentor engineers and advocate for secure-by-default patterns across the organization
Requirements
- 5+ years of hands-on cloud security engineering experience with deep AWS expertise - Strong Kubernetes security background, including cluster hardening, RBAC, network policies, and container vulnerability management - Expert-level proficiency with Terraform for infrastructure-as-code - Working familiarity with AWS-native security services such as IAM, GuardDuty, Security Hub, CloudTrail, and WAF - Exposure to CNAPP platforms and modern cloud-focused SIEM tooling - Solid grasp of secure SDLC, CI/CD security, and DevSecOps methodologies - Strong communication, problem-solving, and cross-functional leadership skills
Nice to have
- AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), or Terraform Associate credentials - Offensive-security or SANS-style certifications
Benefits and work setup
- Market-based compensation with equity participation - Comprehensive health benefits and flexible paid time off - Posted salary range of $198,750 – $295,000, with final placement influenced by experience, demonstrated skills, and interview performance