Principal Cloud Security Engineer
About the role
About LastPass
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, LastPass blends strong security with everyday simplicity.
About the role
LastPass is looking for a Principal Cloud Security Engineer. You will partner with DevOps and CI/CD engineers and our Architects team to ensure security best practices are embedded across our cloud infrastructure. We are looking for an experienced security engineering leader with an ability to scale security and make the right trade-off decisions that enable us to offer secure, innovative solutions to customers.
About the team
The Cloud Security team at LastPass is a collaborative group of talented cloud security engineers working in close partnership with our engineering, platform, and trust & security teams. We are on a mission to safeguard the privacy and security of our company and users' data, embedded directly in the heart of our product development.
Who will you work with?
You will work closely with DevOps and CI/CD engineers, Cloud Architects, and cross-functional engineering teams across LastPass. You will also collaborate with our Trust & Security and Platform teams, acting as a key embedded security partner throughout the product and infrastructure development process to drive secure-by-design outcomes at every stage.
What are some of the exciting challenges you will be working on?
- Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization
- Use your knowledge of security architecture to help engineers build and securely operate products and services from the ground up
- Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements
- Perform proactive research to identify new threats and attack vectors
- Partner with engineering teams to embed shift-left security practices throughout the software development lifecycle
- Implement and manage cloud and Kubernetes security posture management tooling to continuously monitor and reduce risk across containerized workloads
What does it take to work at LastPass?
- Proven experience working with AWS and AWS security services in a secure production environment, including IAM, Config, KMS, Secrets Manager, CloudWatch, CloudTrail, and GuardDuty
- Proven experience working closely with engineering teams and supporting them on their path to shifting security left
- Background with infrastructure as code (AWS CDK, CloudFormation, or Terraform), version control and CI tools such as GitLab and GitLab CI