Jobgether
Staff Cloud Security Engineer
engineeringfull-timeUS
SALARY
$168k – $252k/yr
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more
About the role
Accountabilities
- Design and integrate security controls directly into CI/CD pipelines using platforms such as GitHub, GitLab, Jenkins, or Azure DevOps.
- Evaluate, configure, and manage Infrastructure as Code security scanning tools to identify meaningful risks and reduce false positives.
- Build automated developer feedback and remediation workflows that encourage secure-by-default development practices.
- Develop automation scripts using Python, Bash, or PowerShell to streamline security processes and improve operational efficiency.
- Establish and maintain IAM controls across cloud environments, enforcing least-privilege access and secure identity practices.
- Define standards and lifecycle controls for non-human identities, APIs, application credentials, and cloud secrets.
- Develop secure infrastructure baselines, vulnerability management processes, and hardening standards across AWS, Azure, and/or GCP.
- Use Terraform, CloudFormation, Bicep, or comparable IaC technologies to ensure infrastructure is secure, repeatable, and auditable.
- Lead or contribute to high-impact infrastructure security initiatives, including multi-cloud network isolation, secure multi-tenant architectures, and continuous remediation of misconfigurations.
- Advise engineering teams on secure cloud-native architectures spanning microservices, serverless applications, containers, and PaaS workloads.
- Strengthen container and Kubernetes security through runtime controls, supply-chain protections, and configuration assessments.
- Develop security approaches for AI/ML systems, addressing adversarial threats, unauthorized access, model protection, and data pipeline security.
- Protect sensitive cloud and AI data through encryption, anonymization, secure storage, tokenization, and appropriate data protection controls.
- Partner with Security Operations to improve cloud telemetry, logging, observability, and detection capabilities.
- Onboard relevant cloud log sources and develop detection rules for cloud-based threats using SIEM, CSPM, CWPP, and related technologies.
- Support the triage, investigation, and forensic analysis of cloud and application security incidents, collaborating on containment and remediation.
- Translate complex security requirements into practical guidance for both technical and non-technical stakeholders.
- 7–10+ years of hands-on experience in cloud security, application security, DevSecOps, or closely related engineering disciplines.
- Deep practical expertise securing AWS and/or Azure environments, including the design and maintenance of controls for multi-cloud applications.
- Strong knowledge of cloud identity and access management, infrastructure security, vulnerability management, network security, data protection, and security monitoring.
- Proficiency with Python, Bash, PowerShell, or similar scripting languages for security automation.
- Strong understanding of Docker, Kubernetes, container security, and cloud-native application architectures.
- Hands-on experience securing Infrastructure as Code, particularly with Terraform, ARM, CloudFormation, Bicep, or comparable technologies.
- Experience integrating security practices into CI/CD pipelines and applying DevSecOps principles across software development workflows.
- Familiarity with SIEM, CSPM, CWPP, cloud logging, telemetry, detection engineering, and incident response practices.
- Knowledge of AI/ML security considerations, including protection of models, data pipelines, identities, and workloads, is highly valuable.
- Relevant industry certifications such as CCSP, CISSP, AWS Security Specialty, Azure Security Engineer, GCSA, or OSCP are strongly preferred.
- A proactive builder mindset, with a demonstrated ability to identify security gaps, improve processes, and develop scalable solutions.
- Strong cross-functional collaboration and communication skills, with the ability to explain sophisticated security concepts clearly to varied audiences.
- Comfortable operating in a rapidly changing environment and continuously adapting to emerging cloud, application, and AI security threats.
- Competitive base salary of $168,200–$252,200 for eligible US locations, with a higher range of $179,900–$269,900 applicable to CA, CT, DC, MD, MA, NJ, NY, VA, and WA.
- Annual bonus and equity opportunities as part of the total compensation package.
- Company-sponsored medical, dental, and vision coverage, including fully employer-paid options and substantial dependent coverage.
- FSA and HSA options.
- 401(k) match.
- Telehealth benefits, including One Medical membership options.
- Flexible paid time off and support for autonomous work.
- Learning and development opportunities, comprehensive onboarding, leadership training, and professional growth programs.
- Recognition programs, including peer-nominated awards and rewards.
- Parental leave and family support programs.
- Up to $20,000 in fertility services, including IUI and IVF, plus surrogacy and adoption reimbursement.
- Maternity support through Maven Maternity and free breast milk shipping through Maven Milk.
- Pet insurance, legal advisory services, financial planning tools, and additional wellness and family benefits.
- Fully remote work environment with flexibility and opportunities to work on cutting-edge cloud and AI security challenges.
Requirements
Benefits
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply