Senior Cloud Security Engineer
Job Description
We’re partnering with a rapidly growing, cloud-first SaaS company looking for a Senior Cloud Security Engineer II to join its Security Engineering organization.
\n
\n
This is a highly technical individual contributor role for someone who has owned cloud security in production and wants to help set the technical direction for a large-scale cloud environment.
\n
This is not a DevOps role with some security responsibilities. We’re looking for a true cloud security engineer with deep experience across AWS, Kubernetes, detection engineering, incident response, IAM, threat modeling, and security automation.
\n
\n
What You’ll Own
\n
You’ll help define cloud security standards, guardrails, and reference architectures used across Infrastructure, SRE, and Product Engineering teams.
\n
Key responsibilities include:
\n
- \n
- Lead cloud security architecture and threat modeling initiatives
- Design secure-by-default patterns across AWS and GCP environments
- Own cloud IAM strategy, RBAC, least privilege, and control-plane security
- Build and improve high-signal cloud security detections
- Lead complex cloud incident response and forensic investigations
- Turn incident findings into repeatable detections, controls, and IR playbooks
- Own and optimize security tooling across EDR, CSPM, vulnerability management, and native cloud security platforms
- Drive vulnerability identification, prioritization, and remediation
- Own security across self-managed Kubernetes environments
- Secure Kubernetes control planes, nodes, workloads, admission controls, and runtime environments
- Establish security standards around Terraform, Infrastructure-as-Code, CI/CD pipelines, containers, and base images
- Partner closely with Infrastructure, SRE, and engineering teams
- Mentor other engineers and serve as a senior technical authority for cloud security
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
What We’re Looking For
\n
The strongest candidates will have several years of hands-on ownership of production cloud security environments.
\n
\n
Must-have experience:
\n
- \n
- Deep, hands-on AWS security
- Working knowledge of GCP security
- Strong Kubernetes security experience, ideally with self-managed environments
- Cloud incident response and investigations
- Detection engineering and SIEM
- Cloud IAM, RBAC, and least-privilege architecture
- Threat modeling and secure architecture
- Infrastructure-as-Code security
- Terraform
- Python or similar scripting/programming experience
- Vulnerability management
- Container and CI/CD security
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
Experience with technologies such as CrowdStrike, Tenable, Kubernetes, Terraform, AWS, GCP, and SIEM platforms is highly relevant.
\n
The Profile
\n
