
Senior Engineer II, Cloud Security
Job description
About the role
Lila is hiring a Senior Engineer II, Cloud Security to strengthen cloud and SaaS security across our infrastructure, platforms, and AI-enabled systems. This role owns hands-on security work across cloud posture management, detection and response, container and workload security, identity and privileged access, and security automation. This position sits within IT & Security and partners closely with infrastructure, platform, data, DevSecOps, and AI teams. The person in this role will turn cloud and SaaS security findings into prioritized remediation work, build guardrails that reduce risk before deployment, and improve Lila's ability to detect and respond to threats. The ideal candidate brings deep cloud security experience, strong operational judgment, and the ability to translate technical risk into clear action across engineering and security stakeholders. You will be responsible for owning the security of cloud environments end to end, ensuring that security controls are implemented efficiently and effectively.
Key facts
What you'll do
Own cloud and SaaS security posture management across AWS, IaaS/PaaS, and core SaaS platforms.
Configure, operate, and tune CSPM, CNAPP, and SSPM tooling to surface and prioritize risk.
Partner with infrastructure and platform teams to drive remediation of cloud, SaaS, and workload findings.
Build and tune high-fidelity detections across SIEM, EDR, CSPM, and related security systems.
Lead incident response triage, containment, recovery, and post-incident review for cloud security events.
Strengthen cloud-native workload and container security across AWS, Kubernetes, hardened AMIs, and network controls.
Design policy-as-code and guardrails that prevent insecure deployments without slowing developer velocity.
Partner with AI, data, and platform teams to mature security controls for MLOps pipelines and AI-enabled platforms.
Perform proactive threat hunting and security assessments to identify risks before they are exploited.
Maintain and evolve security playbooks, runbooks, and standard operating procedures for cloud environments.
Collaborate with external auditors and assessors to ensure compliance with security frameworks and standards.
Contribute to the development and enforcement of security architecture principles across the organization.
Support the design and implementation of secure cloud foundations and landing zones.
Engage with the broader security community to stay current with cloud security best practices and emerging threats.
Requirements
Extensive hands-on experience in information security, with deep cloud and SaaS security ownership.
Strong AWS security knowledge, including IAM, SCPs, VPC/networking, KMS, CloudTrail, GuardDuty, Security Hub, and Config.
Hands-on experience with CSPM or CNAPP tooling such as Wiz or comparable platforms.
Experience operating detection and response workflows across SIEM, EDR, CSPM, or related security tooling.
Practical incident response experience, including triage, containment, recovery, and post-incident review.
Strong understanding of workload, container, and Kubernetes security.
Proficiency with scripting and automation using Python, PowerShell, Bash, or similar tools.
Experience securing infrastructure-as-code and CI/CD workflows using Terraform, CloudFormation, ARM, OPA, Sentinel, or native cloud policies.
Strong grasp of IAM, identity federation, least-privilege access, SaaS permission models, and privileged access management practices.
Ability to translate technical findings into business risk and partner cross-functionally with cloud, DevOps, AppSec, and platform teams.
Bachelor's degree in a relevant technical field or equivalent practical experience.
Minimum of eight years of professional experience in information security or a related field.
At least five years of hands-on cloud security experience on AWS or similar public cloud platforms.
Demonstrated ability to work independently and manage multiple priorities in a fast-paced environment.
Excellent written and verbal communication skills for collaborating with technical and non-technical stakeholders.
Nice to have
Deep experience securing MLOps pipelines, AI-enabled platforms, or AI Security Posture Management practices.
Experience with Azure-native security services, including Defender for Cloud.
Depth in CWPP, EDR/XDR, SOAR, or DSPM tooling.
Experience supporting SOC 2, ISO 27001, HIPAA, FedRAMP, PCI-DSS, or similar compliance programs.
Certifications such as CISSP, CCSP, AWS Security, Azure Security, GCIH, GCFA, GCDA, or OSCP.
Practical notes
This is a full-time position based in Cambridge, Massachusetts, USA. Travel may be required as part of the role. Employment eligibility requirements apply. Visas may be sponsored for qualified candidates. The position reports to the IT & Security organization and requires collaboration across multiple teams.