Cloud Security Engineer
Job description
About the role
You will design, implement, and maintain a robust security posture across our multi-cloud environment on Google Cloud Platform and Amazon Web Services. This position owns the security of our cloud infrastructure, focusing on automation of guardrails within delivery pipelines and enabling safe expansion into enterprise AI services. You will treat security as code, emphasizing detection and prevention over static checklists. In this role, you will directly shape how our fast-moving organization secures both traditional cloud workloads and emerging generative AI systems. You are expected to take hands-on responsibility for securing containerized workloads, managing key management strategies, and driving incident response. Your work will ensure that security controls are versioned, peer-reviewed, and consistently enforced across all environments.
Key facts
What you'll do
Design, implement, and maintain security controls across GCP and AWS, including IAM, network segmentation, encryption, logging, and key management.
Operate and tune CrowdStrike Falcon Cloud Security (CSPM) to continuously monitor cloud posture, triage misconfigurations, and drive remediation across accounts and projects.
Run and extend Prowler assessments to benchmark environments against CIS, NIST, and internal standards, integrating findings into automated reporting and ticketing workflows.
Build and maintain security infrastructure as code using Terraform, ensuring controls are versioned, peer-reviewed, and consistently applied across environments.
Embed security into CI/CD pipelines through GitHub (Actions, branch protection, secret scanning, dependency review) so issues are caught before they reach production.
Secure containerized workloads running on Amazon EKS, covering cluster hardening, RBAC, network policies, image scanning, and runtime protection.
Define and enforce security guardrails for enterprise AI adoption, including data governance, access controls, prompt/output safeguards, and monitoring for Amazon Bedrock and Google Gemini Enterprise.
Develop and design agentic security detection and response capabilities, with a focus on scaling existing processes leveraging AI.
Investigate and respond to cloud security incidents, perform root-cause analysis, and lead improvements that prevent recurrence.
Develop automation and tooling to reduce manual effort, improve detection coverage, and provide clear, actionable metrics to leadership.
Contribute to the creation of security policies and standards that align with industry best practices and organizational objectives.
Collaborate closely with development and operations teams to ensure security requirements are integrated into architecture decisions.
Monitor threat landscapes and emerging risks to cloud environments, adjusting controls and recommendations accordingly.
Provide technical leadership and mentorship to less experienced team members on security topics and workflows.
Requirements
You must possess a minimum of 5 years of experience in cloud security, security engineering, or a closely related role.
You must have hands-on experience securing production environments on both Google Cloud Platform and Amazon Web Services.
You must demonstrate a strong working knowledge of infrastructure as code principles, specifically with Terraform.
You must be proficient with GitHub-based workflows and integrating security practices into CI/CD pipelines.
You must have practical experience with cloud security posture management tools such as CrowdStrike Falcon CSPM and Prowler.
You must have practical experience securing Kubernetes clusters, with a focus on Amazon EKS.
You must possess a solid understanding of cloud identity and access management, networking, encryption, and logging fundamentals.
You must have scripting ability in Python, Go, or a similar language to develop automation solutions.
You must have hands-on experience with SIEM platforms for log aggregation, detection, and security monitoring.
You must be able to work effectively in a fully remote environment, managing your schedule and deliverables independently.
You must be comfortable working with command-line interfaces and infrastructure management tools on a regular basis.
You must have a strong attention to detail when reviewing configurations and security policies.
You must be able to read and interpret security findings and translate them into actionable remediation steps.
You must be willing to adhere to the organization's security policies and procedures consistently.
Nice to have
Experience securing or governing enterprise AI or LLM platforms such as Amazon Bedrock or Google Gemini Enterprise.
Experience developing Agentic Security capabilities and workflows.
Familiarity with security frameworks such as CIS Benchmarks, NIST, SOC 2, or ISO 27001.
Background in detection engineering or threat modeling practices.
Relevant certifications such as GCP Professional Cloud Security Engineer, AWS Security Specialty, Certified Kubernetes Security Specialist, or CISSP.
Practical notes
This role operates in a fully remote environment.
Success in this role requires consistent participation in asynchronous communication and scheduled collaboration.
Travel is not required for this position.
No visa sponsorship is provided for this role at this time.