Senior Cloud Security Engineer
Job description
About the role
Yext is actively seeking a security professional to join the Cyber Security Office with the mission of strengthening our product and infrastructure protection against evolving threats. In this role, you will own the design and implementation of automated security controls that safeguard our global agentic marketing platform and ensure operational resilience. You will manage cloud security tools across multiple environments, driving consistency and efficiency in our security posture. A core part of your responsibility will be leading incident response efforts, providing technical guidance, and acting as a subject matter expert during critical situations. You will partner closely with engineering and product teams to embed security into the development lifecycle from the earliest stages. The position requires a proactive mindset focused on identifying risks before they can be exploited in production systems. You will be instrumental in evolving our security practices to align with industry standards and business objectives. This is an opportunity to shape the security culture and tooling for a growing technology company.
Key facts
What you'll do
- Develop and execute automated solutions that close infrastructure gaps and elevate cloud security maturity across platforms.
- Design, implement, and maintain security controls for AWS and GCP environments using infrastructure as code practices with Terraform.
- Establish and enforce security baselines for Docker and Kubernetes environments to ensure hardened configurations and runtime protection.
- Integrate automated scanning tools such as SAST, DAST, and secret detection directly into CI/CD pipelines to shift security left.
- Operate and optimize the cloud vulnerability scanning program, tracking remediation progress and coordinating efforts across engineering teams.
- Perform threat modeling and security architecture reviews for cloud-native applications to identify potential attack vectors and design mitigations.
- Author and maintain security policies, ensuring that technical controls are aligned with SOC2 and ISO 27001 compliance requirements.
- Collaborate with cross-functional stakeholders to translate business requirements into secure technical implementations and controls.
- Investigate security alerts, incidents, and anomalies, applying forensic techniques to determine root cause and impact scope.
- Provide technical leadership during incident response, guiding engineering teams through containment, eradication, and recovery activities.
- Monitor security advisories and threat intelligence to proactively update defenses and address emerging risks to the platform.
- Partner with DevOps teams to promote secure deployment patterns and infrastructure configurations that reduce risk exposure.
- Support the continuous improvement of security tooling, evaluating new technologies and integrating them where appropriate.
- Contribute to the development of security standards, best practices, and documentation that support long-term scalability.
Requirements
- Bring a minimum of 6 years of professional experience in Product Security or Cloud Security Engineering roles.
- Demonstrate hands-on experience securing infrastructure and workloads in both AWS and GCP cloud environments.
- Show proficiency with Infrastructure as Code tools such as Terraform, CloudFormation, or Pulumi for deploying and managing security controls.
- Have practical experience with Kubernetes security, including the implementation of network policies and image scanning workflows.
- Exhibit strong scripting abilities in languages such as Python, Go, PowerShell, or Bash to automate security tasks and investigations.
- Possess solid knowledge of security frameworks and standards including NIST, ISO 27001, or CIS benchmarks and how to apply them.
- Communicate effectively with engineering and product teams to align on priorities and drive security initiatives forward.
- Understand the fundamentals of identity and access management, encryption, and network security in cloud environments.
- Approach problem-solving with attention to detail and a structured methodology for identifying and mitigating risks.
- Willingness to learn and adapt to new technologies, threat landscapes, and evolving business requirements.
Nice to have
- Hands-on experience with SIEM platforms and centralized logging for monitoring, detection, and response activities.
- Familiarity with cloud DFIR methodologies and the application of the MITRE ATT&CK framework in incident analysis.
- Possession of industry certifications such as CCSP, AWS Certified Security
- Specialty, or Google Professional Cloud Security Engineer.
Practical notes
Yext provides reasonable accommodations for individuals with disabilities during the application and interview process to ensure equal opportunity. All official company communication originates from @yext.com email addresses, and candidates are advised to verify the source of any correspondence claiming to come from Yext. The role is based in Hyderabad, India, and requires the ability to work full-time hours as determined by business needs. There are no specific travel requirements or visa sponsorship details indicated in the current listing. This position is full-time and is part of the Product Security team under the direct management of the Manager of Product Security.