Cloud Security Engineer
The job description
Tech stack. AWS (GuardDuty, Security Hub, IAM, KMS), Azure or GCP equivalents, Wiz or Prisma Cloud CSPM, Terraform, Docker and Kubernetes, Python, cloud audit log analysis
About the role
You will join the cloud platform security team of a SaaS company running hundreds of cloud accounts, where your mission is to make the secure path the easy path for every product team. The team embeds guardrails directly into the platform so engineers ship safely by default instead of bolting security on as an afterthought. You will build preventive controls, review high-risk designs, and partner with service owners to remediate findings quickly. This role matters because misconfigurations, not sophisticated zero-days, cause most cloud breaches, and you are the person who eliminates them at the source rather than chasing them after deployment.
What you will achieve
- Cut critical CSPM misconfiguration findings 80 percent in your first year through automated remediation and preventive controls that stop new issues at creation.
- Ship secure Terraform modules adopted by 90 percent of service teams for IAM roles, logging configuration, and encryption defaults.
- Build container image scanning into every deployment pipeline, blocking images with critical CVEs before they can reach production clusters.
- Reduce excessive IAM permissions by 50 percent through structured access reviews, permission right-sizing, and enforced least-privilege policies.
- Deliver a cloud security baseline that every new account inherits automatically at creation, backed by continuous drift detection and alerting.
What you will bring
Must-haves
- 2 to 5 years in cloud engineering, DevOps, or security roles with substantial hands-on AWS or Azure experience.
- Strong IAM fundamentals: roles, policies, permission boundaries, and identity federation patterns in real environments.
- Infrastructure as code experience with Terraform or CloudFormation used in production, not just tutorials.
- Understanding of container and Kubernetes security basics, including image provenance and runtime controls.
- Ability to read and write Python for automation, custom checks, and security tooling.
- Comfort partnering directly with product engineers to fix findings together rather than filing tickets into a queue.
- Working knowledge of cloud audit logging and how to investigate suspicious activity within it.
Nice-to-haves
- AWS Security Specialty or Azure Security Engineer Associate certification.
- Experience with CSPM tools such as Wiz, Prisma Cloud, or Orca.
- Familiarity with Kubernetes admission controllers or policy as code using OPA.
- Exposure to cloud incident response scenarios and forensic log analysis.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta