Cloud Security Engineer
Core
Design and operate cloud security posture, threat detection, and security infrastructure for multi-tenant, regulated (GovCloud/ITAR) environments.
Role type
Senior Cloud Security Engineer
Builds
AWS commercial and GovCloud security controls, automated threat detection pipelines, and compliance-enforced security infrastructure
Domain
Cloud Security, Cybersecurity, Regulated Environments
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
AWS security (IAM, KMS, VPC, GuardDuty, Security Hub, CloudTrail, Config, WAF), threat detection and hunting, detection-as-code, SIEM administration, CSPM, vulnerability management, CI/CD security (GitHub Actions, SAST/DAST/SCA), container/Kubernetes security, Terraform, adversarial mindset
Preferred skills
Threat intelligence operationalization, compliance frameworks (SOC 2, ITAR, GovCloud), incident response, observability tooling (Datadog, PostHog, Sentry), event-driven systems (NATS, Redis, Kafka), PostgreSQL, Kubernetes operations
Technologies
AWS, Terraform, Docker, GitHub Actions, Kubernetes, SIEM, CSPM, WAF, GuardDuty, Security Hub, CloudTrail, Config, Inspector, NATS, Redis, Kafka, PostgreSQL
Responsibilities
Design and operate IAM, encryption, and network security models across AWS commercial and GovCloud; proactively hunt for anomalies in cloud, application, and identity telemetry; integrate and contextualize threat intelligence feeds; architect centralized logging, SIEM, and security monitoring; implement and administer security tooling (CSPM, vulnerability management, secrets management); embed security into CI/CD pipelines and secure containerized workloads; build reproducible security infrastructure using Terraform and policy-as-code; partner on compliance controls for SOC 2, ITAR, and GovCloud; support incident response and post-incident hardening
Seniority
Senior, hands-on IC