Staff Cloud Security Engineer
Core
Trusted advisor for customers facing mass-deletion, ransom, or full-tenant takeover scenarios, validating cloud exposures and reconstructing attack paths.
Role type
Staff Cloud Security Engineer (Customer-facing)
Builds
Customer compromise assessments, post-incident hardening, and actionable cloud security findings.
Domain
Cloud Security / Cybersecurity
Deliverable
client delivery
Required skills
Cloud security architecture, IAM (AWS/Azure/GCP), Kubernetes security, Cloud incident response, Log forensics, AI-assisted tool triage, Cross-account attack path mapping, IaC review (Terraform/Helm/CloudFormation/Bicep), Container runtime security, eBPF telemetry analysis.
Preferred skills
None stated.
Technologies
AWS (IAM, STS, Organizations, SCP, GuardDuty, CloudTrail, EKS, IRSA), Azure (Entra ID, Conditional Access, RBAC, Defender for Cloud, AKS, Workload Identity), GCP (IAM, Org Policy, Audit Logs, GKE), Kubernetes (RBAC, OPA/Gatekeeper), Terraform, Helm, CloudFormation, Bicep, eBPF.
Responsibilities
Lead Wayfinder Frontier AI Services cloud-domain workstreams end-to-end across customer engagements, proactive reviews, compromise assessments, and post-incident hardening; Review and triage cloud security findings from agentic scanning pipelines to eliminate noise and ground exploitability; Conduct deep IAM, network, and identity reviews across AWS, Azure, and GCP; Lead cloud-native attack path discovery and document exposures and remediation; Defend findings under pressure with senior customer stakeholders; Maintain continuous awareness of cloud-native attack techniques, pure-cloud ransomware, and OAuth-app abuse.
Seniority
Staff, hands-on IC with customer advisory focus.