Lead Cloud Security Engineer
Core
Designing, implementing, and maintaining security controls across AWS and Azure cloud environments to protect access systems for millions of users.
Role type
Senior IC Cloud Security Engineer (Multi-cloud)
Builds
Secure multi-cloud environments (AWS/Azure) and CI/CD pipelines for intelligent access products
Domain
Cloud Security / Cybersecurity
Deliverable
production ML models | infrastructure
Required skills
AWS security services (IAM, GuardDuty, Security Hub, VPC, WAF), Azure security services (Entra ID, Defender for Cloud, Azure Policy, NSGs), CSPM platforms (Wiz, Orca, Rapid7, CrowdStrike), Infrastructure-as-Code (Terraform, CloudFormation, Bicep), container security (Docker, Kubernetes), serverless security patterns, network security principles (VPCs, zero trust), CI/CD security integration
Preferred skills
Cloud detection and response (CDR) tooling, cloud-native threat detection, AWS Security Specialty, Azure Security Engineer Associate (AZ-500), CCSP, CISSP
Technologies
AWS, Azure, Terraform, CloudFormation, Bicep, Docker, Kubernetes, EKS, ECS, Lambda, AKS, Azure Functions, Wiz, Orca, Rapid7 InsightCloudSec, CrowdStrike Falcon Cloud Security, GuardDuty, Security Hub, CloudTrail, Config, KMS, WAF, Organizations/SCPs, Entra ID, Defender for Cloud, Azure Policy, Key Vault, NSGs, Azure Monitor, Sentinel
Responsibilities
Architect and enforce cloud security controls including IAM policies, network segmentation, encryption, and logging; Manage and optimize CSPM and CWPP tooling; Conduct cloud security assessments and drive remediation; Design guardrails for IaC pipelines; Monitor and respond to cloud-specific threats; Evaluate and harden container and serverless architectures; Develop and maintain cloud security standards and runbooks; Support incident response activities; Partner with engineering teams to embed security into CI/CD pipelines
Seniority
Senior, hands-on IC