Cloud Security & Automation Engineer

careers-berkley

Wilmington (DE)

On-site

USD 110,000 - 150,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Berkley Technology Services is seeking a Cloud Security & Automation Engineer to enhance security across cloud and container environments. You will own cloud exposure management platforms like Wiz or Prisma Cloud, implement automated controls, and work with Vulnerability Management and AI Security teams to drive risk-based remediation.

The role requires 5+ years in cloud security/DevSecOps, strong scripting (Python/PowerShell), IaC expertise, and experience with Azure and AWS.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering or related discipline.
  • 5+ years of experience in cloud security engineering, security engineering, DevSecOps, cloud platform engineering, or a related technical security role.
  • Hands-on experience securing and operating production environments in Microsoft Azure and/or AWS; multi-cloud experience is preferred.
  • Hands-on experience with CNAPP, CSPM, or cloud exposure management platform such as Wiz or Prisma Cloud, including policy configuration, findings analysis, integrations, reporting, and remediation workflows.
  • Demonstrated comfort using AI-assisted tools in a professional context; approaches AI as a standard part of modern workflow rather than a specialized or optional capability
  • Demonstrated experience prioritizing cloud risk using business context, exploitability, attack paths, asset criticality, identity exposure, network exposure, and data sensitivity.
  • Strong scripting and automation skills using Python, PowerShell, REST APIs, JSON/YAML, source control, and CI/CD practices.
  • Experience with Infrastructure as Code and policy-as-code technologies such as Terraform, Bicep, ARM templates, CloudFormation, Open Policy Agent, or equivalent controls.
  • Solid understanding of cloud identity and access management, non-human identities, least privilege, network security, workload and container security, secrets management, encryption, logging, monitoring, and incident response.
  • Ability to troubleshoot complex technical issues, communicate risk clearly, and drive remediation across teams without relying solely on direct authority.
  • Ability to produce clear technical documentation, operating metrics, and leadership-ready status or risk updates.

Responsibilities

  • Cloud exposure management and platform ownership: Configure, administer, optimize, and troubleshoot cloud security and exposure management platforms such as Wiz or Prisma Cloud across Azure, AWS, and other in-scope services.
  • CTEM operations and risk prioritization: Identify cloud exposures, analyze attack paths, prioritize risk, coordinate remediation, and track exceptions.
  • Security automation and engineering: Design and build reusable automation for cloud security operations using Python, PowerShell, REST APIs, JSON/YAML, and IaC; automate onboarding, policy deployment, and remediation workflows.
  • Cloud security architecture and guardrails: Define and implement cloud security requirements, reference patterns, guardrails, and controls for identity, network, workload, container, data, and logging security.
  • Cross-functional remediation and enablement: Partner with Cloud, DevOps, Vulnerability Management, IAM, and infrastructure teams to drive secure delivery workflows.
  • AI security partnership: Provide cloud security engineering for AI platforms, including identity controls, data-flow protection, logging, and pattern automation.
  • Metrics, governance, and continuous improvement: Develop dashboards and metrics for cloud coverage, exposures, remediation aging, and control adoption.
  • Incident support and escalation: Support investigations with exposure validation, configuration analysis, and incident response.
  • Standards, documentation, and knowledge sharing: Create standards, runbooks, diagrams, and conduct design reviews and coaching.
  • Technical leadership and recruiting: Lead workstreams, mentor engineers, review designs, and participate in resume reviews and interviews.

Skills

Cloud Security
Automation
Python
PowerShell
CI/CD
Terraform
Kubernetes
AI security
Vulnerability mgmt
Incident response
Microsoft Azure
AWS
Policy as code

Education

Bachelor's degree

Tools

Wiz
Prisma Cloud

Job description

Company Details

Company URL: https://www.berkleytechnologyservices.com/

Berkley Technology Services (BTS) is the dynamic technology solution for W. R. Berkley Corporation, a Fortune 500 Commercial Lines Insurance Company. With key locations in Urbandale, IA and Wilmington, DE, BTS provides innovative and customer-focused IT solutions to the majority of WRBC’s 60+ operating units across the globe. BTS’s wide reach ensures that ideas and opinions are considered at every level of the organization to guarantee we find the best solutions possible.

Driven by a commitment to collaboration, BTS acts as consultants to our customers and Operating Units by providing comprehensive solutions that not only address the challenge at hand but proactively plan for the “What’s Next” in our industry and beyond.

With a culture centered on innovation and entrepreneurial spirit, BTS stands as a community of technology leaders with eyes toward the future -- leaders who genuinely care about growing not only their team members, but themselves, and take pride in their employees who shine. BTS offers endless ways to get involved and have the chance to grow your career into a wide range of roles you'd never known existed. Come join us as we push forward into the future of industry leading technological solutions.

Berkley Technology Services: Right Team, Right Technology, Simple and Secure.

Responsibilities

The Cloud Security & Automation Engineer is a hands-on engineering role responsible for improving security across public cloud, hybrid, container, and cloud-native environments. The role owns the day-to-day engineering and operation of cloud exposure management capabilities, including platforms such as Wiz or Prisma Cloud, and converts prioritized risk into durable technical controls, automated workflows, and measurable remediation outcomes. The engineer will work closely with Vulnerability Management and AI Security Teams.

Cloud exposure management and platform ownership Configure, administer,optimize, and troubleshoot cloud security and exposure management platforms such as Wiz or Prisma Cloud. Manage cloudaccountandsubscriptiononboarding, connectors, permissions, policies, rules, integrations, dashboards, and platform health across Azure, AWS, and other in-scope cloud services.

CTEM operations and risk prioritization Support the continuous threat exposure management lifecycle byidentifyingand validating cloud exposures, analyzing attack paths and toxic combinations, prioritizing material risk, coordinating remediation with accountable teams,validating closure, and tracking exceptions. Translate platform findings into a focused, risk-based backlog rather than a high-volume queue of uncontextualized alerts.

Security automation and engineering Design and build reusable automation for cloud security operations using Python, PowerShell, REST APIs, JSON/YAML, workflow orchestration, serverless services, and Infrastructure as Code. Automate asset onboarding, policy deployment, enrichment, ticket routing, evidence collection, remediation validation, reporting, and other repeatable engineering tasks.

Cloud security architecture and guardrails Define and implement cloud security requirements, reference patterns, preventive guardrails, and detective controls for identity, network, workload, container, Kubernetes, data, secrets, logging, and configuration security. Contribute security requirements to cloud landing zones and platform engineering standards.

Cross-functional remediation and enablement Partner with Cloud, DevOps, Vulnerability Management, IAM, infrastructure, and application teams to assign ownership, develop practical remediation patterns, integrate controls into delivery workflows, and improve adoption of secure cloud practices.

AI security partnership Provide cloud security engineering for AI platforms and services, including secure architecture reviews, identity and non-human identity controls,secretsmanagement, data-flow protection, logging and monitoring, exposure analysis, and automation. Help translate emerging AI security requirements into repeatable cloud controls and engineering patterns.

Metrics, governance, and continuous improvement Develop dashboards and operating metrics for cloud coverage, critical exposures, attack paths, remediation aging, exceptions, automation effectiveness, and control adoption. Use metrics toidentify systemic issues and recommend improvements to architecture, tooling, and operating processes.

Incident support and technical escalation Provide cloud securityexpertiseduring investigations and incidents, including exposure validation, cloud configuration analysis, identity and access review, log analysis, containment support, and corrective-action engineering. Participate in senior escalation or Person in Charge coverage when assigned.

Standards, documentation, and knowledge sharing Create andmaintaintechnical standards, standard operating procedures, runbooks, architecture diagrams, operational playbooks, and control documentation. Share knowledge through design reviews, demonstrations, and hands‑on coaching.

Technical leadership and recruiting Lead technical workstreams, mentor engineers, reviewdesignsand automation, and contribute to resume reviews, technical interviews, and practical assessments for cloud security engineering roles.

Qualifications
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering or related discipline
  • 5 or more years of experience in cloud security engineering, security engineering, DevSecOps, cloud platform engineering, or a related technical security role.
  • Hands-on experience securing and operating production environments in Microsoft Azure and/or Amazon Web Services; multi-cloud experience is preferred.
  • Hands-on experience with a CNAPP, CSPM, or cloud exposure management platform such as Wiz or Prisma Cloud, including policy configuration, findings analysis, integrations, reporting, and remediation workflows.
  • Demonstrated comfort using AI-assisted tools in a professional context; approaches AI as a standard part of modern workflow rather than a specialized or optional capability
  • Demonstrated experience prioritizing cloud risk using business context, exploitability, attack paths, asset criticality, identity exposure, network exposure, and data sensitivity.
  • Strong scripting and automation skills using Python and/or PowerShell, REST APIs, JSON/YAML, source control, and CI/CD practices.
  • Experience with Infrastructure as Code and policy-as-code technologies such as Terraform, Bicep, ARM templates, CloudFormation, Open Policy Agent, or equivalent controls.
  • Solid understanding of cloud identity and access management, non-human identities, least privilege, network security, workload and container security,secretsmanagement, encryption, logging, monitoring, and incident response.
  • Ability to troubleshoot complex technical issues, communicate risk clearly, and drive remediation across teams without relying solely on direct authority.
  • Ability to produce clear technical documentation, operating metrics, and leadership-ready status or risk updates.

Preferred Qualifications

  • Experience designing oroperatinga formal CTEM program or exposure management operating model.
  • Experience integrating cloud security platforms with ServiceNow, Azure DevOps, Jira, SIEM/SOAR platforms, messaging platforms, data pipelines, or reporting tools.
  • Experience securing Kubernetes, containers, serverless services, CI/CD pipelines, software supply chains, and cloud-native application architectures.
  • Familiarity with AI/ML security, including AI service architecture, model and data access, agent or workload identities, prompt and data-flow risks, AI security posture management, and governance of AI-enabled services.
  • Working knowledge of cloud and security frameworks such as NIST CSF, NIST 800-53, CIS Benchmarks, CSA CCM, MITRE ATT&CK, OWASP, and relevant regulatory or audit requirements.
  • Relevant certifications such as CCSP, CISSP, CCSK, Microsoft Azure Security Engineer, AWS Certified Security - Specialty, or vendor platform certifications.
  • Ability to sit at a desk and work on a computer for extended periods of time.
  • Must occasionally lift and/or move up to ten pounds.
  • Vision abilities required by this job include close vision and the ability to adjust focus.

The Company is an equal employment opportunity employer.

Additional Company Details

We do not accept unsolicited resumes from third party recruiting agencies or firms.

Additional Requirements

Location and Travel: Primary location Wilmington, DE.

Sponsorship Details

Sponsorship not Offered for this Role

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security & Automation Engineer
Cloud Security & Automation Engineer

Berkley Small Business Solutions (a Berkley Company) • Wilmington (DE)

On-site
USD 107,000 - 198,000
Senior Vice President, Senior Cloud Security Engineer
Senior Vice President, Senior Cloud Security Engineer

BNY • New York (NY)

On-site
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+3
CTEM Cloud and Hardening Analyst/Governance
CTEM Cloud and Hardening Analyst/Governance

Tricascade Tech • United States

On-site
USD 140,000 - 210,000
Senior Technical Consultant - Cloud Security
Senior Technical Consultant - Cloud Security

Jobgether • United States

On-site
USD 140,000 - 190,000
Medical, dental, and vision insurance
401(k) retirement plan
Paid company holidays
+2
Cloud Security Engineer
Cloud Security Engineer

Greenberg Traurig, LLP • Charlotte (NC)

On-site
USD 100,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Fintech Staffing Partners • United States

On-site
USD 130,000 - 160,000
Lead Cloud Security Engineer (contract)
Lead Cloud Security Engineer (contract)

Thomson Reuters  • Richmond (VA)

On-site
USD 75,768 - 89,544
Medical benefits
Dental benefits
Vision benefits
+1
Cloud Security Engineering Manager
Cloud Security Engineering Manager

CIBR Warriors • United States

On-site
USD 140,000 - 210,000
Cloud Security Engineer
Cloud Security Engineer

ECS • Arlington (VA)

On-site
USD 140,000 - 170,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000