Cloud Security Engineer

Renesas Electronics

Los Angeles (CA)

Hybrid

USD 150,000 - 160,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Bonus opportunities

Job summary

Renesas Electronics is seeking a Cloud Security Engineer in Los Angeles to own the security layer of our modern stack, including cloud posture, detection, and enforcement across GovCloud and commercial AWS environments. This role reports into the CISO organization and collaborates with platform engineering, product, and compliance to accelerate security as a competitive advantage.

You will design secure-by-default guardrails, lead threat hunting, and manage centralized logging, SIEM, and

Qualifications

  • 5+ years of hands-on experience in security engineering, cloud security, or DevSecOps with production ownership of security controls and infrastructure.
  • Bachelor's degree in Computer Science or related field (or equivalent practical experience)
  • Deep AWS security expertise—IAM, KMS, VPC/network security, GuardDuty, Security Hub, CloudTrail, Config, WAF—including hands-on experience across commercial and GovCloud environments
  • Demonstrated experience in threat detection and threat hunting across cloud, application, and identity telemetry, including detection engineering / detection-as-code
  • Experience operationalizing threat intelligence to drive proactive defense
  • Strong background in logging, monitoring, and security reporting—centralized logging, SIEM design and administration, alerting, dashboards, and metrics
  • Experience implementing and administering security infrastructure and tooling (CSPM, vulnerability management, secrets management, workload/endpoint protection)
  • Application and pipeline security experience—securing CI/CD (GitHub Actions), SAST/DAST/SCA integration, secrets management, and securing containerized/Kubernetes workloads
  • Infrastructure-as-code proficiency with Terraform and containerization tools such as Docker, applied to security guardrails and controls
  • An innovative, adversarial mindset—you anticipate how systems break and automate the defense before it's needed
  • Strong systems thinking and the ability to design scalable, secure, maintainable controls
  • Excellent written and verbal communication skills
  • Comfort operating in autonomous, fast-paced environments
  • Nice to Have: Certifications and related experience

Responsibilities

  • Design and operate the security posture of Duro's AWS commercial and GovCloud environments—IAM and least-privilege access models, KMS/encryption policy, VPC segmentation, network controls, and secure-by-default guardrails across accounts and tenants.
  • Threat Detection & Hunting: Proactively hunt across cloud, application, and identity telemetry for anomalous and adversarial behavior; build detections as code and reduce false positives.
  • Threat Intelligence: Operationalize threat intel—integrate feeds, contextualize indicators against attack surface, drive proactive hardening.
  • Logging, Monitoring & Reporting: Architect centralized logging, SIEM, and security monitoring; own alerting pipelines, dashboards, and leadership-facing metrics.
  • Security Infrastructure Implementation & Administration: Implement and improve CSPM, vulnerability management, secrets management, workload/endpoint protection, and cloud-native security services.
  • Application & Pipeline Security: Secure CI/CD pipelines (GitHub Actions), integrate SAST/DAST/SCA, enforce secrets hygiene, and secure container/Kubernetes workloads.
  • Security as Code: Build reproducible, version-controlled security infrastructure and guardrails with Terraform and policy-as-code.
  • Compliance-Driven Controls: Map controls to SOC 2, ITAR, GovCloud to leadership; translate framework obligations into technical enforcement.
  • AI-Driven Security Engineering: Use AI-augmented workflows to accelerate detection engineering and control implementation.
  • Incident Response: Support detection, investigation, containment, and post-incident hardening; feed lessons learned into automated coverage.

Skills

Security engineering
Cloud security
Threat detection
Threat hunting
Logging & monitoring
CI/CD security
Communication skills
Autonomous work

Education

Bachelor's degree in Computer Science or related field

Tools

Terraform
Docker
Kubernetes
GitHub Actions
CloudTrail
GuardDuty
Security Hub

Job description

  • Compensation: USD 150000 - USD 160000 - yearly
Job Description

The Cloud Security Engineer secures the platform that hardware engineering teams trust to ship every day. You'll own the security engineering layer of Duro's modern stack—cloud security posture, detection and threat hunting, security telemetry, and the security infrastructure that protects multi-tenant, dedicated, and regulated (GovCloud/ITAR) environments. This is a security-first role on a small, fast-moving team reporting into the CISO organization, where you'll partner closely with platform engineering, product, and compliance to make security an accelerator rather than a gate. We're looking for an engineer who thinks in adversaries and systems, automates relentlessly, and leverages modern AI-augmented workflows to build defenses that scale. This is a hybrid role based in Los Angeles, CA (3 days per week in office).

A day in the life of our Cloud Security Engineer:

  • Cloud Security Engineering: Design and operate the security posture of Duro's AWS commercial and GovCloud environments—IAM and least-privilege access models, KMS/encryption policy, VPC segmentation, network controls, and secure-by-default guardrails across accounts and tenants.
  • Threat Detection & Hunting: Proactively hunt across cloud, application, and identity telemetry for anomalous and adversarial behavior. Build and tune detections as code, reduce false positives, and turn hunt findings into durable, automated coverage.
  • Threat Intelligence: Operationalize threat intelligence—integrate feeds, contextualize indicators and TPPs against Duro's attack surface, and drive proactive hardening ahead of emerging threats.
  • Logging, Monitoring & Reporting: Architect and administer centralized logging, SIEM, and security monitoring across the stack. Own alerting pipelines, dashboards, and the security metrics and reporting that inform leadership, customers, and compliance evidence.
  • Security Infrastructure Implementation & Administration: Implement, administer, and continuously improve the security tooling estate—CSPM, vulnerability management, endpoint and workload protection, secrets management, and cloud-native security services (GuardDuty, Security Hub, CloudTrail, Config, WAF, Inspector).
  • Application & Pipeline Security: Embed security into the SDLC and CI/CD—secure GitHub Actions pipelines, integrate SAST/DAST/SCA, enforce secrets hygiene, and secure container and Kubernetes workloads from build through runtime.
  • Security as Code: Build reproducible, version-controlled security infrastructure and guardrails using Terraform, policy-as-code, and containerization—so controls are enforced automatically and drift is caught early.
  • Compliance-Driven Controls: Partner with CISO leadership to implement and evidence controls mapped to SOC 2, ITAR, and GovCloud requirements, translating framework obligations into concrete technical enforcement.
  • AI-Driven Security Engineering: Leverage AI-augmented workflows to accelerate detection engineering, triage, and control implementation while maintaining rigorous validation and review standards.
  • Incident Response: Support detection, investigation, containment, and post-incident hardening—reducing mean time to detect and respond, and feeding lessons learned back into automated coverage.
Qualifications

Required:

  • 5+ years of hands-on experience in security engineering, cloud security, or DevSecOps with production ownership of security controls and infrastructure
  • Bachelor's degree in Computer Science or related field (or equivalent practical experience)
  • Deep AWS security expertise—IAM, KMS, VPC/network security, GuardDuty, Security Hub, CloudTrail, Config, WAF—including hands-on experience across commercial and GovCloud environments
  • Demonstrated experience in threat detection and threat hunting across cloud, application, and identity telemetry, including detection engineering / detection-as-code
  • Experience operationalizing threat intelligence to drive proactive defense
  • Strong background in logging, monitoring, and security reporting—centralized logging, SIEM design and administration, alerting, dashboards, and metrics
  • Experience implementing and administering security infrastructure and tooling (CSPM, vulnerability management, secrets management, workload/endpoint protection)
  • Application and pipeline security experience—securing CI/CD (GitHub Actions), SAST/DAST/SCA integration, secrets management, and securing containerized/Kubernetes workloads
  • Infrastructure-as-code proficiency with Terraform and containerization tools such as Docker, applied to security guardrails and controls
  • An innovative, adversarial mindset—you anticipate how systems break and automate the defense before it's needed
  • Strong systems thinking and the ability to design scalable, secure, maintainable controls
  • Excellent written and verbal communication skills
  • Comfort operating in autonomous, fast-paced environments

Nice to Have:

  • Relevant certifications (AWS Security Specialty, CISSP, OSCP, GCIH/GCIA/GCFA, or similar)
  • Experience with DuploCloud or similar tenant/cloud management platforms
  • Knowledge of compliance frameworks such as SOC 2, FedRAMP, ITAR, or CMMC
  • Experience building security for PLM, PDM, or hardware/manufacturing industry software
  • Background supporting compliance-driven or regulated (GovCloud, on-premises) deployments
  • Incident response, digital forensics, or purple-team experience
  • Familiarity with observability tooling such as Datadog, PostHog, or Sentry, and event-driven systems (NATS, Redis, Kafka)
  • PostgreSQL and Kubernetes operational familiarity sufficient to secure and reason about those workloads
How We Build

We don't just ship features. We build platforms that make shipping inevitable—and secure by default.

At Duro, AI is integrated into our engineering and security workflows. Engineers leverage AI-powered environments to orchestrate tasks, structure context, and accelerate delivery and defense while maintaining high standards of operational and security excellence.

We value:

Adversarial intuition — understanding how systems fail and how attackers think before building the defense Detection over hope — coverage you can measure, tune, and trust, expressed as code Precision in communication — clear control design produces reliable, auditable systems Pattern recognition — knowing when to abstract, automate, or simplify Operational discipline — building controls that are observable, resilient, and self-healing Intellectual curiosity — continuously improving how we secure and scale

We optimize for engineers who can build security that fades into the background—enabling teams to deploy daily with confidence, not friction.

Additional Information

The expected annual pay range for this position is $150,000-$160,000. This position is also eligible for bonus opportunities. Please note that final offer amount will be dependent on geographic location, applicable experience, and skillset of the candidate.

Renesas Electronics is an equal opportunity and affirmative action employer, committed to celebrating diversity and fostering a work environment free of discrimination on the basis of sex, race, religion, national origin, gender, gender identity, gender expression, age, sexual orientation, military status, veteran status, or any other basis protected by federal, state or local law. For more information, please read our Diversity & Inclusion Statement.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

Renesas Electronics • California (MO)

Hybrid
USD 150,000 - 160,000
Medical benefits
HSA / health savings account
Dental
+5
DevSecOps Engineer
DevSecOps Engineer

Renesas Electronics • Los Angeles (CA)

Hybrid
USD 150,000 - 160,000
Medical benefits
Health Savings Account (HSA)
Dental & Vision
+2
Senior Security Engineer – Hybrid (4649)
Senior Security Engineer – Hybrid (4649)

Hireclout • Los Angeles (CA)

On-site
USD 180,000 - 200,000
Competitive compensation package
Equity participation
100% covered medical, dental, and vision coverage
+5
Cybersecurity Engineer III (Cleared)
Cybersecurity Engineer III (Cleared)

Talanto • Colorado

On-site
USD 144,000 - 216,000
Flexible schedule
Premium Insurance
401k match
+6
Senior DevSecOps Engineer — Cloud Infra & Security (Hybrid LA)
Senior DevSecOps Engineer — Cloud Infra & Security (Hybrid LA)

Renesas Electronics • Los Angeles (CA)

Hybrid
USD 150,000 - 160,000
Medical benefits
Health Savings Account (HSA)
Dental & Vision
+2
Senior Security Engineer
Senior Security Engineer

Via Logic LLC • Columbus (OH)

On-site
USD 131,000 - 237,000
Cybersecurity Engineer (DevSecOps)
Cybersecurity Engineer (DevSecOps)

Arcfield • Home Creek (VA)

On-site
USD 120,000 - 170,000
Health Insurance
Life Insurance
Paid Time Off
+6
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Worky • New York (NY)

Hybrid
USD 170,000 - 230,000
Medical premiums paid by the company
Hybrid work environment
13+ holidays
Senior Security Engineer
Senior Security Engineer

Via Logic LLC • Boulder (CO)

On-site
USD 131,000 - 237,000
Cyber Security Engineer
Cyber Security Engineer

Neros Technologies • Torrance (CA)

On-site
USD 80,000 - 135,000