Cloud Security Engineer

Doist

San Francisco, Northern (CA, KY)

On-site

USD 180,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HappyRobot is seeking a Cloud Security Engineer to own cloud security across AWS, Azure, and GCP. You will drive CNAPP posture, implement policy-as-code gates in Terraform pipelines, and define a unified security baseline for multi-cloud environments.

You will harden Kubernetes clusters, enforce RBAC, and lead remediation with cross-functional teams. The role emphasizes ownership, scalable guardrails, and early-shift security checks.

Qualifications

  • 4–6 years in cloud security or platform/infrastructure security.
  • Expert depth in at least one major cloud provider (AWS, Azure, or GCP).
  • Hands-on experience with a CNAPP/CSPM — Wiz strongly preferred.
  • Terraform in production plus policy-as-code in CI/CD (OPA/Rego, Checkov, tfsec).
  • Kubernetes security fundamentals: RBAC, admission controls, image scanning.

Responsibilities

  • Own cloud posture management end-to-end across CNAPP; triage findings by exploitability and drive remediation.
  • Design and ship policy-as-code gates in the Terraform pipeline to block misconfigurations.
  • Define, document, and enforce a multi-cloud security baseline (AWS/Azure/GCP).
  • Harden Kubernetes clusters, images, and admission paths (EKS/AKS/GKE).
  • Lead remediation with engineering teams without direct authority; track SLAs.

Skills

Cloud security
CNAPP/CSPM
Terraform in prod
Kubernetes security
Python or Go
English B2+

Tools

Wiz
OPA/Rego
Checkov
tfsec

Job description

# Cloud Security EngineerHappyRobot • San Francisco, CA • Software Development • 1w agoSave this role or tell us whether you want more jobs like it.## **About HappyRobot**HappyRobot is the infrastructure for enterprises to build and orchestrate AI workforces. Our AI workers don't just communicate through voice and email - they make decisions, take action, and run operations autonomously across entire enterprise systems. Born in Y Combinator (S23) and backed by a16z, Base10, Prysm Capital and Eurazeo with over $150M raised, we power critical operations for global enterprises worldwide.Our platform is battle-tested in the most demanding environments, where AI has real consequences. We started in logistics, built our own voice stack, models, and orchestration layer from the ground up, and are now bringing that infrastructure to every enterprise that runs the real economy. Learn more about our vision in our manifesto.## **Role Overview**We are looking for a Cloud Security Engineer to join our team. You will be the single accountable owner for cloud security posture across AWS, Azure, and GCP — bringing the technical depth and operational discipline to keep our infrastructure hardened, our findings remediated on SLA, and our security baseline consistent across every environment we run.This is not a governance or advisory role. Your deepest strength is the ability to own outcomes end-to-end: triaging Wiz findings by real-world exploitability, shipping policy-as-code gates that catch misconfigurations before they hit production, and getting remediation done by engineering teams you don't manage. That said, you operate with a platform mindset — building guardrails that scale rather than manually reviewing every change.**What You'll Do*** **Cloud Posture Management** Own the CNAPP end-to-end. Triage Wiz findings by exploitability and business impact, drive remediation across engineering teams to SLA and keep the backlog from accumulating. Be the person who actually gets findings closed, not just reported.* **IaC Security** Design and ship policy-as-code gates in the Terraform pipeline that block misconfigurations at PR and plan time, before they reach production. Use OPA/Rego, Checkov, tfsec, or equivalent — and calibrate gates to stop bad patterns without creating friction that causes teams to route around them.* **Multi-Cloud Baseline** Define, document, and enforce a consistent security baseline across AWS, Azure, and GCP — covering IAM, networking, KMS/encryption, and logging. Own the documentation that supports enterprise customer security reviews and audit evidence requests.* **Kubernetes & Container Security** Harden clusters, images, and admission paths across EKS, AKS, and GKE. Set and enforce RBAC policies, admission controls, and image scanning standards.* **Remediation Leadership** Drive fixes through engineering teams you don't have direct authority over. Track SLAs, communicate risk clearly to technical and non-technical stakeholders, and escalate when needed — without creating noise.* **Shift-Left Guardrails** Grow the share of cloud infrastructure managed via Terraform with active security checks, quarter over quarter. Trend new critical misconfigurations reaching production to zero.**Must Have*** 4–6 years in cloud security or platform/infrastructure security.* Expert depth in at least one major cloud provider (AWS, Azure, or GCP): IAM, networking, KMS/encryption, and logging.* Hands-on experience with a CNAPP/CSPM — Wiz strongly preferred — including triage, prioritization, and driving remediation with engineering teams.* Terraform in production plus policy-as-code experience (OPA/Rego, Checkov, tfsec, or similar) integrated in CI/CD.* Kubernetes security fundamentals: RBAC, admission control, and image scanning.* Scripting proficiency in Python or Go.* English B2+ (professional working proficiency).**Nice to Have*** Working experience across 2+ cloud providers — we deploy on AWS, Azure, and GCP.* Cross-cloud and Kubernetes certifications: CCSK, CKA, CKS, AWS Security Specialty, or equivalent.* EKS/AKS/GKE hardening and container runtime security experience.* TypeScript or Go beyond scripting.* SIEM/detection exposure — we run RunReveal.* SOC 2 / ISO 27001 cloud control evidence experience.## **Why join us?*** Join a world-class team of engineers and builders.* Backed by top investors including a16z, Y Combinator, Base10, Prysm Capital and Eurazeo.* Have ownership and autonomy of projects and are encouraged to ship.* Comprehensive Benefits including healthcare, dental, vision coverage.* Competitive salary + equity in a high-growth startup.## **Our Operating Principles****Extreme Ownership**We take full responsibility for our work and outcomes. No excuses, no blame-shifting. If something needs fixing, we own it.**Craftsmanship**We sweat the details because details compound. We never settle for "just fine" — whether it's a scoping document, a prototype demo, or a customer conversation.**We are "Majos"**Be a good human. Friendly, genuine, kind. We're building something ambitious and it's better when we enjoy it together.**Urgency with Focus**Move fast, but in the right direction. Prioritize ruthlessly. Act decisively. Aim for the highest leverage action.**Talent Density and Meritocracy**Every hire raises the bar. Ability over seniority. Ownership goes to those who earn it.**First-Principles Thinking**Strip problems to their fundamentals, ignore industry dogma, and rebuild from scratch when needed. It's how we build what others think is impossible.*The personal data provided in your application and during the selection process will be processed by Happyrobot, Inc., acting as Data Controller.**By sending us your CV, you consent to the processing of your personal data for the purpose of evaluating and selecting you as a candidate for the position. Your personal data will be treated confidentially and will only be used for the recruitment process of the selected job offer.**In relation to the period of conservation of your personal data, these will be eliminated after three months of inactivity in compliance with the GDPR and legislation on the protection of personal data.**If you wish to exercise your rights of access, rectification, deletion, portability or opposition in relation to your personal data, you can do so through security@happyrobot.ai subject to the GDPR.**For more information, visit* *https://www.happyrobot.ai/privacy-policy**By submitting your request, you confirm that you have read and understood this clause and that you agree to the processing of your personal data as described.*
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Engineer
SOC Engineer

Doist • San Francisco (CA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Healthcare
Dental
Vision
+1
SOC Analyst
SOC Analyst

Doist • San Francisco (CA), Northern (KY)

Hybrid
USD 90,000 - 120,000
Healthcare
Equity
Security / AI Cloud Engineer
Security / AI Cloud Engineer

Cyber74 • Wyoming (OH), Town of Vermont (WI), Indiana (PA)

Hybrid
USD 110,000 - 130,000
Work from home
Flexible schedules
401k with employer match
+2
Cloud Security Engineer
Cloud Security Engineer

Braintrust • San Francisco (CA)

On-site
USD 130,000 - 180,000
Medical, dental, and vision insurance
Daily lunch, snacks, and beverages
Flexible time off
+2
Reliability Engineer - AI Infrastructure & Observability
Reliability Engineer - AI Infrastructure & Observability

HappyRobot • San Francisco (CA)

On-site
Security Engineer, Cloud Security
Security Engineer, Cloud Security

Saronic • San Diego (CA)

On-site
USD 140,000 - 210,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

ServiceTitan, Inc. • United States

Remote
USD 137,000 - 185,000
Flexible time off
Holistic health and wellness benefits
Comprehensive onboarding program
DevOps / Site Reliability Engineer ID70127
DevOps / Site Reliability Engineer ID70127

AgileEngine, LLC. • Dallas (TX)

On-site
USD 150,000 - 190,000
Growth opportunities
Competitive compensation
Remote work options
+3
Senior Security Engineer
Senior Security Engineer

Silversmith Capital Partners • United States

Hybrid
USD 126,000 - 154,000
HDHP + telehealth
Calm subscription
LinkedIn Learning
+3
Site Reliability Engineer
Site Reliability Engineer

Happyrobot Inc. • San Francisco (CA)

On-site
USD 100,000 - 140,000
Competitive salary + equity
Ownership & autonomy in projects
Opportunity to work with top-tier engineers