Cloud Security Engineer

Bright Mind Solutions LLC

Sunnyvale (CA)

On-site

USD 140,000 - 190,000

Full time

11 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Bright Mind Solutions LLC in Sunnyvale, CA is seeking a Cloud Security Engineer for a contract role (6+ months). You will secure multi-cloud infrastructure across AWS, Azure, GCP, OCI with a strong focus on Kubernetes hardening and CSPM.

You will implement IAM controls, enforce least privilege, and oversee container security, IaC security, and compliance automation across environments. Local candidates only for onsite interviews.

Qualifications

  • 5+ years in secure, production‑grade cloud systems
  • Extensive Kubernetes security experience (RBAC, policies, secrets)
  • Hands-on AWS security with multi-cloud exposure
  • Experience with CSPM and IaC security tooling

Responsibilities

  • Secure and maintain multi-cloud infrastructure (AWS, Azure, GCP, OCI) with guardrails.
  • Kubernetes cluster hardening with RBAC, network policies, and admission controls.
  • Develop and enforce IAM policies, least privilege across cloud and containers.
  • Secure container images, registries, and runtimes with scanning tools.
  • Manage IaC security using Terraform, CloudFormation, or AWS CDK.
  • Operate CSPM tools (e.g., Wiz) for misconfigurations and drift remediation.
  • Automate compliance checks and produce audit evidence for audits.
  • Monitor and protect running apps and containers during operations.

Skills

Kubernetes security
RBAC enforcement
IAM & least privilege
CSPM tooling
IaC security
Cloud security architecture
Container security
Compliance automation

Tools

Terraform
CloudFormation
AWS CDK
Wiz
Kubernetes
Docker
Podman

Job description

Cloud Security Engineer
Sunnyvale, CA
Contract / CTH 6+ Months
Backfill role
Local candidate needed for onsite interview
About the role

We are seeking a highly focused Cloud Security Engineer whose role will be fundamentally driven by our environment architecture and deployment methodology. Working alongside our Corporate Security & Infrastructure team, you will play a crucial role in securing our infrastructure across diverse multi-cloud environments (AWS, Azure, GCP, OCI), with a heavy emphasis on Kubernetes cluster hardening. You will establish robust guardrails, enforce Identity and Access Management policies, and maintain our Cloud Security Posture Management (CSPM) to prevent insecure deployments and ensure continuous compliance.

Responsibilities:
  • Cloud Infrastructure Security: Securely deploy and maintain infrastructure across diverse multi-cloud environments (AWS, Azure, GCP, OCI), establishing cloud-specific robust guardrails to prevent insecure deployments and configurations.
  • Kubernetes Cluster Hardening: Implement and enforce security best practices and policies specifically tailored for Cloud native Kubernetes clusters, including granular Role-Based Access Control (RBAC), network policies, and admission controllers.
  • Identity & Access Management (IAM): Develop, implement, and enforce robust security policies and procedures specifically related to user authentication and authorization across all systems. Manage user identities (traditional active directory, email platforms, cloud solutions) and rigorously enforce the principle of least privilege on Cloud, cloud service, and container levels.
  • Container Security: Ensure the security of container images, registries, and runtime environments through the effective use of tools like Docker, Podman, and various container scanning solutions.
  • Infrastructure-as-Code (IaC) Security: Manage infrastructure and security policies through version-controlled Git repositories using tools such as Terraform, CloudFormation, or AWS CDK to ensure consistent, auditable, and secure deployments.
  • Cloud Security Posture Management (CSPM): Maintain CSPM tools such as Wiz to continuously detect and remediate misconfigurations and compliance drifts across the cloud footprint.
  • Compliance Automation: Automate compliance checks and generate necessary evidence for audits across the multi-cloud environment, streamlining regulatory adherence.
  • Runtime Security: Monitor and protect running applications and containers from threats during their operational lifecycle.
We're looking for someone who has:
  • 5+ years of industry experience in software engineering or security engineering, with a focus on designing and building secure, production‑grade cloud systems.
  • Extensive, demonstrable experience with Kubernetes from a security perspective (e.g., securing containerized workloads, enforcing RBAC, and cloud‑native secret management).
  • Implemented AI to rapidly identify, validate, and remediate security issues without impact.
  • Deep operational security experience with AWS (mandatory), with highly preferred practical experience deploying and securing infrastructure across Azure, GCP, or OCI.
  • Proficiency in Infrastructure-as-Code (IaC) tools such as Terraform, CloudFormation, or AWS CDK to deploy and manage environments.
  • Hands‑on expertise in configuring, monitoring, and driving remediation through Cloud Security Posture Management (CSPM) platforms like Wiz.
  • A strong background in designing and enforcing complex Identity & Access Management (IAM) and least‑privilege architectures across both multi‑cloud and traditional on‑premises directory environments.
  • Experience working with container security, image scanning, and runtime protection tools.
Nice to have:
  • Advanced industry certifications related to cloud and container security (e.g., AWS Certified Security Specialty, Certified Kubernetes Security Specialist (CKS), Certified Kubernetes Administrator (CKA)).
  • Strong proficiency in programming or scripting languages commonly used for security automation and backend development (e.g., Go/Golang, Python, or C++).
  • Prior experience automating compliance frameworks and generating audit evidence across a multi‑cloud footprint.
  • Experience securing and operating in air‑gapped or highly constrained on‑premises computing environments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security Engineer: Multi-Cloud & Kubernetes Expert
Cloud Security Engineer: Multi-Cloud & Kubernetes Expert

Bright Mind Solutions LLC • Sunnyvale (CA)

On-site
USD 140,000 - 190,000
Cloud Security Engineer
Cloud Security Engineer

ALLTECH CONSULTING SVC INC • Alpharetta (GA)

On-site
USD 120,000 - 150,000
Cloud Security Engineer
Cloud Security Engineer

smiledigitalhealth • United States

Remote
USD 140,000 - 190,000
Health coverage
Retirement plan
Life and disability coverage
+1
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
Cloud Security Engineer
Cloud Security Engineer

10xTalents • Washington

On-site
USD 100,000 - 140,000
Cloud Security Engineer
Cloud Security Engineer

apex-technology-inc • Los Angeles (CA)

On-site
USD 180,000 - 240,000
Senior DevSecOps Engineer – Cloud Infrastructure Security
Senior DevSecOps Engineer – Cloud Infrastructure Security

Partnerverse • Saint Cloud (MN)

On-site
USD 140,000 - 190,000
Cloud Security Engineer (DevOps)- Active Clearance is required
Cloud Security Engineer (DevOps)- Active Clearance is required

Liberty Personnel Services, Inc. • Westminster (CO)

On-site
USD 140,000 - 170,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Compunnel, Inc. • Pittsburgh

Remote
USD 100,000 - 130,000
Security Engineer
Security Engineer

Factory • San Francisco (CA)

On-site
USD 120,000 - 150,000