Cloud Security Operations Engineer

Cadence Design Systems

San Jose (CA)

On-site

USD 78,523 - 146,025

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Paid vacation
Paid holidays
401(k) match
Medical, dental and vision plan

Job summary

Cadence Design Systems is seeking a Cloud Security Operations Engineer to design and maintain cloud security controls across AWS, Azure, GCP, and IBM Cloud. The role emphasizes data protection and incident management under the Senior Cloud Security Architect.

Key areas include secure IaC, CSPM/CNAPP tooling, DLP, IAM, and automation via Python, PowerShell, Bash and serverless functions. California location, full-time with strong compensation.

Qualifications

  • Bachelor’s degree in computer science, information security or related field (or equivalent experience).
  • Cloud platform security knowledge across AWS/Azure/GCP; strong scripting and security tooling familiarity.
  • Experience with CIS benchmarks, NIST and CCM standards; OS and container security experience.

Responsibilities

  • Secure Architecture and Engineering Design across multi‑cloud environments.
  • Implement IaC security controls using Terraform, CloudFormation, and ARM Templates.
  • Manage IAM, MFA, SSO, and least‑privilege access models.
  • Configure and operate cloud‑native security tools and SIEM integrations.
  • Lead incident response and remediation workflows; conduct root‑cause analysis.
  • Triage DLP alerts and support data classification alignment with GRC.
  • Develop automation in Python, PowerShell, Bash, and serverless functions.
  • Perform CSPM/CNAPP based cloud posture assessments and audits.

Skills

Python
PowerShell
Unix shell
CSPM/CNAPP
CIS Benchmarks
NIST
Zero-trust
Cloud security

Education

Bachelor’s degree in computer science or information security (or equivalent)
AWS Certified Solutions Architect – Associate
AWS Certified Security – Specialty
Microsoft Certified: Azure Administrator Associate
Microsoft Certified: Azure Security Engineer Associate
Google Cloud Associate Cloud Engineer
Google Cloud Professional Cloud Security Engineer
ISC² CCSP
ISC² CISSP

Job description

Job Overview

Cadence is hiring a Cloud Security Operations Engineer. The role focuses on designing and maintaining robust security controls across AWS, Azure, GCP, and IBM Cloud. The engineer will enhance the cloud security posture with emphasis on data protection and incident management and report to the Senior Cloud Security Architect.

Job Responsibilities
  1. Secure Architecture and Engineering Design: deploy secure reference architectures across multi‑cloud environments, integrate security into Infrastructure-as-Code (IaC) using Terraform, CloudFormation, and ARM Templates, implement cloud-native security controls (VPCs, WAFs, DDoS, endpoint protections), ensure data protection via encryption, KMS/HSM and DLP policies.
  2. Identity and Access Management: design, implement, and audit IAM policies, roles, service accounts, and federation models with least‑privilege principles, configure MFA, SSO, and PAM solutions for secure cloud access.
  3. Monitoring, Detection, and Response: configure and maintain cloud-native security tools (AWS Security Hub, Microsoft Defender for Cloud, Google Security Command Center), integrate logs with SIEM systems, lead incident response efforts, continuously monitor through CSPM and CNAPP tools to remediate misconfigurations, manage findings via remediation workflows, partner with other teams for remediation, conduct root‑cause analysis, and recommend preventive controls and automation improvements.
  4. Cloud Data Loss Prevention (DLP) Management: triage and investigate DLP alerts, distinguish policy violations, insider threats, and false positives, serve as SME for DLP tools (Microsoft Purview, Google DLP, CASB solutions), tune policies and rules, generate compliance reports, collaborate with GRC teams for data classification alignment.
  5. Automation and DevSecOps: develop automation scripts in Python, PowerShell, Bash and serverless functions (AWS Lambda, Azure Functions, Google Cloud Run).
  6. Cloud Security Posture Management & Compliance: continuously assess AWS, Azure and GCP with CSPM platforms, develop and enforce cloud security baselines, perform periodic assessments using CIS Benchmarks, CSA CCM, NIST, NIST, etc., drive remediation, support internal and external audits with evidence and reporting.
  7. Secure Access and Network Security Controls: enforce least‑privilege network segmentation, private endpoints (AWS PrivateLink, Azure Private Endpoints, Google Private Service Connect), eliminate unnecessary public exposure, design firewall controls.
  8. Cloud Workload Security and Hardening: maintain secure OS baselines using CIS Benchmarks, perform periodic reviews, collaborate on hardened images and golden image standards, remediate deviations.
Job Qualifications

Technical Expertise: deep knowledge of at least one cloud platform (AWS, Azure, or GCP); proficiency in Python, PowerShell, Unix shell scripting; strong networking and cloud‑native security understanding; experience with CSPM/CNAPP platforms; knowledge of CIS Benchmarks, CCM, NIST and industry best practices; familiarity with securing OS and container environments; experience with secure network architectures and zero‑trust principles; support for cloud compliance and audits.

Education & Certification: Bachelor’s degree in computer science, information security or related field (or equivalent experience).

  • AWS Certified Solutions Architect – Associate
  • AWS Certified Security – Specialty
  • Microsoft Certified: Azure Administrator Associate
  • Microsoft Certified: Azure Security Engineer Associate
  • Google Cloud: Associate Cloud Engineer
  • Google Cloud: Professional Cloud Security Engineer
  • ISC² Certified Cloud Security Professional (CCSP)
  • ISC² Certified Information Systems Security Professional (CISSP)

Soft Skills: strong analytical and problem‑solving abilities; excellent communication and collaboration skills with DevOps and engineering teams.

Compensation & Benefits

Hourly range for California: $57.21 to $106.25. Additional incentive compensation may include bonus, equity, and benefits. Benefits include paid vacation and paid holidays, 401(k) plan with employer match, employee stock purchase plan, medical, dental and vision plans, and more.

Equal Employment Opportunity

Cadence is committed to equal employment opportunity and employment equity throughout all levels of the organization. We strive to attract a qualified and diverse candidate pool and encourage diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, sex, age, national origin, religion, sexual orientation, gender identity, status as a veteran, basis of disability, or any other protected class.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Operations Engineer
Cloud Security Operations Engineer

Cadence Design Systems, Inc. • San Jose (CA)

On-site
USD 78,523 - 146,025
Paid vacation
401(k) with match
Employee stock purchase plan
+1
Cloud Security Engineer - Multi-Cloud, IAM & Automation
Cloud Security Engineer - Multi-Cloud, IAM & Automation

Cadence Design Systems • San Jose (CA)

On-site
Paid vacation
Paid holidays
401(k) match
+1
Software Security Architect
Software Security Architect

Cadence Design Systems, Inc. • San Jose (CA)

On-site
USD 136,500 - 253,500
Paid vacation and holidays
401(k) plan with employer match
Employee stock purchase plan
+1
Multi-Cloud Security Engineer & Incident Response
Multi-Cloud Security Engineer & Incident Response

Cadence Design Systems, Inc. • San Jose (CA)

On-site
USD 78,523 - 146,025
Paid vacation
401(k) with match
Employee stock purchase plan
+1
Lead Cloud Security Engineer
Lead Cloud Security Engineer

The Chamberlain Group LLC • South Carolina

On-site
USD 102,600 - 193,425
Comprehensive benefits package
401(k) contribution
Short-term incentive plan
Director of Software Security
Director of Software Security

Cadence Design Systems • San Jose (CA)

On-site
USD 164,000 - 306,000
Paid vacation
401(k) plan with employer match
Employee stock purchase plan
+1
Cloud Security Engineer
Cloud Security Engineer

Greenberg Traurig, LLP • Charlotte (NC)

Hybrid
USD 100,000 - 130,000
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Cloud Security Engineer - Boston
Cloud Security Engineer - Boston

Motion Recruitment • Boston (MA)

On-site
USD 140,000 - 190,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Manhattan Associates • Atlanta (GA)

On-site
USD 120,000 - 150,000