Principal Cloud & Network Security Engineer

Hard Rock Digital

United States

Hybrid

USD 160,000 - 210,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive pay and benefits
Hybrid / remote working environment
Startup culture backed by a secure, go
Global brand presence

Job summary

Hard Rock Digital is seeking a Principal Cloud & Network Security Engineer to own security across our multi-cloud footprint and edge that fronts millions of players. You’ll operate at the intersection of cloud, network, and edge security, reporting to the VP Security / CISO as the senior technical owner for this domain.

You’ll design secure cloud configurations, enforce guardrails, and lead security architecture across AWS, Azure, GCP, and Cloudflare, partnering with SecOps and product teams to

Qualifications

  • 10+ years in cloud, network, or infrastructure security engineering or equivalent.
  • Hands-on expertise in at least one major cloud (AWS strongly preferred) with working knowledge of a second.
  • Experience with cloud security posture and runtime protection tooling at scale.
  • Strong network security fundamentals: segmentation, firewalls, ZTNA, secure connectivity.
  • Hands-on experience with edge/WAF/CDN protections (Cloudflare a strong plus).
  • IAcC proficiency (Terraform), policy-as-code mindset, and scripting (Python/Bash/Go).
  • Track record of leading through influence across teams and communicating risk to executives.
  • Fluency with AI and applying it to security/engineering work.

Responsibilities

  • Own cloud security posture and runtime protection across AWS, Azure, and GCP.
  • Define and maintain secure configuration baselines and guardrails for new resources.
  • Partner with SecOps to feed cloud signals into detection and response pipelines.
  • Design and implement network segmentation and east-west controls to limit blast radius.
  • Advance Zero Trust network access using Cloudflare Access and private connectivity.
  • Own security configuration of Cloudflare edge (WAF, Bot Management, DDoS protections).
  • Build policy-as-code and Terraform guardrails; embed infrastructure-scanning into CI/CD pipelines.
  • Act as design authority for cloud, network, and edge security and mentor engineers.

Skills

Cloud security
Network security
Edge security
Terraform
Python/Bash/Go
CI/CD pipelines
Zero Trust
WAF
Cloudflare

Tools

Terraform
Wiz/ CNAPP tooling
Cloudflare suite
Kubernetes

Job description

Hard Rock Digital is a team focused on becoming the best online sportsbook, casino, and social gaming company in the world. We’re building a team that resonates passion for learning, operating, and building new products and technologies for millions of consumers. We care about each customer’s interaction, experience, behavior, and insight and strive to ensure we’re always acting authentically.

Rooted in the kindred spirits of Hard Rock and the Seminole Tribe of Florida, Hard Rock Digital taps a brand known the world over as the leader in gaming, entertainment, and hospitality. We’re taking that foundation of success and bringing it to the digital space - ready to join us?

What's the Position?

We're looking for a Principal Cloud & Network Security Engineer to own security across our cloud footprint and all the way out to the edge that fronts millions of players. This spans a genuinely multi-cloud estate — AWS, Azure, and GCP — plus the Cloudflare edge that sits in front of it all.

This role reports directly to our VP Security / CISO — cloud, network, and edge security is a first-class pillar of the security program, not a sub-team. And you won't do it alone: you'll join a 16-person security organization, including a dedicated Security Architecture & Engineering team and a 24/7 SecOps function, as the senior technical owner for this domain.

This is a high-impact, high-autonomy role for someone who is equally comfortable reasoning about a VPC design, writing a Terraform guardrail, and tuning a WAF rule that protects live betting traffic on the biggest game night of the year.

What You'll Do

Cloud Security Posture

  • Own cloud security posture and runtime protection across AWS, Azure, and GCP using Wiz and modern runtime protection tooling — from finding misconfigurations to driving them to closure and catching threats at runtime. You own infrastructure-layer and configuration risk end to end, partnering with our Principal Product Security Engineer, who owns the application and dependency vulnerability lifecycle.
  • Define and maintain secure configuration baselines and guardrails so new cloud resources are safe by default
  • Partner with SecOps to feed high-quality cloud signals into our detection and response pipeline

Network Security & Microsegmentation

  • Design and implement network segmentation and east-west controls that limit blast radius across our environments
  • Advance Zero Trust network access using Cloudflare Access, private connectivity, and service-to-service authentication (including mTLS where it fits) — partnering with our Principal Identity Engineer on the identity signals those policies consume
  • Align our network posture to NIST SP 800-207 and the CISA Zero Trust Maturity Model (Networks pillar)

Edge Security

  • Own the security configuration of our Cloudflare edge — WAF, Bot Management, and DDoS protections — plus our broader Cloudflare Zero Trust deployment, protecting Hard Rock Bet, our customer-facing sportsbook and casino
  • Tune protections to stop abuse and attacks without blocking real players

Infrastructure-as-Code & Platform Security

  • Build policy-as-code and Terraform guardrails, and embed infrastructure-as-code security scanning (Wiz Code) into CI/CD pipelines — you own the infrastructure-scanning side of the pipeline; our Principal Product Security Engineer owns application and dependency scanning
  • Partner closely with platform and infrastructure teams to make secure infrastructure the default path, not an afterthought
  • Automate the boring parts so security scales with a fast-moving engineering org

Technical Leadership

  • Act as the design authority for cloud, network, and edge security — setting standards, mentoring security and platform engineers, and driving alignment across teams you don't manage
What are we looking for?
  • 10+ years in cloud, network, or infrastructure security engineering — or equivalent practical experience
  • Deep, hands-on expertise in at least one major cloud (AWS strongly preferred), with working knowledge of a second
  • Experience with cloud security posture and runtime protection tooling (Wiz or equivalent CNAPP/runtime tooling) at scale
  • Strong network security fundamentals: segmentation, firewalls, ZTNA, and secure connectivity patterns
  • Hands-on experience with edge/WAF/CDN protection (Cloudflare a strong plus)
  • Infrastructure-as-Code proficiency (Terraform), a policy-as-code mindset, and scripting/automation skills (Python, Bash, or Go) — comfortable working in CI/CD pipelines
  • A track record of leading through influence — you set technical direction across teams you don't manage, and you can explain a network path to an engineer and a risk to an executive
  • Fluency with AI — you lead with it, reaching for AI tools daily to work faster and sharper; hands‑on experience applying AI to security or engineering work is a must

You don't need to tick every box. If you're deep in two of the three domains — cloud, network, edge — and curious about the third, we want to hear from you.

Bonus Points
  • Experience in a regulated industry (gaming, financial services, healthcare) — especially PCI DSS network segmentation and scoping, or GLI-19/GLI-33 requirements
  • Deep Cloudflare experience across WAF, Bot Management, Access, and the Zero Trust suite
  • Experience securing containers and orchestration — Kubernetes network policy, service mesh, or workload identity
  • Relevant certifications (e.g., AWS Security Specialty, CCSP, GIAC cloud/network security)
  • Experience deploying DNSSEC (or DNS-layer security controls) across a production, multi-zone estate
Who You Are
  • Fiercely focused — you cut through noise, pick the risks that actually matter, and finish strong
  • Deeply curious — you dig into how attackers move through cloud and network, test your own assumptions, and shut those paths down
  • Customer obsessed — you tune protections so millions of players never notice security; they just feel safe
  • A builder who prefers guardrails over gates — you make the secure path the easy path
  • Meticulous about reducing blast radius and eliminating standing risk
  • You prioritize well amid competing demands and bring others along — engineers trust you because you make their path easier, not harder
Why This Role Is Different

Security for cloud, network, and edge usually gets scattered — split across platform teams, bolted on late, or filed as findings someone else may never fix. Here it's one security mandate, reporting directly to our VP Security / CISO. Our cloud/DevOps and network engineering teams build and run the platform; you're the security authority working beside them — setting the guardrails and secure‑by‑default patterns across three clouds and the edge that fronts millions of players, with the autonomy and air cover to shape the foundations every Hard Rock Digital product runs on. When the biggest game of the year sends traffic vertical, your guardrails are what keep the show running.

This is one of three Principal openings reporting to our VP Security / CISO: Identity (who and what gets access), Cloud & Network Security (where workloads run and how traffic moves), and Product Security (the code and its vulnerabilities).

What's in it for you?

We offer our employees more than just competitive compensation. Our team benefits include:

  • Competitive pay and benefits
  • A hybrid / remote working environment
  • Startup culture backed by a secure, global brand
Roster of Uniques

We care deeply about every interaction our customers have with us, and trust and empower our staff to own and drive their experience. Our vision for our business and customers is built on fostering a diverse and inclusive work environment where regardless of background or beliefs you feel able to be authentic and bring all your talent into play. We want to celebrate you being you (we are an equal opportunity employer

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technology Project Manager - Cyber Security
Technology Project Manager - Cyber Security

hardrockdigital • United States

Hybrid
USD 110,000 - 140,000
Hybrid/Remote working environment
Flexible vacation allowance
Competitive pay and benefits
Technology Project Manager - Cyber Security
Technology Project Manager - Cyber Security

Hard Rock Digital • United States

Hybrid
USD 90,000 - 130,000
Competitive pay and benefits
Hybrid/remote work environment
Startup culture backed by a global, 24
Senior Engineer - DevOps
Senior Engineer - DevOps

Hard Rock Digital • United States

Hybrid
USD 160,000 - 210,000
Hybrid/Remote work options
Competitive compensation
Senior Cloud, Network & Edge Security Architect
Senior Cloud, Network & Edge Security Architect

Hard Rock Digital • United States

Hybrid
USD 160,000 - 210,000
Competitive pay and benefits
Hybrid / remote working environment
Startup culture backed by a secure, go
+1
Staff/Principal Software Engineer - Security Platform
Staff/Principal Software Engineer - Security Platform

Cloudflare • New York (NY)

On-site
USD 185,000 - 275,000
Medical/Rx Insurance
401(k) Retirement Savings Plan
Flexible paid time off
Senior Product Security Engineer
Senior Product Security Engineer

Cloudflare • Austin (TX)

On-site
USD 180,000 - 230,000
Equity plan
Health insurance
401(k) Retirement Savings Plan
+1
Staff/Principal Software Engineer - Security Platform
Staff/Principal Software Engineer - Security Platform

Cloudflare • San Francisco (CA)

On-site
USD 220,000 - 303,000
Equity
Health insurance
401(k) Retirement Savings Plan
+1
Principal Software Engineer, Workers Deploy & Config
Principal Software Engineer, Workers Deploy & Config

Cloudflare • United States

On-site
USD 220,000 - 303,000
Health Insurance
Dental Insurance
Vision Insurance
+11
Network Security Software Engineer
Network Security Software Engineer

Lumindigital • United States

On-site
USD 110,000 - 140,000
Medical, dental, and vision insurance
401(k) with company match
Flexible PTO and 12 paid holidays
Systems Engineer, Product Platform Tools
Systems Engineer, Product Platform Tools

Cloudflare • Austin (TX)

On-site
USD 140,000 - 190,000