Security Engineer, Cloud Security

Saronic

San Diego (CA)

On-site

USD 140,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Saronic is seeking a Security Engineer to own cloud security posture across a multi-account AWS environment, including GovCloud. You will design secure-by-default patterns, build guardrails, and automate evidence for audits. Collaborate across security, IT, and engineering teams to ship features securely.

The role emphasizes automation, scalable CSPM, and proactive remediation, with strong emphasis on IAM, GuardDuty, Config, and third‑party tooling.

Qualifications

  • 3+ years hands-on cloud security, infrastructure security, or DevSecOps experience.
  • Experience building guardrails and automation to enforce secure-by-default patterns.
  • Ability to design and implement multi-account CSPM with remediation and evidence for audits.

Responsibilities

  • Own continuous cloud security posture across commercial AWS and GovCloud.
  • Develop reusable guardrails and policy-as-code to prevent misconfigurations.
  • Lead threat detection, incident response, and automated remediation with cloud-native tools.

Skills

Cloud security
Security automation
AWS security
IAM least-privilege
Terraform
Threat detection

Tools

Terraform
Prowler
CloudTrail
GuardDuty
Config
Security Hub

Job description

  • Security at Saronic is a force multiplier, not a blocker. We’re looking for a Security Engineer for our Cloud Security team to own the continuous security posture of the cloud that runs an autonomous fleet across both commercial AWS and AWS GovCloud and to build the guardrails that let every team ship fast with security baked in from the start
  • You’ll design the secure-by-default patterns teams reach for on their own, treating repeat findings as a signal to build a control rather than re-answer a ticket, and prioritizing by real attack path rather than alert count
  • You’ll work alongside Product Security, Infrastructure, Software, Information Technology, Enterprise Technology, and Internal Applications to keep a multi-account cloud environment secure, compliant, and auditable across its full lifecycle
  • This is an opportunity to own cloud security posture across commercial and GovCloud, build guardrails that speed engineering up rather than slow it down, turn compliance into automated and continuous evidence, and work with strong engineers in a high-trust, low-ego environment
  • Posture & Compliance: Own continuous cloud security posture management (CSPM) across all cloud accounts, detect misconfigurations and drift, and drive remediation with the teams that own the resources. Map technical controls to both government and commercial frameworks (CMMC, NIST SP 800-171, FedRAMP/IL baselines) and keep controls evidence current and audit-ready
  • Cloud Vulnerability Management: Run cloud vulnerability management at scale, find issues, prioritize them by real attack path and exposure rather than raw CVSS, and drive remediation to closure. Use tooling such as Prowler and a CNAPP, and automate remediation wherever possible
  • Guardrails & Secure-by-Default: Build reusable Terraform modules, Service Control Policies, permission boundaries, and policy-as-code that make the secure path the easy path, so whole classes of misconfiguration disappear before they reach production. Replace manual security gates with automated, self-service guardrails
  • Identity, Secrets & Data Protection: Design least-privilege IAM across accounts and workloads, hunt privilege-escalation and cross-account trust paths, govern secrets management, and standardize encryption and key-management patterns
  • Detection, Response & SOC Support: Build and tune cloud-native detections (CloudTrail, GuardDuty, Config, Security Hub) and automated remediation, and support the Security Operations team as they investigate, triage, and remediate cloud-related cases across our infrastructure, including credential compromise, exposed resources, and data exfiltration, reconstructing activity from logs and automating containment. Feed every incident back into new guardrails and detections

Strong infrastructure-as-code (Terraform) and policy-as-code experience3+ years of hands‑on cloud security, infrastructure security, or DevSecOps experience, or an equivalent combination of experience and demonstrated abilityHands‑on cloud vulnerability management and CSPM tooling (e.g., Prowler), with a track record of driving cloud findings to remediationAbility to obtain and maintain a U.S. security clearanceProficiency in scripting for security automationDepth in AWS security services and architecture (IAM, Organizations/SCPs, CloudTrail, Config, GuardDuty, Security Hub, KMS, VPC)A track record of building guardrails or patterns that other teams adopted without frictionVisual acuity to read screens, documents, and reportsManual dexterity to operate a computer keyboard, mouse, and other office equipmentLifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)Prolonged periods of sitting at a desk and working on a computerOccasional standing and walking within the officeOccasional reaching, bending, or stooping to access file drawers, cabinets, or office suppliesExperience in AWS GovCloud, FedRAMP, or IL4/IL5 environmentsAzure and on‑prem security experience a plusMulti‑account landing‑zone and organizational security designCSPM with automated remediation at scaleContainer or Kubernetes securityIAM attack‑path analysis and outcome‑based metricsExperience in defense, aerospace, robotics, or other high‑assurance environmentsFamiliarity with NIST SP 800-171/800-53If this role is based in the United States, it requires access to export‑controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3)This role requires an active U.S. security clearance or eligibility for a U.S. security clearance. Based on guidance from the U.S. Government, only U.S. citizens are eligible for U.S. security clearance, and the U.S. Government may request that you renounce other citizenship in order to obtain and maintain a security clearance

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Cloud Security
Security Engineer, Cloud Security

Saronic Technologies • San Diego (CA)

On-site
USD 120,000 - 180,000
Medical Insurance
Dental and Vision Insurance
401(k) Plan with company match
+6
Security Engineer, Cloud Security
Security Engineer, Cloud Security

Saronic Technologies • Austin (TX)

On-site
USD 140,000 - 210,000
Medical Insurance
Dental and Vision Insurance
Time Off
+8
Security Engineer, Application Security
Security Engineer, Application Security

Saronic Technologies • San Diego (CA)

On-site
USD 120,000 - 160,000
Cloud Security Engineer: Guardrails, CSPM & GovCloud
Cloud Security Engineer: Guardrails, CSPM & GovCloud

Saronic Technologies • San Diego (CA)

On-site
USD 120,000 - 180,000
Medical Insurance
Dental and Vision Insurance
401(k) Plan with company match
+6
Senior DevSecOps Engineer, GovCloud & Compliance
Senior DevSecOps Engineer, GovCloud & Compliance

United States Digital Space LLC • United States

Remote
USD 170,000 - 185,000
Medical, dental, vision
Generous PTO
Remote work within United States
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Security Engineer, Application Security
Security Engineer, Application Security

Saronic Technologies • Austin (TX)

On-site
USD 120,000 - 180,000
Principal Compliance Engineer
Principal Compliance Engineer

True Anomaly • Colorado

On-site
USD 195,000 - 270,000
Health insurance
Dental insurance
Vision insurance
+2
Security Engineer, Application Security
Security Engineer, Application Security

Saronic Technologies Inc. • Town of Texas (WI)

On-site
USD 120,000 - 150,000
Cloud Security Engineer: Guardrails, CSPM & AWS Expertise
Cloud Security Engineer: Guardrails, CSPM & AWS Expertise

Saronic Technologies • Austin (TX)

On-site
USD 140,000 - 210,000
Medical Insurance
Dental and Vision Insurance
Time Off
+8