Senior Cloud Security Engineer

Black-Duck-Software

Belfast (ME)

On-site

USD 130,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Black Duck Software, Inc. is seeking a Cloud Security Subject Matter Expert to define and maintain security baselines across our SaaS platforms. You will shape security posture, develop and implement cloud security standards, and collaborate with engineering and IT to drive DevSecOps maturity.

Responsibilities include designing and operating controls on AWS, GCP, and other clouds, monitoring risks, leading incident response, and mentoring engineers in threat modeling and secure coding practices.

Qualifications

  • 5–7+ years of information security experience with cloud security.
  • Hands-on securing cloud environments (AWS, GCP, Azure) at scale.
  • Bachelor’s degree or equivalent practical experience.
  • Experience with containerized/Kubernetes platforms and cloud monitoring.
  • Proficiency in Python or Bash for security automation; IaC with Terraform/CloudFormation/Helm.
  • Ability to lead projects and coordinate cross-functional teams.

Responsibilities

  • Design, build, and operate cloud security controls for SaaS on AWS, GCP, and other clouds.
  • Monitor cloud resources and triage findings; drive remediation with owners.
  • Lead containment and incident response for cloud security events.
  • Integrate security into CI/CD pipelines and DevSecOps practices.
  • Communicate risks and recommendations to executives.
  • Coach engineers and lead security reviews and threat modeling.

Skills

Cloud security
Python scripting
Leadership
Threat modeling

Education

Bachelor’s degree in Information Security or Computer Science

Tools

Kubernetes
Terraform
CloudFormation
Helm
CSPM/CNAPP tools

Job description

Black Duck Software, Inc. helps organizations build secure, high‑quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry‑leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.

Responsibilities
  • Act as Cloud Security Subject Matter Expert (SME); develop and maintain cloud security standards, policies, procedures, and best‑practice documentation defining Black Duck’s cloud security baseline.
  • Design, build, and operate security controls for SaaS services running on AWS, GCP, and other cloud environments.
  • Continuously monitor cloud resources and configurations to identify security risks; triage findings and drive remediation with resource owners.
  • Identify threats through vulnerability assessments, penetration testing support, and log analysis; ensure security controls meet compliance requirements including SOC 2 and ISO 27001.
  • Automate cloud security controls, data collection, and workflows using Python, Bash, cloud APIs, and infrastructure as code to improve operational efficiency and scale coverage.
  • Operate and enhance the cloud security tooling ecosystem, including logging, monitoring, CSPM/CNAPP, vulnerability management, and detection platforms.
  • Integrate security controls into CI/CD pipelines and engineering delivery workflows, advancing DevSecOps practices across the organization.
  • Lead containment, forensic analysis, and remediation for cloud security incidents in partnership with CSIRT and engineering teams.
  • Lead cloud security projects and major components of complex, cross‑functional initiatives; influence cloud security architecture and strategy decisions across engineering, platform, and IT organizations.
  • Design and improve cloud security processes and operational procedures to systematically reduce risk and increase organizational efficiency.
  • Communicate cloud security risks, findings, and recommendations to Director‑ and VP‑level stakeholders.
  • Serve as a technical leader and coach for less experienced engineers; lead and participate in security reviews, threat modeling sessions, and architecture discussions.
  • Negotiate and build consensus across engineering, platform, IT, and vendor partners; explain difficult or sensitive security information clearly to technical and non‑technical audiences, including executives.
  • Other tasks and activities as assigned.
Qualifications
  • 5–7+ years of experience in information security with demonstrated depth in cloud security; minimum 3 years of hands‑on experience securing cloud environments (AWS, GCP, Azure, or equivalent) at scale.
  • Bachelor’s degree in Information Security, Computer Science, or a related field, or equivalent practical experience.
  • Specialized knowledge of cloud security principles, architectures, and controls with depth in at least one major cloud provider.
  • Hands‑on experience with containerized and Kubernetes‑based platforms; experience with cloud security monitoring, logging, and CSPM/CNAPP tools; demonstrated ability to design, implement, and operate security controls at scale.
  • Strong experience with Python and/or Bash scripting for security automation, tooling, and integration; proficiency with infrastructure as code technologies such as Terraform, CloudFormation, or Helm.
  • Proven ability to lead projects and coordinate cross‑functional teams; track record of designing process improvements and systematic changes that improve team or organizational outcomes.
Equal Employment Opportunity

Black Duck is an equal opportunity employer. We consider all applicants for employment without regard to race, color, national origin, religion, sex, gender identity or expression, age, disability, sexual orientation, veteran or military service status, or any other characteristic protected by applicable law. Black Duck complies with all applicable laws prohibiting employment discrimination in every jurisdiction where it operates and provides reasonable accommodations to individuals with disabilities in accordance with applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer: DevSecOps Leader
Senior Cloud Security Engineer: DevSecOps Leader

Black-Duck-Software • Belfast (ME)

On-site
USD 130,000 - 180,000
Senior DevOps Engineer - Cloud Operations
Senior DevOps Engineer - Cloud Operations

Francisco Partners • Burlington (MA)

On-site
USD 135,000 - 168,000
DevOps Engineer 3 (Sr DevSec Engineer)
DevOps Engineer 3 (Sr DevSec Engineer)

Francisco Partners • Burlington (MA)

On-site
USD 135,000 - 180,000
Senior Cloud DevSecOps Engineer (GCP)
Senior Cloud DevSecOps Engineer (GCP)

Francisco Partners • Burlington (MA)

On-site
USD 135,000 - 180,000
Senior DevOps Engineer - Cloud Operations
Senior DevOps Engineer - Cloud Operations

jobr.pro • Burlington (MA)

On-site
USD 135,000 - 168,000
DevOps Engineer 3 (Sr DevSec Engineer)
DevOps Engineer 3 (Sr DevSec Engineer)

Blackduck • Burlington (MA)

On-site
USD 135,800 - 180,000
DevOps Engineer 3 (Sr DevSec Engineer)
DevOps Engineer 3 (Sr DevSec Engineer)

Black Duck Software, Inc. • Burlington (MA)

On-site
USD 135,000 - 180,000
Senior DevSec Cloud Engineer—GCP Automation & Reliability
Senior DevSec Cloud Engineer—GCP Automation & Reliability

Blackduck • Burlington (MA)

On-site
USD 135,800 - 180,000
Lead Solutions Architect (East Coast)
Lead Solutions Architect (East Coast)

Black Duck Software, Inc. • Massachusetts

Hybrid
USD 123,000 - 186,000
Annual Performance Bonus
Paid Vacation and Wellness Days
Group Retirement Savings Plans
+1
Sr. Manager, Sales Engineering (Enterprise, West Coast)
Sr. Manager, Sales Engineering (Enterprise, West Coast)

Francisco Partners • United States

Hybrid
USD 173,000 - 261,000