Senior Cloud Security Engineer

Vanguard

Malvern (Chester County)

On-site

USD 190,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Vanguard is seeking a senior Cloud Security Architect to define and own the technical architecture for CSPM tooling and automation platforms across thousands of cloud accounts. You will design system-level patterns for secure data flows, drive platform extensibility decisions, and shape the AI-assisted security roadmap for enterprise-scale systems.

You will collaborate with Platform, DevOps, and SRE teams to set technical standards, mentor engineers, and ensure fault-tolerant, auditable

Qualifications

  • Minimum of five years related work experience, with two years experience in cloud security preferred.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.
  • Production-grade proficiency in Python, Go or TypeScript.
  • Strong background in distributed systems concepts: event-driven architectures, async processing, API design, observability.
  • Hands-on experience across at least one of: AWS, GCP, Azure — at the level of org-wide account structures, landing zones, and cross-account security patterns and IAM at scale.
  • Track record of influencing technical direction beyond your immediate team.

Responsibilities

  • Defines and owns the technical architecture for CSPM tooling, automation platforms, and integration frameworks — ensuring they scale reliably across thousands of cloud accounts and multiple business units.
  • Designs system-level patterns (event-driven pipelines, API contracts, data models) that other engineers build on — establishing the foundational approach for how security findings flow from detection through prioritization to remediation.
  • Drives architectural decisions on platform extensibility, service boundaries, and data ownership — balancing near-term delivery against long-term maintainability as the program grows.
  • Architects auto-remediation and shift-left enforcement systems that operate at org scale — designing for fault tolerance, auditability, and graceful degradation when upstream systems change.
  • Evaluates and selects tooling, frameworks, and integration patterns that the broader team adopts — owning the technical standards for how CSPM systems connect to enterprise infrastructure (CI/CD, CMDB, ITSM, identity providers).
  • Partners with engineering leadership across Platform, DevOps, SRE, and application security teams to align on shared interfaces, data contracts, and remediation workflows that reduce friction at organizational boundaries.
  • Leads technical design reviews and mentors engineers on the team — raising the bar on code quality, system thinking, and operational readiness.
  • Shapes the technical roadmap for AI‑assisted security capabilities — evaluating where machine learning and LLM‑based automation can meaningfully reduce risk or operational burden, and architecting the systems to deliver them.

Skills

Python
Go
TypeScript
Distributed systems
Event-driven architectures
Async processing
API design
Observability
AWS
GCP
Azure

Education

Bachelor's degree or equivalent

Tools

AWS
GCP
Azure

Job description

Defines the architecture and technical direction for cloud security, improving posture and tooling at org scale — designing for automation, extensibility, and cross‑functional adoption while shaping the team's strategic roadmap.

Core Responsibilities
  • Defines and owns the technical architecture for CSPM tooling, automation platforms, and integration frameworks — ensuring they scale reliably across thousands of cloud accounts and multiple business units.
  • Designs system‑level patterns (event‑driven pipelines, API contracts, data models) that other engineers build on — establishing the foundational approach for how security findings flow from detection through prioritization to remediation.
  • Drives architectural decisions on platform extensibility, service boundaries, and data ownership — balancing near‑term delivery against long‑term maintainability as the program grows.
  • Architects auto‑remediation and shift‑left enforcement systems that operate at org scale — designing for fault tolerance, auditability, and graceful degradation when upstream systems change.
  • Evaluates and selects tooling, frameworks, and integration patterns that the broader team adopts — owning the technical standards for how CSPM systems connect to enterprise infrastructure (CI/CD, CMDB, ITSM, identity providers).
  • Partners with engineering leadership across Platform, DevOps, SRE, and application security teams to align on shared interfaces, data contracts, and remediation workflows that reduce friction at organizational boundaries.
  • Leads technical design reviews and mentors engineers on the team — raising the bar on code quality, system thinking, and operational readiness.
  • Shapes the technical roadmap for AI‑assisted security capabilities — evaluating where machine learning and LLM‑based automation can meaningfully reduce risk or operational burden, and architecting the systems to deliver them.
Qualifications
  • Minimum of five years related work experience required, with two years experience in cloud security preferred.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.
  • Proficiency in Python, Go or TypeScript - production‑grade, not just scripting.
  • Strong background in distributed systems concepts: event‑driven architectures, async processing, API design, observability.
  • Hands‑on experience across at least one of: AWS, GCP, Azure — at the level of org‑wide account structures, landing zones, and cross‑account security patterns and IAM at scale.
  • Track record of influencing technical direction beyond your immediate team.
Sponsorship

Vanguard is not offering visa sponsorship for this position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Vanguard • Dallas (TX)

On-site
USD 180,000 - 240,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Vanguard • Charlotte (NC)

On-site
USD 180,000 - 240,000
Cloud Security Engineering Manager
Cloud Security Engineering Manager

Vanguard • Malvern

On-site
USD 140,000 - 190,000
Cloud Security Engineering Manager
Cloud Security Engineering Manager

Vanguard • Dallas (TX)

On-site
USD 140,000 - 190,000
Senior Cloud Security Architect
Senior Cloud Security Architect

Compunnel, Inc. • New York (NY)

On-site
USD 130,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Dexian • Dublin (CA)

On-site
USD 180,000 - 240,000
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Jobtailor • Fort Mill (SC), Town of Texas (WI)

On-site
USD 120,000 - 170,000
Cloud Security Engineering Manager
Cloud Security Engineering Manager

CIBR Warriors • Malvern

On-site
USD 150,000 - 190,000
Cloud Security Engineer
Cloud Security Engineer

ALLTECH CONSULTING SVC INC • Alpharetta (GA)

On-site
USD 120,000 - 150,000