Senior Cloud Security Engineer

Talentify

Malvern (Chester County)

Hybrid

USD 140,000 - 200,000

Full time

48 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

Vanguard is seeking a Senior Cloud Security Architect to own the technical architecture for CSPM tooling, automation platforms, and integration frameworks, ensuring scalable, reliable security across thousands of cloud accounts.

You will design system-level patterns, drive architectural decisions, and lead auto-remediation and shift-left initiatives at enterprise scale. Hybrid work is supported, with collaboration across Platform, DevOps, SRE, and security teams.

Qualifications

  • Minimum of five years related work experience required, with two years experience in cloud security preferred.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.
  • Proficiency in Python, Go or TypeScript - production-grade, not just scripting
  • Strong background in distributed systems concepts: event-driven architectures, async processing, API design, observability
  • Hands-on experience across at least one of: AWS, GCP, Azure — at the level of org-wide account structures, landing zones, and cross-account security patterns and IAM at scale.
  • Track record of influencing technical direction beyond your immediate team

Responsibilities

  • Defines and owns the technical architecture for CSPM tooling, automation platforms, and integration frameworks — ensuring they scale reliably across thousands of cloud accounts and multiple business units.
  • Designs system-level patterns (event-driven pipelines, API contracts, data models) that other engineers build on — establishing the foundational approach for how security findings flow from detection through prioritization to remediation.
  • Drives architectural decisions on platform extensibility, service boundaries, and data ownership — balancing near-term delivery against long-term maintainability as the program grows.
  • Architects auto-remediation and shift-left enforcement systems that operate at org scale — designing for fault tolerance, auditability, and graceful degradation when upstream systems change.
  • Evaluates and selects tooling, frameworks, and integration patterns that the broader team adopts — owning the technical standards for how CSPM systems connect to enterprise infrastructure (CI/CD, CMDB, ITSM, identity providers).
  • Partners with engineering leadership across Platform, DevOps, SRE, and application security teams to align on shared interfaces, data contracts, and remediation workflows that reduce friction at organizational boundaries.
  • Leads technical design reviews and mentors engineers on the team — raising the bar on code quality, system thinking, and operational readiness.
  • Shapes the technical roadmap for AI-assisted security capabilities — evaluating where machine learning and LLM-based automation can meaningfully reduce risk or operational burden, and architecting the systems to deliver them.

Skills

Python
Go
TypeScript
Event-driven architectures
API design
Observability
Distributed systems
Cloud security
AWS
GCP/Azure

Education

Bachelor's degree in Computer Science or related field

Tools

CI/CD
CMDB
ITSM
Identity providers

Job description

Open — Vanguard has a posting for this job. Posted 28 Sep 2026.

This posting

Opens vanguard.wd5.myworkdayjobs.com. Talentify has not checked who owns that address. You apply there — Talentify never asks for an account or a CV.

About this job

Core Responsibilities

  • Defines and owns the technical architecture for CSPM tooling, automation platforms, and integration frameworks — ensuring they scale reliably across thousands of cloud accounts and multiple business units.
  • Designs system-level patterns (event-driven pipelines, API contracts, data models) that other engineers build on — establishing the foundational approach for how security findings flow from detection through prioritization to remediation.
  • Drives architectural decisions on platform extensibility, service boundaries, and data ownership — balancing near-term delivery against long-term maintainability as the program grows.
  • Architects auto-remediation and shift-left enforcement systems that operate at org scale — designing for fault tolerance, auditability, and graceful degradation when upstream systems change.
  • Evaluates and selects tooling, frameworks, and integration patterns that the broader team adopts — owning the technical standards for how CSPM systems connect to enterprise infrastructure (CI/CD, CMDB, ITSM, identity providers).
  • Partners with engineering leadership across Platform, DevOps, SRE, and application security teams to align on shared interfaces, data contracts, and remediation workflows that reduce friction at organizational boundaries.
  • Leads technical design reviews and mentors engineers on the team — raising the bar on code quality, system thinking, and operational readiness.
  • Shapes the technical roadmap for AI-assisted security capabilities — evaluating where machine learning and LLM-based automation can meaningfully reduce risk or operational burden, and architecting the systems to deliver them.

Qualifications

  • Minimum of five years related work experience required, with two years experience in cloud security preferred.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.
  • Proficiency in Python, Go or TypeScript - production-grade, not just scripting
  • Strong background in distributed systems concepts: event-driven architectures, async processing, API design, observability
  • Hands-on experience across at least one of: AWS, GCP, Azure — at the level of org-wide account structures, landing zones, and cross-account security patterns and IAM at scale.
  • Track record of influencing technical direction beyond your immediate team

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

The Vanguard Group • Malvern

Hybrid
USD 150,000 - 210,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Vanguard • Dallas (TX)

Hybrid
USD 170,000 - 210,000
Cloud Security Engineering Manager
Cloud Security Engineering Manager

Vanguard • Dallas (TX)

Hybrid
USD 140,000 - 180,000
Hybrid work model
401(k) matching
Career development
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Vanguard • Charlotte (NC)

On-site
USD 150,000 - 210,000
Cloud Engineering, Senior Specialist
Cloud Engineering, Senior Specialist

The Vanguard Group • Dallas (TX)

On-site
USD 120,000 - 170,000
Application Security, Specialist
Application Security, Specialist

The Vanguard Group • Malvern

On-site
USD 120,000 - 190,000
Cloud Engineering Manager
Cloud Engineering Manager

Vanguard • Dallas (TX)

Hybrid
USD 150,000 - 190,000
Cloud Security Engineering Manager
Cloud Security Engineering Manager

Vanguard • Malvern

On-site
USD 140,000 - 200,000
Identity Security MultiCloud Analyst Vanguard · Charlotte, TX + 1 more Full-time · Hybrid — 4 hours ago
Identity Security MultiCloud Analyst Vanguard · Charlotte, TX + 1 more Full-time · Hybrid — 4 hours ago

Emploive • Dallas, Northern (KY)

Hybrid
USD 105,000 - 145,000
Senior Application Security Engineer
Senior Application Security Engineer

Vanguard • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Hybrid work model