Senior Cloud Security Engineer

Aurora

Mountain View (CA)

On-site

USD 162,000 - 235,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

I did my part and supported the Regular Toilet is seeking a Senior Engineer to lead the design and implementation of core security infrastructure. You will tackle complex challenges in AWS, enhancing security protocols for various services.

This role requires a deep understanding of cloud security practices, identity management, and automation frameworks. The expected salary is competitive, with eligibility for bonuses and benefits.

Qualifications

  • 5+ years of experience in software, platform, or security engineering, with 3+ years in AWS security.
  • Proven ability to navigate organizational friction for risk management.
  • Expertise in IAM, VPC Networking, Security Hub, Config, GuardDuty, and KMS.
  • Design and implement security controls for Kubernetes (EKS).
  • Strong proficiency in Python or Go for security automation.

Responsibilities

  • Own the design and implementation of core security infrastructure services.
  • Manage security boundaries and access controls for AWS environment.
  • Develop systems for continuous security control monitoring and remediation.
  • Serve as a key security consultant for engineering teams.
  • Lead threat modeling exercises for critical systems.

Skills

AWS Security Specialization
Security Automation
IAM Management
Network Security
Kubernetes Security
Threat Modeling
Infrastructure as Code (IaC)
Programming (Python/Go)

Tools

Terraform
PKI
GuardDuty
Security Hub

Job description

Aurora’s mission is to deliver the benefits of self-driving technology safely, quickly, and broadly.

The Aurora Driver will create a new era in mobility and logistics, one that will bring a safer, more efficient, and more accessible future to everyone.

At Aurora, you will tackle massively complex problems alongside other passionate, intelligent individuals, growing as an expert while expanding your knowledge.

As a Senior Engineer, you will own the design and implementation of key security infrastructure, serving as a key technical contributor and mentor within the security team and across engineering.

Responsibilities
  • Own the design and implementation of core security infrastructure services, including certificate management (PKI), secrets management, and centralized authentication/authorization services leveraging standards like OIDC and SAML.
  • Deep AWS Security Specialization: Architect and manage security boundaries and access controls for the entire AWS environment, including but not limited to:
    • IAM Governance: Define and enforce least-privilege IAM roles and policies, establish strong IAM Access Boundaries using Service Control Policies (SCPs), and govern inter-service communication.
    • Network Segmentation: Design and implement robust network security controls within VPCs, including Security Groups, Network ACLs, and private connectivity (VPC Endpoints, Transit Gateway).
  • Design and implement security best practices and tooling within AWS and EKS, including controls such as admission controllers, image scanning/signing, pod security standards, and runtime security enforcement.
  • Develop and manage systems for continuous security control monitoring, reporting, and automated remediation (e.g., using AWS Config, GuardDuty, or custom tools).
  • Develop threat models independently, or jointly with system owners. Translate identified threats into tangible security requirements, ensuring controls are strategically deployed to strengthen the security posture of core platforms and services.
  • Serve as a key security consultant to product and platform engineering teams, conducting in-depth security design reviews for new systems and features, and proposing actionable security control implementations.
In this role, you will:
  • Design, implement, and maintain the next generation of security infrastructure, controls, and primitives natively within AWS and across our Kubernetes (EKS) platform.
  • Define Security as Code: Drive the adoption of Infrastructure as Code (IaC) principles (e.g., Terraform) to codify, deploy, and continuously monitor security controls and policies in an auditable and scalable manner.
  • Strategic Threat Modeling: Lead threat modeling exercises for critical systems and architectures, translating risks into prioritized security requirements and verifiable controls.
  • Architectural Guidance: Provide security guidance and consulting for product and platform engineering teams, conducting in-depth security design reviews and providing pragmatic, hands‑on recommendations for securing complex microservice architectures.
  • Automate Remediation: Identify systemic security weaknesses and create robust, scalable automation (e.g., Python/Go‑based tools, Lambda functions, EKS controllers) to eliminate classes of vulnerabilities at the source.
Required Qualifications
  • 5+ years of progressive experience in software, platform, or security engineering, with a minimum of 3+ years focusing exclusively on public cloud security (AWS required).
  • Experience in identifying and managing security risk, and the ability to navigate the organizational friction to manage these risks.
  • Expert‑level, hands‑on experience securing and operating complex environments in AWS, including expertise with IAM, VPC Networking, Security Hub, Config, GuardDuty, and KMS.
  • Proven ability to design and implement security controls for Kubernetes (EKS), including strong knowledge of authorization models, admission controllers, and security best practices.
  • Expertise in one or more Identity and Access Management (IAM) standards and technologies: PKI, OAuth2/OIDC, SAML, and commercial solutions like Okta.
  • Strong proficiency in at least one modern programming/scripting language (e.g., Python or Go) for building security automation, tools, and remediation services.
  • Experience writing, reviewing, and scaling infrastructure with Terraform.
Desirable Qualifications
  • Deep fundamental understanding of enterprise‑level network security, operating system security (Linux), and application security principles.
  • Experience implementing DevSecOps practices, including integration of security testing (SAST/DAST/SCA) into CI/CD pipelines (e.g., GitLab, Jenkins).
  • Familiarity with compliance frameworks (e.g., SOX, SOC 2, ISO 27001).
Compensation

The base salary range for this position is $162,000 - $235,000 per year. Aurora’s pay ranges are determined by role, level, and location. Within the range, the successful candidate’s starting base pay will be determined based on factors including job‑related skills, experience, qualifications, relevant education or training, and market conditions. These ranges may be modified in the future. The successful candidate will also be eligible for an annual bonus, equity compensation, and benefits.

Aurora considers candidates without regard to their race, color, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, pregnancy status, parent or caregiver status, ancestry, political affiliation, veteran and/or military status, physical or mental disability, or any other status protected by federal or state law. Aurora considers qualified applicants with criminal histories, consistent with applicable federal, state, and local law. We are also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at careersiteaccommodations@aurora.tech.

For California applicants, information collected and processed as part of your application and any job applications you choose to submit is subject to Aurora’s California Employment Privacy Policy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Aurora Innovation • San Francisco (CA)

Hybrid
USD 162,000 - 235,000
Annual bonus
Equity compensation
Benefits
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Aurora • Seattle (WA)

Hybrid
USD 146,000 - 235,000
Annual bonus
Equity compensation
Benefits package
+1
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Australian Competition and Consumer Commission • Northern (KY)

Hybrid
USD 146,000 - 235,000
Annual bonus
Equity compensation
Benefits
Staff Security Engineer
Staff Security Engineer

Aurora • Seattle (WA)

Hybrid
USD 189,000 - 274,000
Annual bonus
Equity compensation
Comprehensive benefits package
Staff Security Engineer, Enterprise Security Architecture
Staff Security Engineer, Enterprise Security Architecture

SwiftCruit • Pittsburgh

On-site
USD 171,000 - 273,000
Annual bonus
Equity compensation
Benefits package
Staff Security Engineer, Enterprise Security Engineering
Staff Security Engineer, Enterprise Security Engineering

Aurora Innovation • Detroit (MI)

On-site
USD 171,000 - 273,000
Annual bonus
Equity compensation
Comprehensive benefits
Staff Security Engineer, Enterprise Security Architecture
Staff Security Engineer, Enterprise Security Architecture

Aurora Innovation • Fort Worth (TX), Town of Texas (WI)

On-site
USD 171,000 - 273,000
Annual bonus
Equity compensation
Comprehensive benefits
Staff Security Platform Engineer
Staff Security Platform Engineer

Aurora • Mountain View (CA)

On-site
USD 189,000 - 274,000
Bonus
Equity compensation
Health benefits
Staff Security Engineer
Staff Security Engineer

Aurora • Pittsburgh

On-site
USD 171,000 - 247,000
Annual bonus
Equity compensation
Comprehensive benefits
Staff Security Engineer, Enterprise Security Architecture
Staff Security Engineer, Enterprise Security Architecture

Aurora Innovation • San Francisco (CA)

On-site
USD 189,000 - 303,000
Annual bonus
Equity compensation
Comprehensive benefits