Senior Engineer, Cloud Security

Workstreet

Northern (KY)

Hybrid

USD 140,000 - 190,000

Full time

4 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote-first culture
Mentorship & training
Competitive compensation
Growth opportunities
Flexible scheduling

Job summary

Workstreet is seeking a Senior Engineer, Cloud Security who will build and scale secure cloud infrastructure across Azure and multi-cloud environments. You will design hardened landing zones, automate identity lifecycles, and author reusable Terraform modules rather than performing audits.

The role is hands-on with rapid client engagements, drift-resistant security, and a remote-first culture that supports collaboration across time zones. US ET hours are expected, with travel as needed.

Qualifications

  • Hands-on security builder with cloud infrastructure experience.
  • Deep expertise in Azure and AWS multi-cloud architectures.
  • Proficiency with IaC tools (Terraform, CloudFormation).
  • Strong knowledge of IAM, RBAC, and least-privilege access patterns.
  • Clear, technical communication and workshop facilitation.

Responsibilities

  • Design and maintain reusable Terraform/CloudFormation modules for IAM, networking, and logging.
  • Deploy and manage multi-account AWS structures and Azure Landing Zone architectures.
  • Implement least-privilege IAM and federated identity workflows.
  • Remediate cloud misconfigurations and automate patches.
  • Build automated security operations pipelines and integrate with CI/CD.
  • Configure native cloud security stacks (GuardDuty, Security Hub, Defender, etc.).
  • Design secure networking, encryption, and key management.

Skills

Security engineering
Cloud architecture
Terraform
IAM / RBAC
Technical communication
Multi-account management

Tools

Terraform
CloudFormation
Okta / Entra ID

Job description

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

Get to Know the Security Services Team

We are the team that turns complex security requirements and compliance frameworks into infrastructure and services that actually work. Moving fast and taking true end-to-end ownership, our team spans three core functions: Cloud Security Engineering , where we design hardened AWS, Azure, and GCP environments, write Terraform baselines, and fix failing controls to meet frameworks like SOC 2, ISO 27001, CMMC, and FedRAMP; Penetration Testing , where we run disciplined offensive assessments across networks, apps, cloud, and AI/LLM systems to catch vulnerabilities before adversaries do; and Vulnerability Management , where we continuously prioritize, patch, and validate risk reduction across the client footprint. We do not hide behind process or just point out gaps. We step in, build solutions, and deliver real security posture improvements with minimal disruption.

What makes this team special isn’t just our technical depth; it is how we back each other up. Our strongest engineers and assessors are the ones building reusable modules, writing custom tools, jumping into channels to unblock teammates, and mentoring without being asked. From early-stage startups to regulated enterprises, you will work directly with clients, take on real ownership early, and be surrounded by people who want to see you get good. If you enjoy solving tough security problems and want to be part of a team that is scrappy enough to move fast but seasoned enough to get it right, you will be in good company here.

The Opportunity

Workstreet is seeking a Senior Engineer, Cloud Security who is a builder at heart with deep technical expertise in cloud infrastructure engineering, with a strong emphasis on Azure and multi-cloud architectures. This is a hands-on, high-impact engineering role focused on designing and deploying security infrastructure, building hardened landing zones, automating identity lifecycles, and authoring reusable Terraform modules rather than performing audit assessments.

The successful candidate will integrate rapidly into client environments, taking direct ownership of cloud security engineering tasks, vulnerability remediation, and client engagements within their first 15 days. Working directly with client engineering leads during U.S. Eastern Time business hours, you will lead technical discussions, execute automated security operations, and ensure every environment achieves drift-resistant, code-defined security excellence.

What You'll Do
  • Engineer security via Infrastructure as Code - design and maintain reusable Terraform and CloudFormation modules for IAM, networking, and logging to build drift-resistant cloud environments.
  • Build enterprise cloud architectures - deploy and manage AWS multi-account structures including Organizations and SCPs, alongside Azure Hub-Spoke and Landing Zone architectures.
  • Architect identity and access management - implement least-privilege IAM using RBAC, ABAC, permission boundaries, JIT or PIM automation, and federated identity via Okta or Entra ID.
  • Execute direct vulnerability remediation - remediate cloud misconfigurations through active engineering changes, automated patching, and configuration drift correction.
  • Automate security operations and pipelines - build automated remediation workflows using Lambda, Azure Functions, and Python, integrating SAST, DAST, and secret scanning into GitHub Actions or Azure DevOps pipelines.
  • Configure native cloud security stacks - deploy and tune AWS GuardDuty, Security Hub, AWS Config, Azure Sentinel, and Defender for Cloud to build native logging pipelines for SIEM ingestion.
  • Manage network and encryption engineering - design VPCs, security groups, network segmentation, WAFs, and full-lifecycle encryption using AWS KMS and Azure Key Vault.
  • Implement technical NIST 800-53 controls - translate NIST 800-53, FedRAMP, and CMMC compliance criteria into hands-on technical controls across cloud environments.
  • Drive client-facing technical ownership - interface directly with client engineering teams, lead architectural workshops, and manage multiple client engagements simultaneously.
Who You Are
  • Hands-on security builder - proven track record of deploying security infrastructure, writing OPA policies, and managing secrets in Vault or AWS Secrets Manager.
  • Cloud-native technical specialist - deep expertise in Azure and AWS nuances, capable of distinguishing compliance maps from functional technical controls.
  • Infrastructure as Code expert - proficient in Terraform, with demonstrated expertise in module versioning, state management, and provider security controls.
  • Identity and access authority - deep technical understanding of SAML, OIDC, cross-account IAM roles, and enforcing least privilege without disrupting developer workflows.
  • Articulate technical communicator with a strong verbal presence, able to lead technical workshops and clearly explain complex architecture to engineering teams.
  • Multi-account portfolio operator - thrives in fast-paced startup environments, balancing multiple client priorities and executing rapid remediation without perfect documentation.
What will help you succeed
  • Active cloud security credentials - hold technical certifications such as AWS Certified Security Specialty, Azure Security Engineer Associate, or GCP Professional Security Engineer.
  • FIPS 140 encryption implementation : practical experience configuring and enforcing FIPS 140 standards across cloud services.
  • Federal enclave build experience - hands-on history building CMMC-compliant enclaves or FedRAMP security architectures.
  • Container runtime security mastery - experience implementing runtime security controls and vulnerability scanning across containerized environments.
What We Offer
  • Career Development : Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity : Early-stage company with significant room for career advancement.
  • Remote-First Culture : Flexibility to work from anywhere while collaborating with a global team.
What You'll Need to Thrive
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.
Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.

All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact accommodationsus@workstreet.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Engineer - GOV (FedRAMP 20x)
Senior GRC Engineer - GOV (FedRAMP 20x)

Workstreet • Northern (KY)

Hybrid
USD 150,000 - 210,000
Career development
Training reimbursement
Competitive compensation
+2
GRC Engineer I
GRC Engineer I

Workstreet • United States

On-site
USD 70,000 - 110,000
Remote-First Culture
Career Development
Training reimbursement
Manager, GRC Engineering
Manager, GRC Engineering

Workstreet • Northern (KY)

Hybrid
USD 150,000 - 190,000
Career Development
Role-Related Training
Competitive Compensation
+2
GRC Engineer (NIST)
GRC Engineer (NIST)

Workstreet • Northern (KY)

Hybrid
USD 90,000 - 130,000
Remote-first culture
GRC Engineer (CMMC)
GRC Engineer (CMMC)

Workstreet • Northern (KY)

Hybrid
USD 120,000 - 180,000
Remote-first culture
Career development
Training reimbursement
Senior Manager, GRC Engineering
Senior Manager, GRC Engineering

Workstreet, Inc. • United States

On-site
USD 110,000 - 150,000
Career Development
Technical Training
Competitive Compensation
+2
GRC Engineer (NIST)
GRC Engineer (NIST)

Jobless • Northern (KY)

Hybrid
USD 90,000 - 130,000
Career Development
Role-Related Training
Competitive Compensation
+2
Senior Cybersecurity Engineer (US Federal)
Senior Cybersecurity Engineer (US Federal)

Workday • Reston (VA)

On-site
USD 159,000 - 240,000
Senior Cybersecurity Engineer - US Federal
Senior Cybersecurity Engineer - US Federal

Workday • Reston (VA)

Hybrid
USD 160,000 - 239,000
Marketing Manager
Marketing Manager

Jobless • Northern (KY)

Hybrid
USD 65,000 - 100,000
Remote-First Culture
Career Development
Competitive Compensation