Senior Security Engineer - Cloud Security

PagerDuty

Atlanta (GA)

On-site

USD 170,000 - 210,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

PagerDuty, Inc. is seeking a Senior Security Engineer focused on Cloud Security (Platform, Identity & Cryptography). The role involves hardening AWS and Kubernetes environments, enforcing RBAC and policy controls, and leading encryption standards across a multi-account footprint.

Expect to shape security tooling and collaborate with AppSec and GRC teams. You will leverage SIEM and incident response practices, participate in on-call rotations, and contribute to automation with Terraform and

Qualifications

  • 5+ years as a Security Engineer in an AWS-native, microservice SaaS environment.
  • Deep, hands-on expertise securing Kubernetes and containerized environments - EKS, RBAC, Kubernetes admission control, network policy, and workload identity.
  • Container runtime and image security experience; familiarity with a service mesh such as Istio strongly preferred.
  • Strong, hands-on expertise in PKI and cryptography - certificate lifecycle/management, TLS/mTLS, key management and rotation (AWS KMS or similar HSM/KMS), and encryption-at-rest/in-transit standards.

Responsibilities

  • Harden PagerDuty's AWS and Kubernetes environments against CIS Benchmarks, DISA STIGs, and FedRAMP Moderate baselines across a multi-account, multi-org footprint.
  • Harden EKS clusters and the Istio service mesh against CIS Kubernetes Benchmark and NSA/CISA hardening guidance.
  • Design and enforce Kubernetes RBAC, least-privilege workload identity, and container supply-chain controls.
  • Own PKI and encryption standards across the environment and define the standards other teams build against.
  • Design and roll out SCP guardrails and least-privilege IAM/PAM across dozens of accounts and multiple orgs.
  • Automate security controls as code using Terraform and Python - including Kubernetes policy-as-code.

Skills

Kubernetes security
AWS security services
PKI & cryptography
Container security
Istio service mesh

Tools

Istio
KMS
Secrets Manager
GuardDuty
CloudTrail
Config

Job description

PagerDuty, Inc. (NYSE: PD) is the global leader in AI-first digital operations. By automatically detecting, diagnosing, and remediating issues, the PagerDuty Platform orchestrates AI agents and automated workflows with context from over 750 integrations. Trusted by approximately two-thirds of the Fortune 100 and nearly half of the Fortune 500, PagerDuty is the industry standard for organizations scaling resilient, autonomous operations. Notable customers include Chipotle, Cloudflare, Docusign, Fox, Nvidia, Salesforce, Spotify, Zoom and more. We are growing rapidly and hiring top talent with leading AI skills across engineering, sales, product, marketing, and beyond as we build the leading digital operations platform.

.

Senior Security Engineer - Cloud Security (Platform, Identity & Cryptography)

*This role will require 2 days per week in our Atlanta office...*

What you'll do
  • Harden PagerDuty's AWS and Kubernetes environments against CIS Benchmarks, DISA STIGs, and FedRAMP Moderate baselines across a multi-account, multi-org footprint - proving results through evidence, config-remediation tooling, and KPIs that track posture, identity, and encryption/PKI health so we know where we stand and where the gaps are.
  • Harden EKS clusters and the Istio service mesh against the CIS Kubernetes Benchmark, DISA Kubernetes STIG, and NSA/CISA hardening guidance.
  • Design and enforce Kubernetes RBAC, least-privilege workload identity, and container supply-chain controls (image provenance, admission control, runtime policy).
  • Own PKI and encryption standards across the environment - certificate lifecycle and management, KMS-backed key management and rotation, TLS/mTLS (including within the Istio mesh), and encryption-at-rest and in-transit requirements - and define the standards other teams build against.
  • Design and roll out Service Control Policy (SCP) guardrails and least-privilege IAM/PAM across dozens of accounts and multiple orgs.
  • Lean into AI to unlock efficiency and velocity - consume agentic tooling in day-to-day work and build lightweight agentic solutions that streamline repetitive security work: posture triage, threat modeling, risk assessment, incident enrichment and investigation, compliance-evidence generation, and detection tuning.
  • Shape detection strategy for the domains you own - Kubernetes/Istio, identity, and cryptography - authoring and tuning detections in our SIEM stack, defining what "good" coverage looks like for these domains, and threat hunting for container escape, lateral movement, anomalous mesh traffic, and identity or credential abuse.
  • Participate in the team's on-call rotation, triaging and dispositioning cloud and Kubernetes threat alerts and acting as Incident Lead during incidents - driving containment, blast-radius/exposure analysis, and post-incident review.
  • Automate security controls as code using Terraform and Python - including Kubernetes policy-as-code and tool-to-tool integrations that reduce manual work.
  • Partner closely with our AppSec and GRC teams - aligning platform controls with secure-development needs and translating hardening, identity, and encryption work into audit and compliance evidence.
Additional responsibilities
  • Mentor and guide teammates on platform, identity, and cryptography security practices, and contribute to roadmap and annual planning. At the senior end of this role, you'll help draft external- and auditor-facing communication and represent the team in cross-team planning.
Basic qualifications
  • 5+ years as a Security Engineer in an AWS-native, microservice SaaS environment, with a strong focus on cloud infrastructure, container, and identity security.
  • Deep, hands-on expertise securing Kubernetes and containerized environments - EKS, RBAC, Kubernetes admission control, network policy, and workload identity.
  • Container runtime and image security experience; familiarity with a service mesh such as Istio strongly preferred.
  • Strong, hands-on expertise in PKI and cryptography - certificate lifecycle/management, TLS/mTLS, key management and rotation (AWS KMS or similar HSM/KMS), and encryption-at-rest/in-transit standards.
  • Deep, hands-on expertise with AWS security services, including but not limited to: IAM family, Organizations/SCPs, Secrets Manager, KMS, GuardDuty, CloudTrail, and Config.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer – Kubernetes & PKI (Hybrid)
Senior Cloud Security Engineer – Kubernetes & PKI (Hybrid)

Pager • Atlanta (GA)

On-site
USD 150,000 - 252,000
Company equity
ESPP
Retirement plan
+6
Senior Cloud Security Engineer – IAM, Kubernetes & PKI
Senior Cloud Security Engineer – IAM, Kubernetes & PKI

Pager • Atlanta (GA)

On-site
USD 150,000 - 252,000
Equity and stock programs
Competitive benefits
Senior Cloud Security Engineer — Identity, Crypto & Kubernetes
Senior Cloud Security Engineer — Identity, Crypto & Kubernetes

PagerDuty • Atlanta (GA)

Hybrid
USD 170,000 - 210,000
Senior Security Engineer - Cloud Security
Senior Security Engineer - Cloud Security

Pager • Atlanta (GA)

Hybrid
USD 150,000 - 252,000
Equity and stock programs
Competitive benefits
Senior Security Engineer - Cloud Security New Atlanta
Senior Security Engineer - Cloud Security New Atlanta

Pager • Atlanta (GA)

Hybrid
USD 150,000 - 252,000
Company equity
ESPP
Retirement plan
+6
Senior Director Information Security
Senior Director Information Security

EverCommerce • Denver (CO)

Hybrid
USD 180,000 - 240,000
Wellness stipend
Udemy training
401k with company match
+2
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Triwill Group • United States

Remote
USD 120,000 - 190,000
Member of Technical Staff (Security)
Member of Technical Staff (Security)

Fireworks AI • United States

On-site
USD 130,000 - 170,000
Staff Platform Engineer, Security
Staff Platform Engineer, Security

Engg • Denver (CO), Long Beach (CA), San Francisco (CA)

On-site
USD 160,000 - 250,000
Security Engineer
Security Engineer

Enterprise Engineering Inc. (EEI) • New York (NY)

On-site
USD 120,000 - 160,000