Software Engineer – Security

Jobtailor

California (MO)

On-site

USD 120,000 - 150,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a senior cloud security engineer to design and govern secure, scalable AWS architectures and IaC governance. You will drive CSPM tooling usage, implement secure-by-default patterns for Kubernetes workloads, and own end-to-end security projects from discovery to rollout.

You will collaborate across engineering, product, and security teams, focusing on IAM, encryption, and vulnerability management while aligning with NIST CSF, ISO 27001, SOC 2, and CIS benchmarks.

Qualifications

  • Expertise in building security tooling and automation
  • Experience enabling secure multi-account AWS architectures
  • Ability to implement secure-by-default patterns across cloud and container workloads
  • Strong understanding of IAM and least privilege

Responsibilities

  • Build and scale Infrastructure as Code governance strategies with security embedded
  • Operate and tune CSPM tooling and coordinate remediation
  • Investigate security events, triage incidents, and own remediation to resolution
  • Architect secure AWS cloud account structures, including landing zones and cross-account roles
  • Design secure network architectures with VPCs, subnets, routing, and egress controls
  • Embed security across Kubernetes and containerized workloads
  • Design IAM role and policy architectures for human and machine identities
  • Implement encryption for data at rest and in transit with AWS KMS and related services
  • Conduct threat modeling, architecture reviews, and secure design assessments
  • Assess and secure AI/ML product architectures and data flows
  • Build secure automation using Python, AWS services, and policy-as-code
  • Own complex security projects end-to-end from discovery to ownership
  • Align cloud security with NIST CSF, ISO 27001, SOC 2, and CIS benchmarks
  • Partner with infrastructure, platform, product, and security teams
  • Embed security from code to cloud across systems and developer workflows

Skills

AWS Cloud Architecture
Infrastructure as Code
Network Security
IAM Role & Policy Management
Threat Modeling
Python Programming
Go Programming
CSPM Tooling
Encryption & Key Management
Container & OS Hardening
Vulnerability Management
Secure Design Assessments
Automation Development
Security Tooling
Multi-Account Strategies

Education

NIST CSF
ISO 27001
SOC 2
CIS Benchmarks

Tools

AWS KMS
Secrets Manager
HashiCorp Vault
CI/CD Pipelines
Policy-as-Code Frameworks

Job description

  • Build and scale Infrastructure as Code governance strategies that embed security while enabling developer velocity
  • Operate and tune CSPM tooling and coordinate remediation through engineering teams
  • Investigate security events, triage incidents, identify root causes, and own remediation through resolution
  • Architect secure AWS cloud account structures, including landing zones, multi-account patterns, network segmentation, and cross-account roles
  • Design and implement network security architectures using security groups, NACLs, subnetting, routing layers, and egress controls
  • Establish secure-by-default design patterns across Kubernetes and containerized workloads
  • Design, maintain, and govern IAM role and policy architectures for human and machine identities
  • Implement encryption for data at rest and in transit, including key rotation using AWS KMS and related services
  • Conduct threat modeling, architecture reviews, and secure design assessments
  • Assess and secure AI/ML product architectures, trust boundaries, API boundaries, and data flows through training and inference pipelines
  • Build secure automation using Python, AWS-native services, and policy-as-code frameworks
  • Own complex security projects end-to-end, from discovery and design documentation through implementation, rollout, and long-term ownership
  • Align cloud security strategy with NIST CSF, ISO 27001, SOC 2, and CIS benchmarks
  • Partner with infrastructure, platform, product, application, engineering, and security teams
  • Embed security from code to cloud across systems, data, customer environments, and developer workflows
Requirements
  • Programming skills in Python, Go, or similar languages, with ability to build security tooling and automation
  • Experience building and operating systems at scale in cloud-native, containerized environments
  • Proficiency with Infrastructure as Code (Terraform), including modules, CI/CD pipelines, deployment governance, and security reviews
  • AWS cloud architecture experience: multi-account strategies, landing zones, environment isolation, and cross-account role design
  • IAM experience: role and policy architectures, least privilege, and human and machine identity patterns
  • Network security experience: security groups, NACLs, VPC design, subnet segmentation, routing layers, and egress controls
  • Experience with threat modeling and secure design assessments
  • Experience with encryption and key management using AWS KMS, Secrets Manager, or HashiCorp Vault
  • Experience with container and OS hardening
  • Experience with CSPM tooling
  • Experience investigating security events, including triage, root cause assessment, and remediation ownership
  • Experience with vulnerability management lifecycle
  • Awareness of AI/ML security risks, including prompt injection, data poisoning, model extraction, and training data protection
  • Knowledge of NIST CSF, ISO 27001, SOC 2, and CIS benchmarks
  • Experience designing secure architectures for high-growth SaaS or cloud-native environments
  • Ability to communicate security risks, trade-offs, and recommendations to technical and non-technical audiences
  • Ability to write concise, structured technical documentation
  • Ability to build alignment across teams without relying on positional authority
  • Ability to collaborate with engineering, product, and infrastructure teams
  • Comfortable with broad ownership, context-switching, and self-direction
  • Ability to manage multiple concurrent initiatives
  • Commitment to continuous learning
  • Preferred: secure development lifecycle practices, incident response/DFIR, detection engineering, offensive security, multi-cloud environments, zero-trust architecture, and DLP strategies
Core Competencies

Demonstrates expertise in building and scaling Infrastructure as Code governance strategies, with a strong focus on security and developer velocity. Proficient in AWS cloud architecture, IAM role management, and network security, while effectively communicating risks and collaborating across teams.

Highest-signal resume keywords
  • AWS Cloud Architecture
  • Infrastructure as Code (Terraform)
  • Network Security
  • IAM Role and Policy Management
  • Threat Modeling
Hard Skills
  • Python Programming
  • Go Programming
  • CSPM Tooling
  • Encryption and Key Management
  • Container and OS Hardening
  • Vulnerability Management
  • Secure Design Assessments
  • Automation Development
  • Security Tooling
  • Multi-Account Strategies
Soft Skills
  • Communication of Security Risks
  • Collaboration Across Teams
  • Context-Switching
  • Self-Direction
  • Continuous Learning
Certifications & Qualifications
  • NIST CSF
  • ISO 27001
  • SOC 2
  • CIS Benchmarks
Industry Keywords
  • Infrastructure as Code Governance
  • Cloud-Native Environments
  • Zero-Trust Architecture
  • Secure Development Lifecycle
  • Incident Response/DFIR
Tools & Technologies
  • AWS KMS
  • Secrets Manager
  • HashiCorp Vault
  • CI/CD Pipelines
  • Policy-as-Code Frameworks
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Engineer
Principal Security Engineer

Jobtailor • Town of Texas (WI)

On-site
USD 140,000 - 190,000
Senior Cloud Infrastructure Engineer
Senior Cloud Infrastructure Engineer

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000
Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000
Platform Automation Engineer
Platform Automation Engineer

Jobtailor • Maryland

On-site
USD 120,000 - 180,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Jobtailor • McLean (VA)

On-site
USD 150,000 - 190,000
Senior Manager, Platform Security
Senior Manager, Platform Security

Jobtailor • Town of Florida (NY)

On-site
USD 180,000 - 260,000
Staff Cloud Security Engineer
Staff Cloud Security Engineer

Jobtailor • Menlo Park (CA)

On-site
USD 185,000 - 240,000
Associate Director, Lead Cloud Architect
Associate Director, Lead Cloud Architect

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000
Software Engineering Lead
Software Engineering Lead

Jobtailor • Colorado

Hybrid
USD 170,000 - 210,000
Chief Information Security Officer – CISO
Chief Information Security Officer – CISO

Jobtailor • Salt Lake City (UT)

On-site
USD 180,000 - 240,000