Sr. Cloud Security Engineer

LHH

San Francisco (CA)

Hybrid

USD 180,000 - 250,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision insurance
401(k) plan with match
19 days of PTO + 11 paid holidays
Equity

Job summary

LHH is seeking a Sr. Cloud Security Engineer to join our client’s team in a full-time hybrid role based in San Francisco, CA.

This hands-on senior position will own the intersection of platform engineering, cloud security, and DevSecOps automation, turning security controls into code while protecting developer velocity. You will build secure infrastructure as code with Terraform, secure AKS, drive GitOps with Argo CD, and implement policy-as-code across the Azure cloud landing zone.

Qualifications

  • 8+ years in DevOps, SRE, cloud security or related; senior-level track record in fast-moving environments.
  • Hands-on Terraform with modules and IaC across environments.
  • Strong Kubernetes security experience, preferably AKS in production.
  • GitOps experience with Argo CD; Flux helpful if adapting quickly.
  • Enterprise-grade DevSecOps across CI/CD security, scanning, policy-as-code, vulnerability management.
  • Azure security depth preferred (Defender for Cloud, Sentinel, Entra ID, Key Vault, ACR, RBAC, PIM).
  • Experience with ISO, SOC 2, NIST or similar compliance evidence automation.
  • Ability to work independently in a startup-style environment.
  • Clear communication, low ego, collaborative with eng, infrastructure, security, and GRC partners.
  • Nice to have: AI/ML platform security exposure (Azure AI Foundry, MITRE ATLAS, NIST AI RMF).
  • Nice to have: Azure AZ-500 or SC-100, Kubernetes CKS or other cloud/security credentials.
  • Nice to have: experience in high-growth SaaS/startup/platform environments.

Responsibilities

  • Build, author, and operate secure infrastructure as code using Terraform, including reusable modules and plans from scratch.
  • Own Kubernetes platform security for AKS with hardened baselines and policy controls.
  • Drive GitOps delivery with Argo CD, including manifest drift management and release automation.
  • Build and operate secure CI/CD pipelines with SAST/DAST and SBOMs as automated gates.
  • Implement policy-as-code and Azure-native controls across the cloud landing zone (Azure Policy).
  • Operate and tune Azure security tooling (Defender for Cloud, Sentinel, Key Vault, Entra ID, RBAC, PIM).
  • Partner with engineering and SRE to define monitoring policies, alerting, and incident workflows.
  • Operationalize vulnerability management with remediation prioritization and reduced false positives.
  • Support secure software supply chain with signed images, SBOMs, provenance, and hardened images.
  • Contribute to ISO 27001/42001 and SOC 2 certification efforts with GRC partners.

Skills

Terraform
Kubernetes security
GitOps
DevSecOps
Azure security
Cloud security
Compliance
IaC
RBAC
PIM

Tools

AKS
Argo CD
Defender for Cloud
Sentinel
Key Vault
Entra ID
RBAC
PIM

Job description

LHH is seeking a Sr. Cloud Security Engineer to join our client's team in a full-time + hybrid-role, based in San Francisco, CA. This is an emerging enterprise intelligence startup focused on enabling organizations to effectively manage and optimize a blended workforce of human employees and autonomous AI systems.

About the role:

Our client is building a cloud-native, agentic AI SaaS platform on an Azure-native stack and are looking for a hands-on Sr. Cloud Security Engineer to own the intersection of platform engineering, cloud security, and DevSecOps automation. This person will turn security controls into code, strengthen the platform before go-to-market, and help protect developer velocity while raising the company’s security and compliance posture.

Salary and Benefits:
  • $180k to $250k + equity
  • Medical, dental, and vision insurance
  • 401(k) plan w/match
  • 19 days of PTO + 11 paid holidays
Qualifications:
  • Required: 8+ years of experience across DevOps, SRE, cloud security, security engineering, or platform engineering, with senior-level depth and a track record of building in fast-moving environments.
  • Required: Deep hands-on experience with Terraform, including writing modules or plans from scratch and applying infrastructure-as-code practices across environments.
  • Required: Strong Kubernetes and container security experience, preferably with AKS in production or near-production environments.
  • Required: GitOps experience with Argo CD strongly preferred; Flux experience is also relevant if you can quickly adapt to Argo CD.
  • Required: Enterprise-grade DevSecOps capability across CI/CD security, scanning automation, policy-as-code, vulnerability management, incident response, and secure release practices.
  • Required: Azure security depth is preferred, including Defender for Cloud, Sentinel, Entra ID, managed identities, RBAC, PIM, Key Vault, ACR, and Azure networking. Strong AWS or GCP cloud security experience may be considered if paired with the ability to ramp quickly in Azure.
  • Required: Experience contributing to compliance or certification efforts such as ISO, SOC 2, NIST, or similar frameworks, especially through evidence automation or control implementation.
  • Required: Ability to work independently, identify where you can add value, and execute with limited technical oversight in a startup-style build environment.
  • Required: Clear communication, sound judgment, low ego, professionalism, and a collaborative approach to working with engineering, infrastructure, security, and GRC partners.
  • Nice to have: AI/ML platform security exposure, including Azure AI Foundry, OWASP LLM Top 10, MITRE ATLAS, or NIST AI RMF.
  • Nice to have: Azure security certifications such as AZ-500 or SC-100, Kubernetes security certifications such as CKS, or other relevant cloud/security credentials.
  • Nice to have: Experience in high-growth SaaS, startup, platform engineering, or product-led environments where security must be embedded into how software is built and shipped.
Essential Job Functions:
  • Build, author, and operate secure infrastructure as code using Terraform, including reusable modules and plans created from scratch rather than only maintaining existing templates.
  • Own Kubernetes platform security for AKS, including hardened baselines, network policy, admission control, runtime protection, and practical hands-on implementation of security controls.
  • Drive GitOps delivery with Argo CD, including AKS manifest drift management, release automation, controlled deployment workflows, and rollback or failback patterns where needed.
  • Build and operate secure CI/CD pipelines with SAST, DAST, dependency, container, and infrastructure scanning as automated quality gates without unnecessarily slowing engineering teams.
  • Implement policy-as-code and Azure-native controls across the cloud landing zone, including Azure Policy and secure patterns for identity, access, and privileged operations.
  • Operate and tune Azure security tooling, including Microsoft Defender for Cloud, Microsoft Sentinel, Key Vault, Entra ID, RBAC, managed identities, and PIM.
  • Partner with engineering and SRE to define monitoring policies, alert triggers, and incident response workflows for the platform.
  • Help operationalize the vulnerability management program, including remediation workflows, prioritization, ownership, and reduce false positives across scanning and WAF-related processes.
  • Support secure software supply chain practices, including signed images, SBOMs, provenance, hardened base images, and policy-enforced registries.
  • Contribute technical evidence and automation to support ISO 27001 / 42001 and SOC 2 certification efforts, in partnership with GRC and infrastructure stakeholders.
Equal Opportunity Employer/Veterans/Disabled

To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to https://www.lhh.com/us/en/candidate-privacy

The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:

The California Fair Chance Act

Los Angeles City Fair Chance Ordinance

Los Angeles County Fair Chance Ordinance for Employers

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer: Azure & DevSecOps Expert
Senior Cloud Security Engineer: Azure & DevSecOps Expert

LHH • San Francisco (CA)

Hybrid
USD 180,000 - 250,000
Medical, dental, and vision insurance
401(k) plan with match
19 days of PTO + 11 paid holidays
+1
Senior Security Engineer – Hybrid (4649)
Senior Security Engineer – Hybrid (4649)

Hireclout • Los Angeles (CA)

On-site
USD 180,000 - 200,000
Competitive compensation package
Equity participation
100% covered medical, dental, and vision coverage
+5
Senior Cloud Engineer
Senior Cloud Engineer

Bayview Fund Management, LLC • Agoura Hills (CA)

Hybrid
USD 140,000 - 170,000
Annual bonus
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Theory Ventures • San Francisco (CA)

On-site
USD 150,000 - 210,000
Equity & Ownership
Impact & Visibility
Collaborative Culture
+1
Sr. Cloud Security Engineer (Remote)
Sr. Cloud Security Engineer (Remote)

Inspira Financial • Oak Brook (IL)

Hybrid
USD 125,000 - 155,000
Healthcare
401(k)
Paid time off
+2
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Arkadia Search Recruiting • Irving (TX)

On-site
USD 80,000 - 120,000
401(k)
Pet insurance
First day benefits
+1
Cloud Security Architect - St. Louis, MO
Cloud Security Architect - St. Louis, MO

Hubbell Incorporated • St. Louis (MO)

On-site
USD 150,000 - 190,000
Sr. IT Engineer
Sr. IT Engineer

LHH • Portland (OR)

On-site
USD 110,000 - 150,000
3 weeks PTO to start
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Rescale • United States

On-site
USD 123,000 - 181,000
Senior Platform Engineer
Senior Platform Engineer

LHH • Alpharetta (GA)

On-site
USD 140,000 - 170,000
Medical benefits
Dental benefits
Vision benefits
+5