Staff Cloud Security Engineer

Jobtailor

Menlo Park (CA)

On-site

USD 185,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Grail is seeking a senior cloud security leader to drive the design, implementation, and ongoing improvement of secure AWS architectures across the product lifecycle. You will partner with Platform and Cloud Engineering to implement IAM, KMS, GuardDuty, Security Hub, and other native services for proactive threat detection and risk management.

You will develop standards, guardrails, and governance across AWS accounts, containers, and hybrid workloads, and automate monitoring, compliance, and

Qualifications

  • 8+ years in product security, cybersecurity, cloud security, or related roles.
  • Hands-on security threat modeling, risk assessments, and vulnerability management for complex software.
  • Experience embedding security into CI/CD and DevSecOps practices.
  • Experience supporting security incident response and root-cause analysis in production.
  • Bachelor’s degree or equivalent practical experience in a cybersecurity/CS-related field.

Responsibilities

  • Lead design, implementation, and improvement of cloud security architectures across AWS environments.
  • Partner with Platform and Cloud Engineering teams to design and manage AWS-native security services.
  • Develop and enforce cloud security standards, guardrails, and governance across AWS accounts, containers, Kubernetes, serverless, and hybrid workloads.
  • Automate security monitoring, compliance validation, vulnerability management, and incident response workflows using IaC and scripting.
  • Conduct cloud threat modeling, architecture risk assessments, and security reviews for AWS-hosted apps, APIs, and infra.
  • Mentor engineers on AWS security best practices and DevSecOps methodologies.

Skills

Cloud security architecture
Threat modeling
Vulnerability management
DevSecOps
Automation

Education

Bachelor’s degree in Cybersecurity, CS, or related field

Tools

AWS
IAM
KMS
GuardDuty
Security Hub
Inspector
Macie
WAF
Shield
CloudTrail
CloudWatch

Job description

  • Lead the design, implementation, and continuous improvement of cloud security architectures across AWS environments, ensuring product security, and secure-by-design principles throughout the infrastructure and application lifecycle.
  • Partner with Platform, and Cloud Engineering team to design, implement, and manage AWS-native security services including IAM, KMS, GuardDuty, Security Hub, Inspector, Macie, WAF, Shield, CloudTrail, Config, and CloudWatch for proactive threat detection and risk management.
  • Develop and enforce cloud security standards, guardrails, and governance frameworks across AWS accounts, containers, Kubernetes/EKS, serverless, and hybrid cloud workloads.
  • Automate security monitoring, compliance validation, vulnerability management, and incident response workflows using Infrastructure as Code (IaC), scripting, and cloud-native automation tools.
  • Conduct cloud threat modeling, architecture risk assessments, and security reviews for AWS-hosted applications, APIs, infrastructure, and enterprise-integrated systems.
  • Secure DevOps platforms and cloud-native application environments by implementing least-privilege access controls, secrets management, secure network segmentation, encryption, and workload protection.
  • Manage and enhance continuous cloud security posture management (CSPM), container security, and runtime protection capabilities across AWS environments.
  • Scope, coordinate, and review penetration testing, vulnerability assessments, and advanced security testing activities across cloud infrastructure, applications, and DevOps tooling.
  • Serve as a cloud security subject matter expert during security incidents, forensic investigations, root cause analysis, and remediation activities.
  • Partner with Engineering, Platform, Infrastructure, Compliance, and Product teams to align cloud security strategies with regulatory, privacy, and industry cybersecurity requirements.
  • Define, track, and report cloud security metrics, operational KPIs, and compliance status to provide visibility into organizational security posture and risk trends.
  • Mentor and guide engineers on AWS security best practices, DevSecOps methodologies, automation strategies, and secure cloud engineering principles to strengthen organizational security maturity at GRAIL.
Requirements
  • 8+ years of experience in product security, cybersecurity, Cloud Security, application security, or related technical security roles.
  • Hands-on experience leading threat modeling, security risk assessments, and vulnerability management for complex software products.
  • Experience embedding security into modern software development environments, including CI/CD and DevSecOps practices.
  • Experience supporting security incident response and conducting root cause analysis in production environments.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent practical experience.
Core Competencies

Demonstrates expertise in cloud security architecture, including the design and implementation of AWS-native security services and compliance frameworks. Proficient in automating security processes and mentoring teams on best practices in cloud security and DevSecOps.

Highest-signal resume keywords
  • Cloud Security Architecture
  • AWS Security Services
  • Threat Modeling
  • Vulnerability Management
  • DevSecOps Practices
ATS Optimization Keywords
Hard Skills
  • Cloud Security
  • Product Security
  • Cybersecurity
  • Application Security
  • Security Risk Assessment
  • Incident Response
  • Infrastructure as Code
  • Scripting
  • Continuous Security Posture Management
  • Penetration Testing
Soft Skills
  • Mentoring
  • Collaboration
  • Communication
Industry Keywords
  • Cybersecurity Requirements
  • Compliance
  • Risk Management
  • Secure-by-Design Principles
  • Cloud-Native Automation
Tools & Technologies
  • AWS
  • IAM
  • KMS
  • GuardDuty
  • Security Hub
  • Inspector
  • Macie
  • WAF
  • CloudTrail
  • CloudWatch
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Engineer
Principal Security Engineer

Jobtailor • Town of Texas (WI)

On-site
USD 140,000 - 190,000
Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000
Staff Infrastructure and Security Engineer
Staff Infrastructure and Security Engineer

Jobtailor • Chicago (IL)

On-site
USD 140,000 - 190,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Jobtailor • McLean (VA)

On-site
USD 150,000 - 190,000
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Senior Manager, Platform Security
Senior Manager, Platform Security

Jobtailor • Town of Florida (NY)

On-site
USD 180,000 - 260,000
Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • United States

On-site
USD 140,000 - 190,000
Senior Software Engineer, Cloud Security
Senior Software Engineer, Cloud Security

Jobtailor • Boston (MA)

On-site
USD 150,000 - 210,000
Senior Principal Cloud Engineer
Senior Principal Cloud Engineer

Jobtailor • Washington

On-site
USD 180,000 - 240,000
Information Technology Manager
Information Technology Manager

Jobtailor • Illinois

On-site
USD 150,000 - 190,000