Staff Cloud Security Engineer

ServiceTitan, Inc.

Northern (KY)

Hybrid

USD 150,000 - 210,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flextime & learning
Medical/dental/vision coverage
401k match
Parental leave
Fertility support
Maven Maternity
Breast milk shipping
Pet insurance

Job summary

ServiceTitan, Inc. is seeking a Staff Cloud Security Engineer to shape the security foundation of our cloud environments and applications. You will design automated security controls, harden multi-cloud infrastructure, and champion secure development practices across the organization.

You’ll lead DevSecOps initiatives, build feedback loops, and implement secure CI/CD pipelines, while ensuring data protection and threat detection across AWS, Azure, or GCP.

Qualifications

  • 7-10+ years of hands-on experience in cloud security, application security, DevSecOps, or related engineering roles.
  • Deep hands-on experience with Azure and/or AWS security services, including the design and maintenance of multi-cloud application controls.
  • Proficiency in scripting (Python, Bash, PowerShell) to automate security tasks.
  • Strong understanding of container security (Docker, Kubernetes) and IaC security (Terraform, ARM).
  • Industry certifications such as CCSP, CISSP, AWS Security Specialty, Azure Security Engineer, GCSA, or OSCP are highly preferred.

Responsibilities

  • DevSecOps and Automation Pipeline Integration: Integrate robust security controls directly into CI/CD platforms such as GitHub, GitLab, Jenkins, or Azure DevOps.
  • Automated Scanning: Evaluate and implement pipeline-based security IaC scanning; manage and configure IaC scanning tools to surface true risk.
  • Developer Feedback Loops: Build and optimize developer feedback loops and automated remediation workflows to secure software by default.
  • Identity and Access Management (IAM) Cloud Identity Controls: Build and maintain IAM security controls across cloud platforms, enforcing least privilege.
  • Non-Human Identity Management: Standardize management, security controls, and lifecycle expectations for non-human identities.
  • Secrets Management: Govern secure use of cloud identities, APIs, and secrets management.
  • Infrastructure Security and Hardening: Develop secure baselines, vulnerability management, and hardening standards across AWS, Azure, or GCP.
  • Infrastructure as Code: Validate security configurations with Terraform, CloudFormation, or Bicep.

Skills

Cloud security
DevSecOps
Scripting
Container security
IaC security
IAM security

Tools

Terraform
CloudFormation
Bicep
Docker
Kubernetes

Job description

Ready to be a Titan? We are seeking an experienced Staff Cloud Security Engineer to shape the security foundation of our modern cloud environments and next-generation applications. In this high-impact role, you will design cutting-edge automated security controls, harden multi-cloud infrastructure, and champion secure development practices across the organization. If you are passionate about cloud security, DevSecOps, and staying ahead of emerging threats, this role puts you right at the center of innovation.

What You’ll Do:
  • DevSecOps and Automation Pipeline Integration: Integrate robust security controls directly into CI/CD platforms such as GitHub, GitLab, Jenkins, or Azure DevOps.
  • Automated Scanning: Evaluate and implement pipeline-based security Infrastructure as Code (IaC) scanning. Manage and configure IaC scanning tools to surface true risk.
  • Developer Feedback Loops: Build and optimize developer feedback loops and automated remediation workflows to ensure software is secure by default. Develop automated scripts using Python, Bash, or PowerShell to streamline security processes.
  • Identity and Access Management (IAM) Cloud Identity Controls: Build and maintain IAM security controls across cloud platforms, assessing policies to enforce the principle of least privilege.
  • Non-Human Identity Management: Standardize management, security controls, and lifecycle expectations with regard to non-human identity.
  • Secrets Management: Govern the secure use of cloud identities, Application Programming Interfaces (APIs), and secrets management.
  • Infrastructure Security and Hardening Cloud Posture: Develop and implement secure infrastructure baselines, vulnerability management processes, and hardening standards across AWS, Azure, or GCP environments.
  • Infrastructure as Code (IaC): Validate security configurations and leverage IaC tools like Terraform, CloudFormation, or Bicep to ensure repeatable, auditable, and secure infrastructure provisioning.
  • Network Security: Tackle high-impact infrastructure projects such as multi-cloud network isolation, secure multi-tenant use, and continuous remediation of discovered misconfigurations.
  • Workload Security Cloud-Native Architectures: Guide engineering teams on secure architecture design for cloud apps, microservices, serverless services, and PaaS workloads.
  • Container Security: Advance container and Kubernetes security by implementing runtime controls, supply-chain security, and configuration assessments.
  • AI & Emerging Tech: Secure in-house and public AI/ML systems against cyber threats, adversarial attacks, and unauthorized access, ensuring models and data pipelines are protected throughout the solution lifecycle.
  • Data Security and Privacy Data Protection: Ensure that sensitive cloud and AI data is properly encrypted, anonymized, and securely stored.
  • Encryption Standards: Assess and implement strong encryption configurations, checkpoint encryption, and tokenization to protect data at rest and in transit.
  • Compliance Alignment: Develop and enforce policies to align data security and privacy measures with industry regulations, ethical standards, and organizational governance requirements.
  • Telemetry & Visibility: Partner with Security Operations to improve cloud application telemetry, logging, and observability. Help expand monitoring capabilities by onboarding log sources and building detection rules for cloud-based threats.
  • Threat Detection: Monitor and analyze security events using SIEM, Cloud Security Posture Management (CSPM), and Cloud Workload Protection Platforms (CWPP).
  • Incident Response: Support the triage, investigation, and forensic analysis of cloud-based application or pipeline security incidents, working collaboratively to contain and mitigate threats.
What You’ll Bring:
  • Experience: 7-10+ years of hands-on experience in cloud security, application security, DevSecOps, or related engineering roles.
  • Cloud Expertise: Deep hands-on experience with Azure and/or AWS security services, including the design and maintenance of multi-cloud application controls.
  • Technical Skills: Proficiency in scripting (Python, Bash, PowerShell) to automate security tasks. Strong understanding of container security (Docker, Kubernetes) and IaC security (Terraform, ARM).
  • Certifications: Industry certifications such as CCSP, CISSP, AWS Security Specialty, Azure Security Engineer, GCSA, or OSCP are highly preferred.
Why this role?

Transformative Impact: You will have a proactive, "builder" mindset with a passion for improving processes and reducing risk, directly driving scalable solutions across our real-world infrastructure.

Cross-Functional Collaboration: You will work closely with diverse engineering, DevOps, and product teams to ensure secure solution delivery, translating complex security concepts for both technical and non-technical stakeholders.

Continuous Growth: Join a dynamic team where you will continuously adapt to evolving challenges, stay ahead of emerging cloud threats, and explore the secure integration of frontier AI workloads.

Be Human With Us:

Being human isn’t about checking every box on a list. It’s about the experiences we have, people we meet, and the perspectives we share. So, if you have the skills but are hesitant to apply because of your background, apply anyway. We need amazing people like you to help us challenge the conventional and think differently about the problems that we’re solving. We’re in this together. Come be human, with us.

Use of AI Technology:

We use technology, including automated and AI-assisted tools, to support certain aspects of our recruitment process. These tools are designed to improve efficiency and enhance the candidate experience. AI tools are not used to make hiring decisions; all hiring decisions are made by our hiring teams.

What We Offer:
  • Flextime, recognition, and support for autonomous work: Flexible time off with ample learning and development opportunities to continue growing your career. We offer a comprehensive onboarding program, leadership training for Titans at all levels, and other programs and events. Great work is rewarded through Bonusly, peer-nominated awards, and more.
  • Holistic health and wellness benefits: Company-paid medical, dental, and vision (with 100% employer paid options and 90% coverage for dependents), FSA and HSA, 401k match, and telehealth options including memberships to One Medical.
  • Support for Titans at all stages of life: Parental leave and support, up to $20k in fertility services (i.e. IUI and IVF), surrogacy, and adoption reimbursement, on demand maternity support through Maven Maternity, free breast milk shipping through Maven Milk, pet insurance, legal advisory services, financial planning tools, and more.
  • At ServiceTitan, we celebrate individuality and uniqueness. We believe that the convergence of fresh perspectives and experiences from all walks of life is what makes our product and culture so great.
  • We strongly encourage people from underrepresented groups to apply. We do not discriminate against employees based on race, color, religion, sex, national origin, gender identity or expression, age, disability, pregnancy (including childbirth, breastfeeding, or related medical condition), genetic information, protected military or veteran status, sexual orientation, or any other characteristic protected by applicable federal, state or local laws.
  • ServiceTitan is committed to fair and equitable compensation for all of our employees. We thoughtfully consider a wide range of factors when determining individual compensation, which may change over time. We comply with all applicable minimum wage laws.
  • For candidates in the United States, the good faith salary ranges estimate for this role is Zone1: $179,900 USD - $269,900 USD Applicable for: CA, CT, DC, MD, MA, NJ, NY, VA, and WA Zone2: $168,200 USD - $252,200 USD Applicable for: All other US locations. International Compensation for candidates residing outside the United States will vary by location and will be discussed during the hiring process. Actual compensation within a range is determined by factors including relevant experience, skill set, qualifications, and performance. In addition to base salary, our total compensation package includes an annual bonus, equity, and a holistic suite of benefits.
  • We’re building the first end-to-end solution to transform the trades, a trillion-dollar global industry that’s been underserved by technology for far too long. Recognized by Forbes as one of the top cloud companies, we use our deep industry knowledge and technical expertise to develop solutions that empower everyday entrepreneurs to grow and scale their businesses. While our vision is bold, we always stay humble. Join us. We’re just getting started.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Site Reliability Engineer
Senior Site Reliability Engineer

JobCubby • Northern (KY)

On-site
USD 138,000 - 221,000
Flex-time and growth opportunities
Comprehensive health benefits
Parental leave and family support
+1
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Socket.dev • California (MO)

Hybrid
USD 170,000 - 210,000
Flextime & autonomous work
Health & wellness benefits
Parental leave & fertility support
Director, Software Engineering (Infrastructure)
Director, Software Engineering (Infrastructure)

ServiceTitan • United States

On-site
USD 247,000 - 396,000
Flexible time off
Health benefits
Parental leave & fertility support
Sr. Lead Engineer, Integration & Automation
Sr. Lead Engineer, Integration & Automation

ServiceTitan, Inc. • Northern (KY)

Hybrid
USD 168,000 - 270,000
Flexible time off
Medical, dental, and vision benefits
401(k) match
Implementation Consultant I
Implementation Consultant I

ServiceTitan, Inc. • Northern (KY)

Hybrid
USD 59,000 - 95,000
Flextime
Comprehensive onboarding
Leadership training
+3
Implementation Consultant I
Implementation Consultant I

ServiceTitan, Inc. • California (MO)

Hybrid
USD 59,000 - 95,000
Flextime
Learning & development programs
Company health benefits
+1
Senior Events Specialist
Senior Events Specialist

ServiceTitan, Inc. • Northern (KY)

Hybrid
USD 93,000 - 139,000
Flexible time off
Comprehensive onboarding program
Wellness benefits
Director, Software Engineering (Infrastructure)
Director, Software Engineering (Infrastructure)

ServiceTitan, Inc. • California (MO)

On-site
USD 247,000 - 396,000
Flexible time off
Medical, dental & vision insurance
401k match
+1
Technical Program Manager, Fintech
Technical Program Manager, Fintech

ServiceTitan, Inc. • Glendale (CA), Northern (KY)

Hybrid
USD 112,000 - 168,000
Flexible time off
Onboarding program
Annual bonuses
+2
Technical Program Manager, Fintech
Technical Program Manager, Fintech

ServiceTitan, Inc. • California (MO)

Hybrid
USD 105,000 - 168,000
Flexible time off
Onboarding program
Bonus program
+1