Staff Cloud Security Engineer

Jobgether

United States

On-site

USD 168,000 - 270,000

Full time

4 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Fully remote work
Competitive compensation
401(k) match
Comprehensive health coverage
Professional development opportunities

Job summary

Jobgether is seeking a Staff Cloud Security Engineer to strengthen the security foundation across multi-cloud environments and next-generation applications. You will design automated security controls and embed security into development workflows, spanning DevSecOps, IAM, infrastructure hardening, and threat detection.

You will partner with engineering, DevOps, product, and security teams to build secure-by-default systems at scale and protect AI/ML workloads from evolving threats.

Qualifications

  • 7–10+ years in cloud/security/DevSecOps or related engineering fields.
  • Deep experience securing AWS and/or Azure multi-cloud environments.
  • Strong IAM, vulnerability management, and cloud security monitoring knowledge.
  • Scripting abilities in Python, Bash, or PowerShell for automation.
  • Understanding of Docker, Kubernetes, and cloud-native architectures.

Responsibilities

  • Design security controls into CI/CD pipelines using GitHub, GitLab, Jenkins, or Azure DevOps.
  • Manage IaC security scanning and reduce false positives.
  • Automate developer feedback and remediation workflows for secure-by-default development.
  • Develop automation scripts to streamline security processes.
  • Establish IAM controls across cloud environments with least-privilege access.
  • Define lifecycle controls for non-human identities and cloud secrets.
  • Develop secure infrastructure baselines and vulnerability management across AWS/Azure/GCP.
  • Lead multi-cloud security initiatives and secure multi-tenant architectures.
  • Advise on secure cloud-native architectures for microservices/serverless/containers.
  • Enhance container/Kubernetes security with runtime controls and supply-chain protections.
  • Develop AI/ML security approaches, protecting models and data pipelines.
  • Protect sensitive cloud/AI data with encryption, tokenization, and data protection controls.
  • Collaborate with Security Operations to improve telemetry, logging, and detection.
  • Onboard cloud log sources and build detection rules for cloud threats.

Skills

Cloud security
DevSecOps
IAM
CI/CD security
Python scripting
Kubernetes security
IaC security
Threat detection

Education

CCSP
CISSP
AWS/Azure/GCP security certs

Tools

Terraform
CloudFormation
Bicep
SIEM
CWPP

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Cloud Security Engineer based in United States.


As a Staff Cloud Security Engineer, you will help define and strengthen the security foundation of modern, multi-cloud environments and next-generation applications.


You will design automated security controls and embed security directly into development and deployment workflows.


The role spans DevSecOps, identity and access management, infrastructure hardening, workload security, data protection, and threat detection.


You will partner closely with engineering, DevOps, product, and security teams to build secure-by-default systems at scale.


You will also help secure emerging AI/ML workloads, protecting models, data pipelines, identities, and sensitive information from evolving threats.


Your work will directly reduce organizational risk while improving developer efficiency, visibility, and resilience.


This is a high-impact technical leadership opportunity for a hands-on security engineer who enjoys building scalable solutions in a rapidly evolving environment.


Accountabilities


  • Design and integrate security controls directly into CI/CD pipelines using platforms such as GitHub, GitLab, Jenkins, or Azure DevOps.

  • Evaluate, configure, and manage Infrastructure as Code security scanning tools to identify meaningful risks and reduce false positives.

  • Build automated developer feedback and remediation workflows that encourage secure-by-default development practices.

  • Develop automation scripts using Python, Bash, or PowerShell to streamline security processes and improve operational efficiency.

  • Establish and maintain IAM controls across cloud environments, enforcing least-privilege access and secure identity practices.

  • Define standards and lifecycle controls for non-human identities, APIs, application credentials, and cloud secrets.

  • Develop secure infrastructure baselines, vulnerability management processes, and hardening standards across AWS, Azure, and/or GCP.

  • Use Terraform, CloudFormation, Bicep, or comparable IaC technologies to ensure infrastructure is secure, repeatable, and auditable.

  • Lead or contribute to high-impact infrastructure security initiatives, including multi-cloud network isolation, secure multi-tenant architectures, and continuous remediation of misconfigurations.

  • Advise engineering teams on secure cloud-native architectures spanning microservices, serverless applications, containers, and PaaS workloads.

  • Strengthen container and Kubernetes security through runtime controls, supply-chain protections, and configuration assessments.

  • Develop security approaches for AI/ML systems, addressing adversarial threats, unauthorized access, model protection, and data pipeline security.

  • Protect sensitive cloud and AI data through encryption, anonymization, secure storage, tokenization, and appropriate data protection controls.

  • Partner with Security Operations to improve cloud telemetry, logging, observability, and detection capabilities.

  • Onboard relevant cloud log sources and develop detection rules for cloud-based threats using SIEM, CSPM, CWPP, and related technologies.

  • Support the triage, investigation, and forensic analysis of cloud and application security incidents, collaborating on containment and remediation.

  • Translate complex security requirements into practical guidance for both technical and non-technical stakeholders.


Requirements


  • 7–10+ years of hands-on experience in cloud security, application security, DevSecOps, or closely related engineering disciplines.

  • Deep practical expertise securing AWS and/or Azure environments, including the design and maintenance of controls for multi-cloud applications.

  • Strong knowledge of cloud identity and access management, infrastructure security, vulnerability management, network security, data protection, and security monitoring.

  • Proficiency with Python, Bash, PowerShell, or similar scripting languages for security automation.

  • Strong understanding of Docker, Kubernetes, container security, and cloud-native application architectures.

  • Hands-on experience securing Infrastructure as Code, particularly with Terraform, ARM, CloudFormation, Bicep, or comparable technologies.

  • Experience integrating security practices into CI/CD pipelines and applying DevSecOps principles across software development workflows.

  • Familiarity with SIEM, CSPM, CWPP, cloud logging, telemetry, detection engineering, and incident response practices.

  • Knowledge of AI/ML security considerations, including protection of models, data pipelines, identities, and workloads, is highly valuable.

  • Relevant industry certifications such as CCSP, CISSP, AWS Security Specialty, Azure Security Engineer, GCSA, or OSCP are strongly preferred.

  • A proactive builder mindset, with a demonstrated ability to identify security gaps, improve processes, and develop scalable solutions.

  • Strong cross-functional collaboration and communication skills, with the ability to explain sophisticated security concepts clearly to varied audiences.

  • Comfortable operating in a rapidly changing environment and continuously adapting to emerging cloud, application, and AI security threats.


Benefits


  • Competitive base salary of $168,200–$252,200 for eligible US locations, with a higher range of $179,900–$269,900 applicable to CA, CT, DC, MD, MA, NJ, NY, VA, and WA.

  • Annual bonus and equity opportunities as part of the total compensation package.

  • Company-sponsored medical, dental, and vision coverage, including fully employer-paid options and substantial dependent coverage.

  • FSA and HSA options.

  • 401(k) match.

  • Telehealth benefits, including One Medical membership options.

  • Flexible paid time off and support for autonomous work.

  • Learning and development opportunities, comprehensive onboarding, leadership training, and professional growth programs.

  • Recognition programs, including peer-nominated awards and rewards.

  • Parental leave and family support programs.

  • Up to $20,000 in fertility services, including IUI and IVF, plus surrogacy and adoption reimbursement.

  • Maternity support through Maven Maternity and free breast milk shipping through Maven Milk.

  • Pet insurance, legal advisory services, financial planning tools, and additional wellness and family benefits.

  • Fully remote work environment with flexibility and opportunities to work on cutting-edge cloud and AI security challenges.


We appreciate your interest and wish you the best!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Staff Engineer - DevSecOps
Senior Staff Engineer - DevSecOps

Exelixis Inc • Alameda (CA)

On-site
USD 154,500 - 220,500
401(k) plan with company contributions
Group medical, dental, and vision coverage
Flexible spending accounts
+1
Senior Security Engineer – Hybrid (4649)
Senior Security Engineer – Hybrid (4649)

Hireclout • Los Angeles (CA)

On-site
USD 180,000 - 200,000
Competitive compensation package
Equity participation
100% covered medical, dental, and vision coverage
+5
Cloud Engineer
Cloud Engineer

Tata Consultancy Services • New London (NH)

On-site
USD 150,000 - 180,000
Annual incentive
Medical coverage
Parental leave
+6
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Spinwheel Solutions Inc. • Oakland (CA)

On-site
USD 140,000 - 190,000
Remote-First
Salary & Equity
Unlimited PTO
+2
Cloud Security & Automation Engineer (IaC Lead)
Cloud Security & Automation Engineer (IaC Lead)

Tata Consultancy Services • Irving (TX)

On-site
USD 110,000 - 135,000
Discretionary incentive
Medical coverage
Parental leave
+12
Senior Cloud Security Engineer
Senior Cloud Security Engineer

United States Digital Space LLC • Bellevue (NY)

Hybrid
USD 187,000 - 220,000
Challenging, high-impact work to grow
Bonus programs, equity ownership, and
100% paid health insurance for all
+4
Infrastructure Security Engineer
Infrastructure Security Engineer

Pantera Capital • Palo Alto (CA)

On-site
USD 200,000 - 340,000
Equity
Comprehensive medical coverage
401(k) retirement plan
+2
Infrastructure Security Engineer
Infrastructure Security Engineer

xAI • New York (NY)

Hybrid
USD 100,000 - 258,000
Equity
Medical insurance
Vision insurance
+4
Manager, Security Engineering, Cloud & AppSec
Manager, Security Engineering, Cloud & AppSec

Horizon3 AI • United States

On-site
USD 149,000 - 185,000
Health, vision & dental insurance
Flexible vacation policy
Generous parental leave
+2
Security / AI Cloud Engineer
Security / AI Cloud Engineer

Cyber 74, LLC • Connecticut

Hybrid
USD 110,000 - 130,000
Remote work option
Flexible schedules
Company provided training
+3