Staff Cloud Security Engineer

Engine

United States

Hybrid

USD 137,275 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive base pay
Opportunities for bonuses and commissions
Hybrid-work model

Job summary

Engine is looking for a Staff Cloud Security Engineer in the United States to lead security across AWS and GCP. The ideal candidate will apply deep expertise in cloud security to enhance infrastructure resilience, manage cloud risks, and collaborate with cross-functional teams. Competitive compensation includes a base pay between $137,275 and $190,000, along with other benefits in a hybrid work environment.

Qualifications

  • Deep hands-on experience securing modern cloud environments, especially AWS.
  • Experience with GCP security or ability to ramp in multi-cloud environments.
  • Strong understanding of cloud IAM and access control mechanisms.

Responsibilities

  • Lead security hardening across AWS and GCP environments.
  • Own and mature Engine's approach to cloud security risks.
  • Serve as a primary responder for cloud-specific security alerts.
  • Collaborate with teams to improve detection logic and response workflows.

Skills

Cloud Security Expertise
Multi-Cloud Capability
IAM & Access Control
Cloud Architecture Judgment
CSPM / CNAPP Tooling
Infrastructure-as-Code
Cloud Detection & Response
Engineering Partnership
Analytical Problem Solving
Security Program Maturity
AI / Emerging Technology Awareness
Compliance & Frameworks

Tools

AWS
GCP
Terraform
Orca
Wiz
Prisma Cloud
Lacework

Job description

At Engine, we’re transforming business travel into something personalized, rewarding, and simple. For too long, managing travel and spend has been overwhelming and fragmented — we’re here to change that. We believe the future of travel should be seamless and powered by technology that delights customers at every step. That’s why we’re building a platform that brings together corporate travel, a powerful charge card, and modern spend management in one place.

To make this vision real, we’re looking for exceptional, mission-driven people to help redefine how businesses manage and experience travel.

More than 20,000 companies already rely on Engine to support over 1 million travelers and billions in annual bookings each year. Cash flow positive with rapid growth, we pair exclusive Engine-only rates, industry-leading rewards, and intelligent automation to help businesses save money while delivering world-class personalization and convenience.

Backed by Telescope Partners, Blackstone, and Permira, Engine has been recognized as one of the fastest-growing travel and fintech platforms in North America, with honors including the Deloitte Fast 500 and Built In’s Best Places to Work.

Staff Cloud Security Engineer

Engine is seeking a highly-skilled and motivated Staff Cloud Security Engineer to join our team. In this role, you will be a foundational member of Engine’s dedicated Cloud Security function, helping secure and scale our cloud environments across AWS and GCP.

You will be responsible for hardening cloud infrastructure, reducing systemic cloud risk, improving visibility and response for cloud-originated threats, and partnering closely with infrastructure, platform, engineering, and security teams. This role requires deep technical cloud security expertise, strong architectural judgment, and the ability to influence security decisions across a fast-moving engineering organization.

As Engine’s cloud footprint expands, including increased use of AWS, GCP, Terraform, and AI-enabled workloads, you will help ensure our cloud environments are secure, resilient, well-monitored, and built to scale.

Your Mission

As part of the Engine team, you’ll play a vital role in an environment where innovation meets collaboration. You will drive work independently, syncing regularly to ensure quality and alignment across the following areas:

  • Cloud Security Architecture & Hardening: Lead security hardening across AWS and GCP environments, including identity and access management, network segmentation, logging, monitoring, configuration hygiene, and secure cloud architecture patterns. You will help define standards that scale across teams and cloud platforms.
  • Cloud Risk Ownership: Own and mature Engine’s approach to identifying, prioritizing, and remediating cloud security risks. You will assess systemic risk, separate high-priority issues from low-value noise, and drive practical remediation in partnership with infrastructure and engineering teams.
  • Orca Findings Management: Own the end-to-end lifecycle of Orca findings, including monitoring new alerts, triaging severity, identifying root cause, tracking remediation, and driving findings to closure with the appropriate technical owners.
  • Cloud Alert Response: Serve as a primary responder for cloud-specific security alerts. You will help improve detection quality, reduce response time, and ensure cloud-originated threats are investigated and addressed effectively.
  • Infrastructure-as-Code Security: Partner with teams using Terraform and related infrastructure-as-code workflows to review, improve, and harden cloud configurations before risk reaches production.
  • AI Cloud Security: Help secure Engine’s expanding AI-related cloud footprint by identifying risks related to sensitive data, elevated IAM permissions, new service integrations, model/data access patterns, and infrastructure configurations.
  • Cross-Functional Collaboration: Partner closely with infrastructure, platform, engineering, SecOps, and security leadership to move security work forward. You will adapt your messaging across audiences, build trust with technical teams, and influence decisions without relying on direct authority.
  • Cloud-Native Threat Detection: Collaborate with SecOps to improve cloud telemetry, cloud-specific detection logic, SIEM signal quality, and response workflows for threats such as credential abuse, lateral movement, misconfigured storage, and data exfiltration.
  • Security Standards & Advocacy: Build clear, actionable cloud security guidelines, guardrails, and best practices for engineering teams. You will help create the paved paths that allow Engine to move quickly while reducing cloud security risk.
What You’ll Bring to Engine

We’re looking for a senior technical leader who is ready to take ownership of cloud security outcomes and deliver high-quality work:

  • Cloud Security Expertise: Deep hands-on experience securing modern cloud environments, especially AWS, with strong knowledge of cloud-native security controls, services, risks, and remediation patterns.
  • Multi-Cloud Capability: Experience with GCP security or the ability to quickly ramp in a multi-cloud environment spanning AWS and GCP.
  • IAM & Access Control: Strong understanding of cloud IAM, privilege reduction, identity boundaries, service permissions, key management, and common access-control failure modes.
  • Cloud Architecture Judgment: Ability to evaluate architecture decisions, identify systemic risk, and recommend scalable security patterns that balance risk reduction with engineering velocity.
  • CSPM / CNAPP Tooling: Experience with cloud security platforms such as Orca, Wiz, Prisma Cloud, Lacework, or similar tools, including triage, prioritization, remediation tracking, and reduction of alert noise.
  • Infrastructure-as-Code: Hands-on experience reviewing and securing Terraform or other infrastructure-as-code configurations.
  • Cloud Detection & Response: Experience investigating cloud security alerts and improving telemetry, logging, monitoring, and detection logic across cloud environments.
  • Engineering Partnership: Proven ability to earn credibility with infrastructure, platform, and engineering teams through practical recommendations, clear communication, and strong technical depth.
  • Analytical Problem Solving: Ability to assess complex cloud security issues, identify root causes, prioritize risk, and make sound decisions with incomplete information.
  • Security Program Maturity: Experience building or improving cloud security standards, guardrails, operating rhythms, remediation processes, or security review practices.
  • AI / Emerging Technology Awareness: Understanding of how AI workloads can expand cloud attack surface through sensitive data usage, elevated permissions, new integrations, and infrastructure complexity.
  • Compliance & Frameworks: Familiarity with cloud security concepts as they relate to compliance frameworks such as SOC 2, PCI, or similar standards.

Compensation

Our compensation packages are based on several factors, including your experience, expertise, and location. In addition to a competitive base salary, total compensation may include equity and/or variable pay (OTE). Your recruiter will share your complete compensation package as you move through the process.

Base Pay Range

$137,275 - $190,000 USD

The Engine Edge: Perks & Compensation We believe in rewarding great work with great benefits.

  • Compensation: Competitive base pay tied to role and experience, with opportunities for bonuses, commissions, and equity.
  • Environments for Success: Different roles have different needs in terms of the environments that drive success which is why we have a hybrid-hub model. Whether you are in one of our amazing offices or fully remote, we’ll make sure you have what you need to succeed.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Socket.dev • United States

Remote
USD 115,000 - 160,000
Competitive base pay with bonuses and equity
Hybrid work model for flexible work environments
Senior Engineering Manager, Infrastructure-IAM
Senior Engineering Manager, Infrastructure-IAM

Engine • United States

Remote
USD 184,000 - 255,000
Competitive base pay
Bonuses and equity opportunities
Hybrid work model
Senior Manager, Information Technology
Senior Manager, Information Technology

Engine • United States

Hybrid
USD 160,000 - 230,000
Equity
Variable pay
Hybrid work model
Director, Growth Platform & AI
Director, Growth Platform & AI

Engine • United States

Hybrid
USD 181,000 - 250,000
Hybrid-hub model
Office or remote work
Director Growth, Distribution
Director Growth, Distribution

Engine • United States

Hybrid
USD 173,000 - 240,000
Equity
Bonuses & commissions
Chief of Staff
Chief of Staff

Engine • Northern (KY)

Hybrid
USD 190,000 - 230,000
Hybrid-hub model
Bonus eligibility
Equity (OTE)
Internal Communications Manager, Product Delivery
Internal Communications Manager, Product Delivery

Engine • Chicago (IL)

Hybrid
USD 139,000 - 170,000
Equity opportunities
Hybrid/hub model
Office or remote options
Director Product Marketing
Director Product Marketing

Engine • Chicago (IL)

Hybrid
USD 170,000 - 235,000
Hybrid-hub model
Equity
Bonuses
Director, Partner Growth
Director, Partner Growth

Engine • Seattle (WA)

Hybrid
USD 144,000 - 195,000
Hybrid work model
Equity
Bonuses & commissions
+1
Director, Growth Platform & AI
Director, Growth Platform & AI

Doist • United States

Hybrid
USD 181,000 - 250,000
Hybrid-hub model
Remote-friendly offices
Equity opportunities