Staff Cloud Security Specialist

Waystar, Inc

Atlanta (GA)

On-site

USD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Waystar, Inc is seeking a skilled Staff Cloud Security Architect to design and implement secure cloud architectures primarily in Google Cloud Platform. This role focuses on securing cloud workloads and ensuring compliance with regulations typical for healthcare payments.

The ideal candidate will bring 3+ years of experience in cloud security, strong communication skills, and a Bachelor's degree in a related field. The position offers a dynamic work environment and supports equal opportunity in employment.

Qualifications

  • 3+ years of hands-on experience securing workloads in cloud environments.
  • Solid understanding of IAM, networking, encryption, and cloud security.
  • Strong written and verbal communication skills.

Responsibilities

  • Contribute to cloud security design and implementation.
  • Help operate secure cloud landing zone controls.
  • Participate in threat modeling and security design reviews.

Skills

Cloud security
IAM
Network segmentation
Encryption
Terraform
DevSecOps

Education

Bachelor’s degree in Computer Science, Engineering, or related field

Tools

Terraform
CloudFormation
Bicep

Job description

About This Position

This role is a core contributor to the design and implementation of secure cloud architectures across our multi‑cloud environments (GCP primary; AWS/Azure supporting) and cloud‑adjacent SaaS services. As a staff‑level architect, you will focus on applying established security patterns, implementing guardrails, and partnering with engineering teams to ensure cloud workloads meet regulatory, audit, and customer assurance requirements typical of a healthcare payments organization (e.g., PCI DSS, HIPAA/HITECH, HITRUST, SOC 2, SOX, and aligned NIST controls).

What You’ll Do
  • Cloud security design & implementation – Contribute to and maintain cloud security reference architectures, standards, and implementation patterns for IaaS, PaaS, containers/Kubernetes, and serverless workloads.
  • Landing zone & governance support – Help implement and operate secure cloud landing zone controls including account/project structures, network segmentation, IAM boundaries, logging, and policy guardrails; support infrastructure‑as‑code and policy‑as‑code implementations aligned with defined standards.
  • Identity & access management – Implement least‑privilege IAM for workforce and workload identities; support MFA, conditional access, secrets management, and privileged access patterns designed by senior architects.
  • Data protection – Apply encryption, key management, tokenization, and data handling standards for sensitive data including payment and healthcare data; assist with data classification, retention, and secure deletion controls in cloud platforms.
  • Security‑by‑design in engineering – Participate in threat modeling and security design reviews for cloud services and applications; help integrate DevSecOps and SDLC security controls into CI/CD pipelines using established tooling and patterns.
  • Detection & response readiness – Ensure required cloud audit logs, telemetry, and security signals are enabled and flowing to centralized monitoring; partner with Security Operations to improve visibility, detection coverage, and incident readiness in cloud environments.
  • Vulnerability & configuration management – Help define and maintain cloud hardening baselines, container/image standards, and configuration compliance controls; work with engineering teams to remediate recurring or systemic cloud security findings.
  • Third‑party & SaaS security – Support reviews of cloud‑connected vendors and SaaS integrations against established security requirements; assist in defining and validating compensating controls and monitoring expectations.
  • Audit & evidence support – Partner with GRC and audit teams to map technical cloud controls to compliance frameworks; support evidence collection, control validation, and remediation activities during audits and assessments.
  • Conduct Security Reviews – Work with project teams to evaluate the security of new, cloud‑based initiatives, projects, and products for customer facing and internal use applications.
  • Compliance, risk, and assurance expectations – Design cloud security controls aligned to PCI DSS, HIPAA/HITECH, HITRUST CSF, SOC 2, SOX ITGC, and internal security standards; support continuous compliance efforts such as automated configuration checks, continuous monitoring, and repeatable evidence generation; participate in risk assessments, exception handling, and corrective action plans for cloud security gaps; contribute to customer assurance activities by providing clear technical explanations and diagrams with guidance from senior architects.
What You’ll Need
  • 3+ years of hands‑on experience securing workloads in public cloud environments (Google Cloud Platform, AWS, or Azure). Multi‑cloud experience preferred.
  • Solid understanding of core cloud security concepts: IAM, networking, segmentation, logging/monitoring, encryption, key management, secrets management, and workload security.
  • Experience using infrastructure‑as‑code and automation tools (e.g., Terraform, CloudFormation, Bicep) and supporting CI/CD pipelines.
  • Familiarity with container and/or Kubernetes security fundamentals.
  • Experience participating in threat modeling or security design reviews.
  • Strong written and verbal communication skills; able to document designs and explain security requirements to engineering teams.
  • Bachelor’s degree in Computer Science, Engineering, or a related field (or equivalent practical experience).
  • Preferred qualifications: exposure to PCI DSS, HIPAA/HITECH, or HITRUST control implementation in cloud environments; experience with CSPM tools, cloud‑native security services, or SIEM integrations; familiarity with application security and DevSecOps tooling (SAST/DAST/SCA, secrets scanning); knowledge of modern cloud patterns such as zero trust, API security, or event‑driven architectures; relevant certifications (CCSP, GCP Professional Cloud Security Engineer, AWS/Azure security specialty, or equivalent).

We are proud to be an equal opportunity workplace. Qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, marital status, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. This applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Manhattan Associates • Atlanta (GA)

On-site
USD 120,000 - 150,000
Cloud Engineer
Cloud Engineer

American Academy of Orthopaedic Surgeons • Rosemont (IL)

Hybrid
USD 102,000 - 105,000
Competitive salary
Training and development opportunities
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Global Solutions Consulting LLC. • Baltimore (MD)

Hybrid
USD 90,000 - 135,000
Competitive salary and benefits package
Opportunities for professional growth
Collaborative work environment
+1
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Cloud Security Operations Engineer
Cloud Security Operations Engineer

Cadence Design Systems • San Jose (CA)

On-site
Paid vacation
Paid holidays
401(k) match
+1
Lead Cloud Security Engineer
Lead Cloud Security Engineer

The Chamberlain Group LLC • South Carolina

On-site
USD 102,600 - 193,425
Comprehensive benefits package
401(k) contribution
Short-term incentive plan
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
Cloud Security Lead
Cloud Security Lead

Persistent Systems • Los Angeles (CA)

Hybrid
USD 180,000 - 240,000
Competitive salary and benefits
Talent development & education funding
Cutting-edge technologies exposure
+2
Security Engineer
Security Engineer

Healthmark Group • United States

Remote
USD 100,000 - 130,000
Cloud Engineer
Cloud Engineer

MegazoneCloud Global • New York (NY)

On-site
USD 100,000 - 130,000