Staff Security Engineer, Cloud

ALSO.

Palo Alto (CA)

On-site

USD 205,000 - 240,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Robust health coverage
One Medical membership
Progyny fertility benefits
Flexible time off
401(k) match

Job summary

ALSO. is seeking a Staff Security Engineer for Cloud to own security end-to-end in a connected, software-defined EV platform.

You will design the security architecture and implement it in Go alongside the backend team, addressing telemetry, diagnostics, and fleet APIs with a focus on scale and safety. The role requires deep AWS and Kubernetes security expertise, threat modeling, and hands-on coding to ship secure services, CI/CD controls, and incident response.

Qualifications

  • 10+ years in backend and infrastructure engineering with production security ownership.
  • Expert, hands-on AWS security including IAM, VPC design, KMS, Secrets Manager and guardrails.
  • Deep Kubernetes security—RBAC, admission controllers, policies, and runtime protection.
  • Fluent Go development for security services and tooling.
  • Experience with threat modeling, incident response, and security reviews.

Responsibilities

  • Own cloud security end to end across AWS, Kubernetes and microservices.
  • Design and implement workload identity, org IAM and least privilege.
  • Harden containers, admission control, network policy, and service mesh security.
  • Secure the software supply chain: SBOMs, scanning, signed artifacts, CI/CD gatekeeping.
  • Develop Go-based authorization services and policy enforcement tooling.
  • Operate detection, telemetry, alerting, runbooks, and on-call for security incidents.
  • Secure vehicle-to-cloud boundary with device identity, OTA updates and PKI lifecycle.
  • Lead security assurance activities including tests, vulnerability management, and postmortems.

Skills

Backend engineering
Cloud security
AWS security
Kubernetes security
Go programming
Threat modeling
CI/CD security
Incident response
Identity & access management
Security governance

Education

Bachelor's degree

Tools

KMS
Secrets Manager
GuardDuty
Security Hub
CloudTrail
Config
EKS
ECS
ECR
Lambda

Job description

About ALSO.We’re ALSO, an electric mobility company originally conceived as a part of Rivian. We’re a passionate team of builders, dreamers, doers and innovators, focused on creating entirely new (not to mention, innovative and delightful) vertically integrated, small EVs designed to meet the global mobility challenges of today and tomorrow. Our mission is to inspire everyone to ride ALSO—replacing many local car, truck and SUV miles with ones on vehicles that are more affordable, more enjoyable and 10-50x more efficient.

About ALSO.We’re ALSO, an electric mobility company originally conceived as a part of Rivian. We’re a passionate team of builders, dreamers, doers and innovators, focused on creating entirely new (not to mention, innovative and delightful) vertically integrated, small EVs designed to meet the global mobility challenges of today and tomorrow. Our mission is to inspire everyone to ride ALSO—replacing many local car, truck and SUV miles with ones on vehicles that are more affordable, more enjoyable and 10-50x more efficient.

At ALSO, we are looking for a Staff Security Engineer for Cloud who wants to own security end to end — not advise on it, build it — for a connected, software-defined EV platform where nearly everything of value runs through the cloud: telemetry streaming in from vehicles in the field, remote diagnostics and updates, fleet intelligence, and the product APIs customers touch every day.

You'd set the security architecture and then build it yourself, in Go, alongside the backend team — equally comfortable writing a threat model, reviewing a Kubernetes admission policy, and shipping the service that enforces it. You'd be the person the company turns to for every question that starts with "is this secure," with the autonomy to actually answer it properly rather than just flag the risk and move on.

What You'll Do
  • Own cloud security end to end — strategy, architecture, implementation, and operations across AWS, Kubernetes, and our microservices platform — including threat modeling new systems in architecture reviews before the code exists
  • Design and implement identity and access at scale: workload identity, org-wide IAM, least privilege by default, secrets management, and certificate/key lifecycle, including mutual TLS between services and between cloud and vehicle
  • Harden containers and orchestration: image provenance, admission control, runtime and network policy, service mesh configuration, and clean isolation across microservices
  • Secure the software supply chain: SBOM generation, dependency and image scanning, signed artifacts, and CI/CD pipelines that fail closed on what matters and stay quiet on what doesn’t
  • Build the controls in Go — authorization services, policy enforcement, provisioning and rotation tooling — and serve as the DevSecOps function, writing guardrails and policy as code so other engineers move fast without routing every decision through security
  • Run detection and response: security logging and telemetry, meaningful alerting, runbooks, on-call for security incidents, and blameless postmortems that produce real fixes
  • Secure the vehicle-to-cloud boundary: device identity and provisioning, fleet-wide certificate rotation, secure OTA update paths, and anomaly and tamper detection at scale
  • Contribute to core backend work alongside the team, and own assurance — penetration tests, vulnerability management, evidence collection, and proportionate standards work that strengthens the product instead of slowing it down
What You'll Bring
  • 10+ years in backend and infrastructure engineering, with a substantial portion spent owning security in production
  • Expert, hands-on AWS: IAM, VPC and network design, KMS, Secrets Manager, GuardDuty, Security Hub, CloudTrail, Config, and org-level guardrails (SCPs), alongside core compute and data services (EKS, ECS, ECR, Lambda, DynamoDB, S3)
  • Deep Kubernetes and container security — RBAC, admission controllers, pod security standards, network policy, secrets handling, runtime detection, and image hardening — with real experience operating clusters, not just reading about them
  • Fast, fluent Go: you design, review, and ship production Go code today, not several years ago
  • Microservices and distributed systems security: service-to-service authentication and authorization, API gateway patterns, rate limiting, tenant isolation, and event-driven pipeline security
  • Identity protocols and applied cryptography in practice: OAuth2, OIDC, JWT, SAML, mutual TLS, and PKI with certificate lifecycle management at scale
  • Infrastructure and policy as code, with security gating built into CI/CD
  • Threat modeling and secure architecture review as routine practice, with specific examples of designs you\'ve changed, plus incident response you\'ve personally led from detection through postmortem
  • Demonstrated 0 to 1 ownership: you\'ve stood up a security function or program where none existed, without a large team behind you

The salary for this position ranges from $205,000 - $240,000 per year, depending on experience, qualifications, and location.

Perks & Benefits

  • Robust health coverage — excellent health, dental and vision insurance covered up to 100% by ALSO with FSA & HSA options
  • One Medical membership and dedicated insurance advocates
  • Rich fertility and family building benefits with Progyny
  • Flexible time off
  • 401(k) match
Why ALSO.

We’re passionate about helping the world find a better way to get there—wherever it is you’re headed.

We’re located in the heart of Silicon Valley and have brought together a world-class team from some of the biggest brands in the technology, automotive, cycling, outdoor recreation and retail spaces.

Together we’re working hands-on to imagine, design and build an entirely new solution to a global set of transportation challenges.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer, Cloud
Staff Security Engineer, Cloud

ALSO • Palo Alto (CA)

On-site
USD 205,000 - 240,000
Health insurance
Dental & Vision coverage
401(k) matching
+2
Staff Security Engineer, Cloud
Staff Security Engineer, Cloud

Also, Inc. • Palo Alto (CA), Northern (KY)

Hybrid
USD 205,000 - 240,000
Health coverage
One Medical membership
Fertility and family benefits
+2
Senior Full Stack Engineer, Cloud Platform
Senior Full Stack Engineer, Cloud Platform

Also • Palo Alto (CA)

On-site
USD 175,000 - 205,000
Health insurance
401(k) match
One Medical membership
+2
Staff Firmware Engineer, Platform Security
Staff Firmware Engineer, Platform Security

Also • Palo Alto (CA)

On-site
USD 200,000 - 240,000
Health/dental/vision
One Medical
Fertility benefits
+2
Staff Cloud Backend Developer
Staff Cloud Backend Developer

ALSO. • Palo Alto (CA)

On-site
USD 170,000 - 210,000
Robust health insurance
One Medical membership
Progyny fertility benefits
+2
Staff Cloud Backend Developer
Staff Cloud Backend Developer

Also, Inc. • Palo Alto (CA)

On-site
USD 170,000 - 210,000
Health coverage
One Medical membership
Fertility benefits with Progyny
+2
Staff Firmware Engineer, Platform Security
Staff Firmware Engineer, Platform Security

Also, Inc. • Palo Alto (CA), Northern (KY)

Hybrid
USD 200,000 - 240,000
Health insurance
One Medical
Fertility benefits
+2
Senior Full Stack Engineer, Cloud Platform
Senior Full Stack Engineer, Cloud Platform

Also, Inc. • Palo Alto (CA), Northern (KY)

Hybrid
USD 175,000 - 205,000
Health coverage
One Medical membership
Fertility benefits
+2
Staff Firmware Engineer, Platform Security
Staff Firmware Engineer, Platform Security

ALSO. • Palo Alto (CA)

On-site
USD 200,000 - 240,000
Robust health coverage
One Medical membership
Progyny fertility benefits
+2
Sr. Validation & Tools Engineer - Web & Cloud
Sr. Validation & Tools Engineer - Web & Cloud

ALSO. • Palo Alto (CA)

On-site
USD 170,000 - 200,000
Robust health coverage
Flexible time off
401(k) match
+2