Cloud Security Engineer

5 days, 3 hours ago
Full-time
Senior
DevOps and Infrastructure
WorkWave

WorkWave

WorkWave provides field service management software solutions to automate business operations, improve efficiency, and enhance customer experiences through a suite of products like PestPac® and WorkWave Service™.

Professional Services
251-1K
Founded 1984

Description

  • Lead deployment and optimization of AWS Control Tower, Security Hub, and AWS WAF for a secure multi-account strategy.
  • Own cloud security outcomes across AWS, Azure, and limited GCP, including landing zone standards, guardrails-as-code, detection coverage, and remediation automation.
  • Design and implement secure-by-default cloud patterns, hardened Terraform modules, reference architectures, and baseline configurations.
  • Collaborate with AppSec to secure EKS and ECS environments, including runtime protection, image scanning, and least-privilege orchestration.
  • Perform baseline assessments of the cloud environment and deliver prioritized recommendations to close security gaps.
  • Lead least-privilege IAM design and enforcement across AWS accounts and workloads.
  • Develop secure configuration standards, documentation, and operational procedures for cloud services.
  • Partner with security operations to centralize and improve cloud telemetry from tools such as CloudTrail, GuardDuty, and VPC Flow Logs.
  • Align cloud controls with internal standards and external compliance requirements such as ISO 27001 and SOC 2, including audit-ready evidence collection.
  • Manage secure access and configuration for third-party security vendor tools and participate in on-call incident response for cloud security issues.
  • Build and run the cloud vulnerability management program for AWS and Azure workloads, container images, and base AMIs.
  • Own CSPM and MDR onboarding, coverage validation, tuning, and remediation workflow improvements.
  • Design and enforce secure secrets, keys, and credential management patterns, including KMS governance and automated rotation.
  • Secure the CI/CD and software supply chain with policy-as-code, identity federation, artifact integrity controls, and developer-friendly guardrails.
  • Build cloud incident playbooks, run tabletop exercises, and ensure forensics readiness and break-glass access controls.
  • Establish minimum security baselines for Azure and GCP and help secure hybrid connectivity with data center environments.
  • Define cloud security metrics and use them to track coverage, misconfigurations, MTTR, control adoption, and vulnerability SLAs.
  • Mentor engineers and improve security literacy across platform and DevOps teams through reviews and enablement.

Requirements

  • 5–8+ years of experience in Information Security, including at least 3+ years focused on AWS Cloud Security.
  • Deep hands-on experience designing and securing AWS environments and core services such as IAM, VPC, S3, and KMS.
  • Experience with AWS security services such as GuardDuty, Inspector, and Config.
  • Strong hands-on experience with Terraform for cloud infrastructure management.
  • Proven experience securing containerized workloads in EKS or ECS.
  • Willingness to provide basic security support for an existing Azure environment; deep Azure expertise is not required.
  • Ability to assess a complex environment and create a practical roadmap to improve security.
  • Ability to work collaboratively with engineers and solve problems in a consultative, partnership-oriented way.
  • Ability to translate technical configurations into clear, repeatable documentation and procedures.
  • Strong drive to automate manual security tasks and reduce human error.
  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent work experience.
  • AWS Certified Security – Specialty, Azure security certification, or a related certification is highly desirable.

Benefits

  • $120,000 - $145,000 annual salary range.
  • Health and dental insurance.
  • 401(k) with company match.
  • Flexible Time Off policy or generous PTO plan, plus paid holidays.
  • Up to 4 weeks of paid bonding leave.
  • Tuition reimbursement.
  • Employee Assistance Program with free 24/7/365 counseling, financial counseling, legal guidance, and adoption assistance.
  • 24/7 virtual medical care through Teladoc.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

[Job - 29022] Senior Cloud Application - GoLang/Python, Brasil

CI&T 5K-10K Internet Software & Services

CI&T is hiring a Senior Developer in Golang/Python (AWS) to work on a financial services project building scalable cloud applications in Brazil.

AWS Go Kubernetes Microservices Python
3 hours, 25 minutes ago

Senior / Staff Software Engineer - Parser Team

Stellar Cyber 51-250 Professional Services

Stellar Cyber is hiring a Senior or Staff Software Engineer to own parser development for its AI-driven cybersecurity platform, turning diverse security logs into normalized data that powers detection and analytics.

Apache Spark AWS Azure C++ Cybersecurity Docker GCP Hadoop Java JSON Kafka Kubernetes LLM Python Ruby SIEM XML
4 hours, 51 minutes ago

IAM Engineer - SailPoint ISC (Remote in the US)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is hiring a full-time Identity Governance and Administration Engineer to implement and enhance SailPoint ISC/IDN identity governance solutions for enterprise clients.

Active Directory JSON REST API SAP SOAP XML
4 hours, 55 minutes ago

Sr. Network Security Engineer III (Clearable) (6563)

MetroStar 251-1K IT Services

MetroStar is hiring a Sr. Network Security Engineer III to secure and harden mission-critical federal network environments while supporting secure mission delivery for a high-visibility customer.

Agile Cisco Fortinet IDS IPS
12 hours, 14 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers