We are seeking a Cloud Security Engineer to strengthen the security posture of our cloud infrastructure through automation, infrastructure-as-code, and proactive risk identification. This role sits at the intersection of security engineering and cloud platform engineering — you will design and build tooling that prevents misconfigurations before they reach production, automate detection and response workflows, and continuously raise the bar on how our team scales security across a growing cloud footprint. Success in this role requires equal parts technical depth, ownership mentality, and a relentless drive to improve the processes around you.
Responsibilities
Design, build, and maintain secure cloud infrastructure using Terraform, embedding security guardrails directly into IaC modules and pipelines
Develop Python-based automation to detect, triage, and remediate cloud security findings at scale
Identify gaps in existing security processes and lead initiatives to streamline, automate, or eliminate manual toil
Build and maintain policy-as-code frameworks (e.g., OPA, Checkov, custom Terraform validators) to enforce security standards in CI/CD
Contribute to incident response for cloud-related events and drive root-cause-based process improvements afterward
Document tooling, runbooks, and architectural decisions so the broader team can operate and extend what you build
Requirements
SKILLS:
3+ years of hands-on experience securing cloud environments (AWS, Azure, or GCP)
Strong proficiency with Terraform, including module design, state management, and CI/CD integration
Production-quality Python skills with experience building automation, integrations, and tooling against cloud APIs
Deep understanding of cloud security fundamentals: IAM, network segmentation, encryption, logging, and identity federation
Demonstrated track record of identifying problems and driving improvements without being asked
Experience integrating security tooling into developer workflows (pre-commit, CI checks, PR automation)
Excellent written communication and the ability to influence engineering teams through code and clear documentation
Bonus: experience with detection engineering, SOAR platforms, Kubernetes security, or contributing to open-source security tools