Apply

Cloud Security Engineer

Posted 7 days agoViewed

View full description

💎 Seniority level: Senior, 7+ years

📍 Location: USA

💸 Salary: 145500.0 - 214000.0 USD per year

🔍 Industry: Software Development

🏢 Company: Stitch Fix👥 5001-10000💰 $11,850,773 over 7 years ago🫂 Last layoff 11 months agoE-CommerceRetailFashionApparel

🗣️ Languages: English

⏳ Experience: 7+ years

🪄 Skills: AWSAWS EKSCloud ComputingCybersecurityOAuthAPI testingServerlessCI/CDRESTful APIsLinuxDevOpsTerraformMicroservicesJSON

Requirements:
  • 7+ years of experience in cloud security, DevSecOps, or application security, with a focus on AWS.
  • Expert in AWS security services such as GuardDuty, Security Hub, Inspector, IAM, KMS, and AWS Organizations.
  • Deep experience with Infrastructure as Code (IaC), including Terraform and CloudFormation, to enforce security at scale.
  • Strong understanding of application security principles, including OWASP Top 10, SAST, DAST, and secure SDLC methodologies.
  • Proficient in DevSecOps tooling, such as SAST, DAST, SCA, IAST, and container security scanning tools.
  • Expert-level AWS knowledge: VPC design, IAM, KMS, EKS, Lambda, AWS Organizations.
  • Experience securing APIs, microservices, and serverless functions, ensuring proper authentication and authorization.
  • Proactive problem solver, able to diagnose security challenges across both cloud and application layers.
  • Excellent communication and collaboration skills, allowing you to effectively advise engineering and product teams on security best practices.
Responsibilities:
  • Design secure cloud and application architectures, ensuring security is embedded in both infrastructure and software development.
  • Integrate security automation into CI/CD pipelines and enforcing secure coding practices.
  • Work with engineering and product teams to proactively mitigate application security risks.
  • Design and manage AWS multi-account environments, ensuring minimal attack surface and robust logging/monitoring.
  • Implement AWS security best practices, leveraging services like GuardDuty, Security Hub, Inspector, and custom Lambda scripts for continuous threat detection.
  • Develop secure IaC templates (Terraform/CloudFormation) to enforce consistent security configurations.
  • Automate security controls to detect misconfigurations, vulnerabilities, and compliance violations (CIS, NIST, PCI-DSS).
  • Integrate application security testing (SAST, DAST, SCA, IAST) into CI/CD pipelines to detect vulnerabilities early.
  • Define secure coding guidelines and collaborate with engineering teams to ensure adherence.
  • Conduct threat modeling and secure code reviews to proactively mitigate application security risks.
  • Enforce API security best practices, including OAuth, JWT, rate limiting, and input validation.
  • Work closely with the Senior Security Architect to align cloud and application security with overarching security standards.
  • Partner with engineering, DevOps, and product teams to embed security into the SDLC and cloud infrastructure.
  • Educate development teams on secure coding, application security testing, and cloud security best practices.
Apply

Related Jobs

Apply

📍 United States, Canada

🧭 Full-Time

💸 120000.0 - 150000.0 CAD per year

🔍 Blockchain Infrastructure

🏢 Company: Figment👥 11-50HospitalityTravel AccommodationsArt

  • 3+ years of experience in Cloud Security, DevOps, or Platform Engineering.
  • Strong experience with AWS and/or GCP security principles.
  • Hands-on experience managing Kubernetes clusters.
  • Up-to-date knowledge of cloud security advisories.
  • Experience in scripting for automation.
  • Design, implement, and manage security controls for cloud infrastructure in AWS and GCP.
  • Develop and enforce security policies, IAM roles, and least privilege access across cloud environments.
  • Implement and maintain cloud security monitoring, logging, and alerting.
  • Secure Kubernetes workloads and conduct regular cloud security assessments.
  • Deploy and maintain cloud infrastructure using code.

AWSCybersecurityGCPKubernetesCI/CDTerraformScripting

Posted 10 days ago
Apply
Apply

📍 United States

💸 84000.0 - 132000.0 USD per year

🔍 Benefits technology and services

🏢 Company: Businessolver👥 501-1000💰 Private about 7 years agoAccountingFinancial ServicesInformation Technology

  • 4+ years of experience in securing cloud infrastructures in AWS.
  • 5+ years of security monitoring experience and incident response activities.
  • Experience with Linux and serverless environments.
  • Familiar with AWS Security principles and services such as AWS Config, IAM, WAF, GuardDuty, CloudFormation.
  • Understanding of automation tools like Ansible, Puppet, Chef, Terraform.
  • Proficient in a modern scripting language.
  • Familiarity with CI/CD platforms and version control systems.
  • Experience with container security and Kubernetes.
  • Development experience in Java or Python is a plus.
  • BS in Computer Science, CIS, Software Engineering, or related degree.
  • Build and manage a central security policy for cloud infrastructure.
  • Develop continuous audit solutions to validate systems against policies.
  • Create techniques for development teams to identify flaws pre-production.
  • Establish security standards based on best practices.
  • Respond to security incidents and provide on-call support.
  • Propose solutions that enhance business success and client satisfaction.
  • Guide and lead less-experienced technical staff.

AWSPythonCloud ComputingCybersecurityJavaKubernetesCI/CDLinuxTerraformAnsible

Posted 25 days ago
Apply