Staff Cloud Security Engineer
X
XometryManufacturing technology
Location: Waltham, MA; Location Type: RemoteFull-TimeStaff
Salary$180,000- $200,000 annually + bonus
Apply NowOpens the employer's application page
Job Details
- Experience
- Minimum 8 years
- Required Skills
- AWSPythonKubernetesTerraform
Requirements
- Minimum 8 years of experience in cloud security, security engineering, or a related infrastructure security discipline.
- Hands-on experience with a cloud security posture management (CSPM) platform — CrowdStrike, Wiz, Prisma Cloud, Orca, or equivalent.
- Deep familiarity with AWS security architecture: IAM/SCP policy design, VPC networking, security groups, CloudTrail, and cloud-native security controls.
- Proficiency with infrastructure as code (IaC) tools such as Terraform, OpenTofu, or CloudFormation.
- Strong Python and shell scripting skills for security automation, detection rule development, and tooling integration.
- Hands-on Kubernetes security experience: securing and managing production clusters, including Network Policies, RBAC, and Admission Controllers.
- Experience with cloud-native SIEM solutions, including writing detection rules in Python or SQL.
- Experience securing microservices architectures, including service mesh security (Istio or Linkerd).
- Bachelor’s degree in Computer Science, Information Security, or a related field.
Responsibilities
- Own CrowdStrike Falcon configuration, ensuring policies are appropriately scoped, tuned, and generating actionable alerts.
- Partner with MDR to define alert routing, triage thresholds, and escalation logic, ensuring the right signals reach the right team.
- Monitor cloud environments (primarily AWS) for security posture drift: misconfigured IAM roles, overly permissive security groups, exposed storage, and non-compliant resource configurations.
- Secure Kubernetes clusters and containerized workloads: manage Network Policies, RBAC, Admission Controllers, and runtime detection for anomalous container behavior.
- Develop and enforce cloud security policies and standards for AWS infrastructure, ensuring secure and scalable deployments align with organizational risk posture.
- Evaluate and lead the implementation of additional detection tooling, including cloud SIEM platforms, designing detection rules and alerting pipelines.
- Manage infrastructure as code (IaC) security using Terraform or OpenTofu — ensuring IaC definitions meet security standards before deployment.
- Automate security posture checks and detection workflows using Python and shell scripting.
- Stay current with the evolving cloud threat landscape and translate emerging threats into detection coverage or posture improvements.
View Full Description & ApplyYou'll be redirected to the employer's site