Senior Cloud Security Engineer

Posted 2 weeks ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Senior Cloud Security Engineer securing AWS, Kubernetes, and CI/CD platforms for Pax8’s AI and cloud marketplace serving SMBs. Defining security standards, controls, and architecture at scale.

Responsibilities

  • Review AWS, Kubernetes, CI/CD, and SaaS environments to identify security gaps, misconfigurations, and architectural weaknesses
  • Perform threat modeling, security architecture reviews, and cloud security assessments
  • Assess infrastructure against security baselines and drive remediation or formal risk acceptance
  • Validate security controls across cloud, identity, network, and platform layers
  • Establish and evolve cloud and platform security hardening standards
  • Develop reference architectures, ADRs, and security design guidance
  • Define and maintain secure patterns, guardrails, and baseline configurations
  • Define and enforce least-privilege access models across AWS and Kubernetes
  • Review IAM policies, RBAC models, identity federation, service identities, and cross-account trust boundaries
  • Assess and improve CI/CD security controls, secrets management, deployment protections, and pipeline trust boundaries
  • Review Infrastructure-as-Code patterns and recommend secure-by-default approaches
  • Validate network security controls, segmentation, ingress controls, and cloud networking architecture
  • Assess Kubernetes security controls and workload isolation
  • Maintain platform security posture visibility through metrics, reporting, and tracking
  • Track remediation progress and communicate risk in terms of business impact, exposure reduction, and blast radius
  • Partner with DevOps, SRE, and Engineering teams as a trusted advisor
  • Influence technical decisions through expertise, collaboration, and practical recommendations

Requirements

  • 7+ years of experience in Cloud Security, Infrastructure Security, Platform Security, Security Architecture, DevSecOps, or related disciplines
  • Experience assessing cloud environments and identifying security weaknesses, misconfigurations, or architectural risks
  • Extensive hands-on AWS expertise across IAM, VPC, EKS, KMS, Secrets Manager, CloudTrail, S3, logging, networking, and access controls
  • Proven Kubernetes security experience including RBAC, service accounts, workload identities, network policies, and workload isolation
  • Experience securing CI/CD pipelines and cloud-native delivery workflows
  • Strong understanding of threat modeling and risk-based security assessments
  • Experience writing or maintaining security standards, hardening baselines, reference architectures, or security design guidance
  • Strong Infrastructure-as-Code fluency, particularly Terraform
  • Ability to read and review Helm charts
  • Experience partnering with DevOps, SRE, Platform Engineering, or Infrastructure teams
  • Ability to operate independently and influence outcomes without formal authority
  • Legal right to work in the United States
  • Preferred: experience in large SaaS, technology, fintech, cloud-native, or highly regulated organizations
  • Preferred: experience with GitHub Actions, OIDC federation, secrets management, and deployment protection controls
  • Preferred: experience operating CNAPP, CSPM, or cloud security posture management platforms
  • Preferred: experience producing ADRs, security design documents, or architecture standards
  • Preferred: familiarity with AI platform security, agentic workloads, and AI-enabled development practices
  • Preferred: relevant certifications such as AWS Security Specialty, CCSP, CISSP, CKS, or equivalent

Benefits

  • Competitive salary
  • Annual performance bonus
  • Stock options / stock option eligibility
  • Comprehensive medical, dental, and vision insurance
  • 401(k) retirement plan with company contribution / employer match
  • Generous paid time off and company holidays
  • Flexible, open vacation
  • Paid sick time off
  • Extended leave for life events
  • Dedicated learning time with LinkedIn Learning access
  • Wellbeing initiatives
  • Employee assistance program
  • Employer-paid short- and long-term disability, life, and AD&D insurance
  • Career development programs
  • Employee-led resource groups
  • RTD Eco Pass for local Colorado employees
  • Internal development hub
  • Access to Learning & Development trainers, AI-powered tools, mentors, and cross-continent collaboration

Job type

Full Time

Experience level

Senior

Salary

$115,000 - $150,000 per year

Degree requirement

No Education Requirement

Tech skills

AWSCloudKubernetesTerraform

Location requirements

RemoteUnited States

Report this job

Found something wrong with the page? Please let us know by submitting a report below.