Cloud Security Engineer
Summary
Design and enforce cloud security baselines for AWS, monitor risks, drive remediation, and automate detection to protect a regulated crypto exchange serving 18M users.
Responsibilities:
- Responsible for the overall planning, construction, and continuous optimization of AWS cloud environment security architecture, covering account systems, IAM, VPC, compute, storage, container, and data security.
- Responsible for the design, configuration, and operation of WAF and DDoS protection systems, including AWS WAF, AWS Shield, CloudFront, Route 53, and third-party security products.
- Design and implement network isolation strategies, including multi-account, multi-VPC, production and non-production environment isolation, subnet segmentation, east-west access control, egress control, and zero-trust access.
- Responsible for the configuration and auditing of Security Group, NACL, Transit Gateway, PrivateLink, VPN, Direct Connect, and other network security components.
- Proficient in using AI technologies and tools to carry out cloud security operations, achieving cloud resource risk identification, security monitoring, anomalous behavior analysis, intelligent alert triage, and incident response automation, improving the efficiency of security threat detection and handling.
- Build cloud security monitoring and response capabilities, discovering and handling security risks based on CloudTrail, GuardDuty, Security Hub, Config, VPC Flow Logs, and other tools.
- Drive the implementation of cloud resource configuration baselines, vulnerability management, key management, log auditing, data encryption, and disaster recovery strategies.
- Participate in cloud security incident response, attack tracing, risk assessment, and remediation tracking.
- Drive infrastructure as code and security automation, integrating security checks into Terraform, CloudFormation, CI/CD, and other processes.
- Collaborate with R&D, operations, network, and AI teams to provide security architecture review and launch support for business systems.
Requirements:
- Bachelor's degree or above, majors in computer science, cybersecurity, software engineering, or related fields preferred.
- 5+ years of experience in cloud security, network security, or cloud platform operations.
- Familiar with AWS security architecture and core services, including IAM, Organizations, Control Tower, VPC, EC2, EKS, S3, KMS, CloudFront, WAF, Shield, CloudTrail, GuardDuty, Security Hub, and Config.
- Familiar with TCP/IP, DNS, HTTP/HTTPS, TLS, VPN, routing, load balancing, firewalls, and common network attack and defense principles.
- Able to independently design network isolation and access control solutions across multiple accounts, regions, and environments.
- Familiar with WAF rule design, bot protection, API protection, rate limiting strategies, and DDoS emergency response.
- Familiar with Kubernetes, container, and cloud-native security, with experience in EKS network policies, image security, RBAC, and runtime security.
- Possess scripting or automation skills, familiar with at least one of Python, Go, or Shell.
- Familiar with infrastructure as code tools such as Terraform and CloudFormation.
- Possess good security risk analysis, troubleshooting, documentation, and cross-team communication skills.
- Hold certifications such as AWS Certified Security – Specialty, AWS Solutions Architect, CISSP, CCSP, CISA, etc.
- Experience with large-scale AWS multi-account governance, Landing Zone, or cross-region cloud architecture construction.
- Experience with generative AI, LLM, MLOps, GPU/Kubernetes cluster security operations.
- Familiar with zero trust, SASE, micro-segmentation, service mesh, and cloud-native network security products.
- Familiar with security platforms such as SIEM, SOAR, CSPM, CNAPP, CWPP.
- Have practical experience in security incident response, offense-defense exercises, or red-blue team confrontation.
Preferred Qualifications
Skills
- AI
- API
- Automation
- AWS
- Bash
- CI/CD
- Cissp
- Cloud
- Cloud Native
- Cloud Security
- CloudFormation
- Cryptocurrency
- Cybersecurity
- DNS
- EC2
- EKS
- Emergency Response
- Firewall
- Generative AI
- IAM
- Infrastructure as Code
- Kubernetes
- LLM
- MLOps
- Network Security
- Python
- RBAC
- Risk Assessment
- S3
- Sase
- SIEM
- TCP/IP
- Terraform
- TLS
- VPC
- VPN
- WAF
- Zero Trust
As published by lever
Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, Other website, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL