Cloud Security Engineer
You will own and improve AWS security controls across accounts, regions, and services. You will build secure infrastructure defaults, integrate automated checks into deployments, manage cloud security telemetry and secrets, investigate threats, remediate findings, and support audits and access reviews.
Responsibilities
- Own and continuously improve AWS security posture across accounts, regions, and services
- Review and contribute to infrastructure-as-code modules that encode security defaults
- Integrate automated security checks into the deployment pipeline
- Own cloud-side security telemetry, including CloudTrail, GuardDuty, Security Hub, Config Rules, VPC Flow Logs, and S3 access logging
- Develop and tune detection logic for cloud-specific threats
- Partner on alert fidelity, incident response runbooks, and AWS-level investigations
- Govern secrets management and manage KMS key policies, rotation, and envelope encryption patterns
- Drive remediation of findings from AWS Inspector, Security Hub, and third-party CSPM tooling
- Maintain benchmarks aligned to CIS AWS Foundations
- Support audit and compliance activities and conduct regular access reviews
Requirements
- 4+ years of experience in cloud security, cloud engineering, or a security-focused infrastructure role
- Hands-on expertise with AWS security services including IAM, SCP, GuardDuty, Security Hub, CloudTrail, Config, KMS, WAF, Inspector, and VPC
- Experience writing infrastructure as code with Pulumi, Terraform, CDK, or equivalent
- Understanding of AWS networking and misconfiguration attack surface
- Proficiency in Python, TypeScript, or Go for automation and tooling
- Ability to evaluate architectural decisions for security risk and communicate findings clearly
- Familiarity with Pulumi and TypeScript-based stacks
- Familiarity with Web3, blockchain infrastructure, or crypto-sector threat models
- Experience securing containerized workloads on ECS or EKS, including image scanning and runtime security
- AWS security or solutions architect certification
- Exposure to SOC 2 Type II or PCI-DSS cloud control requirements
Benefits
- Equity
- Unlimited PTO
- Health, vision, and dental coverage
- 401k match
- New MacBook Pro, display, and accessories