freehire launches on Product Hunt on 26 August.

Follow →

Senior Cloud Security Engineer

Open 18d

Summary

Design and implement automated cloud security controls, container security, and Security as Code for AWS/GCP environments at a global enterprise marketing platform.

Yext (NYSE: YEXT) is the enterprise agentic marketing platform. Built on the world's most comprehensive structured data platform for local businesses, Yext gives brands and their partners the visibility intelligence to win every moment of discovery – across AI and traditional search. Yext's API-first architecture connects structured data to APIs, MCP servers, and generative interfaces, so partners and developers can build purpose-built experiences on the same infrastructure powering Yext's own products. Thousands of brands and digital marketing partners in financial services, healthcare, retail, hospitality, and food rely on Yext to manage, measure, and optimize visibility at scale. For more information, visit .

Yext is actively seeking a Senior Cloud Security Engineer reporting to the Manager of Product Security within the Cyber Security Office. This role will serve as a core pillar of our Product and Infrastructure Security program, shifting our focus toward robust Cloud Security automation, container security, and Security as Code. The role will enable product, engineering, IT, and security teams to make the right architectural decisions by implementing automated security controls, managing advanced cloud security tools, and leading security incident response efforts. In this role, you will also assist other Cyber Security leaders in driving a culture of security awareness within Yext, promote DevSecOps best practices, and champion cloud compliance initiatives.

What You'll Do

  • Drive Cloud Security Maturity: Lead the maturity of our Cloud and Enterprise Security programs by proactively identifying architectural infrastructure gaps and developing optimized, automated solutions.
  • Security as Code & Guardrails: Design, deploy, and maintain immutable cloud security controls across AWS and GCP environments using Infrastructure as Code (IaC) tools like Terraform.
  • Container & Orchestration Security: Define, implement, and monitor security baselines for containerized workloads and orchestration platforms, focusing on Docker and Kubernetes runtime security.
  • CI/CD & DevSecOps Automation: Integrate automated security testing tools (SAST, DAST, dependency, and secret scanning) directly into engineering deployment pipelines.
  • Vulnerability & Patch Management: Oversee the cloud vulnerability scanning program, prioritizing vulnerabilities based on runtime risk and coordinating comprehensive remediation processes across engineering teams.
  • Threat Modeling & Architecture Reviews: Lead comprehensive security architecture reviews and threat modeling sessions for cloud-native applications, providing actionable technical recommendations to Product and Engineering partners.
  • Policy & Compliance: Author and contribute to cloud security policies, procedures, and standards while mapping technical controls to compliance frameworks like SOC2 and ISO 27001.

What You Have

  • Experience: 6+ years of relevant work experience in Cloud Security Engineering or Product Security
  • Cloud Infrastructure Expertise: Deep technical knowledge and hands-on implementation experience managing security controls within AWS and/or GCP environments.
  • Infrastructure as Code: Proven experience utilizing Terraform, CloudFormation, or Pulumi to deploy and manage secure infrastructure.
  • Container Security Proficiency: Practical experience securing Kubernetes environments, managing network policies, and scanning container images.
  • Security Automation: High proficiency in security automation using Python, Go, PowerShell, or Bash scripting to eliminate manual tasks.
  • Framework Familiarity: Strong alignment with security frameworks and standards such as NIST, ISO 27001, or CIS benchmarks.
  • Communication & Collaboration: Strong communication skills and a proven history of collaborating effectively with Engineering, IT, and Product stakeholders to build high-trust partnerships.

Nice To Have But Not Required

  • SIEM & Log Analysis: Strong understanding of centralized logging architectures, SIEM platforms, and data analysis for identifying anomalies.
  • DFIR & Frameworks: Practical knowledge of cloud DFIR methodologies and advanced application of the MITRE ATT&CK framework to detect and remediate modern threat vectors.
  • Certifications: CCSP, AWS Certified Security - Specialty, Google Professional Cloud Security Engineer, or equivalent cloud security certifications.

In today's dynamic threat environment, software firms are increasingly acknowledged as a highly-targeted industry for cyberattacks due to the confidentiality and sensitivity of customer data, as well as the immediacy in which that data is needed to perform their operational duties. Given Yext’s vital role within the software ecosystem, protection of data is paramount in ensuring high-trust relationships with customers, partners, and vendors.

#LI-RK1

Yext is an equal opportunity employer committed to building a results-driven, engaging culture where every employee has the opportunity to contribute to the success of the Company, perform at the highest possible level, and grow their skills and capabilities. Yext welcomes employees and applicants of all backgrounds and demographics, and does not engage in discrimination on the basis of any protected characteristic recognized under applicable law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. The Company believes a broad variety of life experiences across the Yext team is critical to its mission to help every business in the world be visible everywhere customers search. By seeking out fresh perspectives and fostering a positive interview experience and employee experience, Yext can remain at the forefront of innovation, and better serve its customers.

It is Yext’s policy to provide reasonable accommodations to people with disabilities as required by applicable law. If you have a disability that requires an accommodation in completing this application, interviewing, or participating in the employee selection process, please complete this form.

Security Alert

All legitimate Yext communications come from @yext.com email addresses. Messages from other domains (for example, @yext.team) are not authorized and are likely fraudulent. If you receive a message that seems suspicious, do not share personal information, click on links, or provide payment. Instead, please report the communication to [email protected].

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location

  • How did you hear about this job? choose one
  • Have you been employed by Yext in the past? choose one
  • LinkedIn Profile optional
  • Website optional
  • Desired salary
  • Are you legally authorized to work in the country where the job is located? choose one
  • Will you now or in the future require visa sponsorship for employment visa status? choose one
  • Prospective Talent and Job Applicant Privacy Notice choose any
  • City
  • Are you open for relocation? choose one
  • Country choose one
  • Current address optional
  • Current Employer
  • Years of Experience: Total Amount
  • Years of Experience: Relevant Experience
  • Current Title optional
  • Notice Period
  • Are you currently serving notice period choose one
  • Skill Sets written answer
  • Current Fixed Remuneration
  • Current Variable Remuneration
  • Highest Qualification choose one · optional
  • University optional

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available