Cloud Security Engineer
On-siteDallas, Texas, United States
Job Summary
Conduct security risk assessments for cloud systems, implement OWASP and NIST-aligned controls, and perform threat modeling for cloud-enabled applications. Propose technical guardrails to prevent unauthorized access, evaluate third-party tools for compliance, and design secure cloud workloads. Integrate security into CI/CD pipelines, partner with IT Risk and Engineering teams, and support incident response for cloud-related threats. Develop security standards, runbooks, and architecture documentation while assisting with audits and regulatory compliance activities in a regulated financial environment.
Required Qualifications
- 3+ years of experience in cloud security, application security, or a combination of both
- Hands-on experience securing cloud-native infrastructure and applications
- Experience with DevSecOps practices and integrating security into CI/CD pipelines
- Understanding of cloud architecture concepts (IaaS/PaaS/SaaS) and the ability to apply security principles across cloud environments
- Familiarity with OWASP (including guidance for cloud-native applications) and NIST frameworks
- Experience in regulated environments (financial services or FINRA preferred)
Desired Qualifications
- Strong communication skills across technical and non-technical stakeholders
- Experience with AWS, Azure, or other major cloud platforms
- Certifications such as AWS Security Specialty, CISSP, or CCSP
- Experience with SAST/DAST tools
- Exposure to cloud governance and risk frameworks
- Familiarity with cloud-specific threats such as misconfiguration, data exfiltration, and identity/access compromise
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.