Cloud Security Engineer
On-siteFlorida, United States or Dallas, Florida, United States
Job Summary
Design, implement, and maintain secure cloud infrastructure across AWS, Azure, and/or GCP by configuring firewalls, security groups, and network policies. Manage identity and access control policies, enforce least privilege access, and monitor for unauthorized permissions. Integrate security into CI/CD pipelines, automate compliance validation, and conduct vulnerability assessments to remediate misconfigurations. Monitor cloud environments for threats, respond to incidents, and develop detection rules for threat prevention. Ensure environments comply with standards like SOC 2, ISO 27001, and NIST while supporting security audits and documentation. Collaborate with Cloud Engineering, DevOps, and Security teams to shift security left and improve overall cloud security posture.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field
- 3+ years of experience in cloud security, infrastructure security, or DevSecOps roles
- Strong experience with AWS, Azure, and/or GCP security services
- Knowledge of IAM, network security, encryption, and cloud architecture principles
- Experience with CI/CD pipelines and DevOps tools
- Familiarity with Infrastructure as Code (Terraform, CloudFormation, ARM templates, etc.)
- Strong understanding of security monitoring and incident response
- Knowledge of vulnerability management and risk assessment practices
- Strong problem-solving and analytical skills
- Must currently reside in one of the approved locations listed above
Desired Qualifications
- Cloud certifications such as: AWS Certified Security – Specialty
- Microsoft Azure Security Engineer Associate
- Google Professional Cloud Security Engineer
- Experience with SIEM tools (Splunk, Sentinel, QRadar, etc.)
- Experience with container security and Kubernetes security tools
- Knowledge of DevSecOps platforms (GitHub Actions, GitLab CI/CD, Jenkins)
- Familiarity with Zero Trust architecture principles
- Experience with security automation and orchestration tools (SOAR)
- Knowledge of compliance frameworks such as SOC 2, ISO 27001, NIST, PCI-DSS, HIPAA
- Experience in regulated industries such as finance, healthcare, insurance, or enterprise SaaS
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.