Staff Security Engineer
On-siteNew York City, New York, United States
Job Summary
Own the technical strategy and architecture for cloud security across CIH's multi-cloud environment, setting direction for other security and platform engineers. Design safe-by-default infrastructure patterns, paved-road tooling, and automated guardrails to enable fast engineering without compromising security. Architect scalable controls across AWS, Azure, and GCP, including identity, network segmentation, and container/Kubernetes security. Drive adoption of AI-powered security tooling and governance to defend against AI-enabled threats while harmonizing security posture across previously separate Compass and Anywhere stacks. Act as the technical escalation point for CNAPP tooling strategy and lead response for high-severity cloud security events, embedding threat modeling early in the development lifecycle. Mentor senior and mid-level engineers through documentation and technical coaching rather than one-off reviews. Represent Security in cross-functional forums to drive risk tradeoffs, roadmap prioritization, and audit readiness with Engineering leadership, Compliance, and Legal.
Required Qualifications
- 8+ years in security engineering roles
- 4+ years focused specifically on cloud security architecture at scale
- Demonstrated experience owning cloud security strategy or architecture for an organization of significant scale
- Deep, production-grade expertise with AWS security services (IAM, EC2, VPC, container services including ECR, ECS, EKS)
- Strong working knowledge of Azure security controls
- Hands-on experience deploying and operationalizing a CNAPP or equivalent cloud security platform (e.g., Wiz, Orca Security, Lacework, Upwind) at an organizational level
- Strong proficiency in at least one programming language (e.g., Python, Go) used to build production-grade security automation and tooling
- Deep fluency in core security principles — least privilege, defense-in-depth, zero trust, and security monitoring
- Strong experience with containerization (Docker) and Kubernetes security at scale
- Demonstrated experience mentoring engineers and influencing technical direction beyond your immediate team
- Experience securing environments through a merger, acquisition, or major infrastructure consolidation
- Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes
Desired Qualifications
- Experience with GCP, OCI, or designing cloud-agnostic, multi-cloud security architectures
- Experience operating in a post-M&A environment
- Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes
- Relevant certifications (e.g., AWS Security Specialty, CISSP, OSCP)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.