Cloud Security Engineer

Applied Intuition Applied Intuition · Robotics · Sunnyvale, CA · Security & IT Operations

Seeking a Cloud Security Engineer to secure multi-cloud environments (AWS, Azure, GCP, OCI) with a focus on Kubernetes hardening, guardrails, IAM policies, and CSPM. Responsibilities include deploying and maintaining infrastructure security, implementing Kubernetes security best practices, developing IAM policies, ensuring container security, managing IaC security, maintaining CSPM tools, automating compliance checks, and monitoring runtime security.

What you'd actually do

  1. Securely deploy and maintain infrastructure across diverse multi-cloud environments (AWS, Azure, GCP, OCI), establishing cloud-specific robust guardrails to prevent insecure deployments and configurations.
  2. Implement and enforce security best practices and policies specifically tailored for Cloud native Kubernetes clusters, including granular Role-Based Access Control (RBAC), network policies, and admission controllers.
  3. Develop, implement, and enforce robust security policies and procedures specifically related to user authentication and authorization across all systems.
  4. Ensure the security of container images, registries, and runtime environments through the effective use of tools like Docker, Podman, and various container scanning solutions.
  5. Manage infrastructure and security policies through version-controlled Git repositories using tools such as Terraform, CloudFormation, or AWS CDK to ensure consistent, auditable, and secure deployments.

Skills

Required

  • 5+ years of industry experience in software engineering or security engineering, with a focus on designing and building secure, production-grade cloud systems.
  • Extensive, demonstrable experience with Kubernetes from a security perspective (e.g., securing containerized workloads, enforcing RBAC, and cloud-native secret management).
  • Implemented AI to rapidly identify, validate, and remediate security issues without impact.
  • Deep operational security experience with AWS (mandatory), with highly preferred practical experience deploying and securing infrastructure across Azure, GCP, or OCI.
  • Proficiency in Infrastructure-as-Code (IaC) tools such as Terraform, CloudFormation, or AWS CDK to deploy and manage environments.
  • Hands-on expertise in configuring, monitoring, and driving remediation through Cloud Security Posture Management (CSPM) platforms like Wiz.
  • A strong background in designing and enforcing complex Identity & Access Management (IAM) and least-privilege architectures across both multi-cloud and traditional on-premises directory environments.
  • Experience working with container security, image scanning, and runtime protection tools.

Nice to have

  • Advanced industry certifications related to cloud and container security (e.g., AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), Certified Kubernetes Administrator (CKA)).
  • Strong proficiency in programming or scripting languages commonly used for security automation and backend development (e.g., Go/Golang, Python, or C++).
  • Prior experience automating compliance frameworks and generating audit evidence across a multi-cloud footprint.
  • Experience securing and operating in air-gapped or highly constrained on-premises computing environments.

What the JD emphasized

  • AWS (mandatory)