Security Engineer, Cloud Security

Saronic · Defense · Austin, TX · Software

Senior Security Engineer to own the design, implementation, and continuous improvement of security guardrails across Saronic's cloud infrastructure (AWS, GovCloud). Responsibilities include security architecture, IaC standards, preventive/detective controls, IAM, secrets management, CI/CD security, compliance validation, and incident response. Requires 6+ years of cloud security experience, expertise in AWS security services and Terraform, and experience with regulated environments (GovCloud/FedRAMP).

What you'd actually do

  1. Own the security architecture for Saronic's AWS environments, including multi-account strategy, network segmentation, identity architecture, and data protection across commercial AWS and AWS GovCloud
  2. Design and maintain secure-by-default Terraform modules and IaC standards that teams adopt as the standard path, enforcing least privilege, secure defaults, and compliance requirements
  3. Implement preventive controls (SCPs, permission boundaries, policy-as-code) and detective controls (Config rules, CloudTrail analysis, GuardDuty) as a unified, layered security model
  4. Design and enforce IAM patterns across AWS accounts, services, and workloads including least-privilege policies, permission boundaries, cross-account access, federation, and service-to-service authentication
  5. Implement and govern secrets management using tools such as AWS Secrets Manager or Vault, integrated into CI/CD and runtime environments

Skills

Required

  • 6+ years of hands-on experience in cloud security engineering, infrastructure security, DevSecOps, or a closely related security engineering role
  • Expert-level proficiency with Terraform, including module design, state management, policy-as-code, and managing complex multi-environment configurations
  • Deep expertise in AWS security services and architecture, including IAM, Organizations, SCPs, Control Tower, CloudTrail, Config, GuardDuty, Security Hub, KMS, and VPC security
  • Demonstrated experience building security guardrails and reusable infrastructure patterns that engineering teams adopt without friction
  • Strong experience with CI/CD pipeline security, IaC review processes, and automated compliance validation
  • Experience operating in AWS GovCloud or FedRAMP-regulated cloud environments
  • Strong proficiency in Python, Go, Rust, or equivalent languages for building security automation and tooling
  • Ability to obtain and maintain a security clearance

Nice to have

  • Experience in defense, aerospace, robotics, autonomy, or other high-assurance environments
  • Experience designing multi-account AWS landing zones and organizational security architectures from the ground up
  • Hands-on experience with Kubernetes security, container security, and service mesh security in cloud-native environments
  • Familiarity with NIST SP 800-171, NIST SP 800-53, FedRAMP, or Cloud Computing SRG Impact Levels
  • Experience with infrastructure drift detection, automated remediation, and continuous compliance monitoring
  • Relevant certifications such as AWS Security Specialty, AWS Solutions Architect Professional, HashiCorp Terraform Associate/Engineer, CCSP, or CISSP

What the JD emphasized

  • security guardrails
  • AWS GovCloud
  • FedRAMP
  • security clearance