Senior Cloud Security Engineer

Iterable Iterable · Enterprise · United States · Remote · Security & IT

Senior Cloud Security Engineer role focused on enhancing the security posture of an AI-powered customer engagement platform. Responsibilities include reviewing system designs, consulting with engineers, developing cloud security architecture, implementing automated security testing tools, promoting DevSecOps principles, and ensuring secure deployments through Infrastructure as Code. Requires strong experience in cloud security, Kubernetes, AWS services, and Terraform, with proficiency in Python or Go.

What you'd actually do

  1. Review system designs and implementations, and consult with engineers across the organization to identify and/or avoid security issues through alignment with security standards and best practices, document and ensure security issues are appropriately remediated
  2. Leverage subject matter expertise of systems and infrastructure to propose solutions and drive architectural improvements which address classes of security vulnerabilities
  3. Develop and implement cloud and infrastructure security architecture and contribute to overall strategy and roadmap plans
  4. Participate in the selection, design, development, implementation, and management of automated security testing tools, such as cloud security posture management and image vulnerability scanners
  5. Implement solutions that integrate into CI pipelines to shift security as far left as possible and raise concerns early to engineering teams.

Skills

Required

  • 5+ years hands-on-keyboard in Cloud Security, SRE, DevOps, DevSecOps, or Infra Engineering.
  • Strong working knowledge of Kubernetes and ecosystem tools such as helm, ArgoCD.
  • Production experience with AWS services, particularly AWS Organizations, AWS Identity (SSO), Identity and Access Management (IAM), Service Control Policies (SCPs), Virtual Private Clouds, Elastic Load Balancers, AWS CloudTrail, and Security Groups.
  • Proficiency with Terraform.
  • Experience developing custom actions or workflows in Github or Gitlab.
  • Solid understanding of cloud security vulnerabilities defense techniques and security best practices, including AWS security practices and present-day threats
  • Proficiency in a high level programming language, such as Python or Go
  • Familiarity with policy management tools such as OPA or Kyverno

Nice to have

  • SRE Experience
  • Scala or JVM ecosystem experience
  • Familiarity with common observability tools such as Datadog, Prometheus/Grafana
  • Experience with AWS EKS
  • Experience with Panther SIEM
  • Hands on work standing up Jupyter notebook instances, using Jupyter operationally.

What the JD emphasized

  • enterprise-grade security and compliance
  • security posture
  • cloud security capabilities
  • security by design
  • security standards and best practices
  • security issues
  • security vulnerabilities
  • cloud and infrastructure security architecture
  • automated security testing tools
  • cloud security posture management
  • image vulnerability scanners
  • shift security as far left as possible
  • DevSecOps principles
  • Infrastructure as Code (IaC) scanning
  • policy enforcement
  • secure and compliant
  • penetration tests
  • Cloud Security
  • SRE
  • DevOps
  • DevSecOps
  • Infra Engineering
  • cloud security vulnerabilities defense techniques
  • AWS security practices