Senior Security Engineer II – Cloud & Data Security

Sigma Computing Sigma Computing · Data AI · New York, NY · Security / GRC / IT

This role is for a Senior Security Engineer focused on securing a large-scale, cloud-native SaaS platform. The engineer will be a subject matter expert in cloud security architecture across platform, IAM, network, workload, data, and AI enablement. Responsibilities include designing secure architectures, embedding controls into infrastructure-as-code, and building automated guardrails. The role emphasizes automation and building security solutions within AWS, GCP, and Azure environments, including threat modeling, incident response, IAM, data security, and managing security stack components. While the role involves AI enablement and using AI securely, its core function is cloud security engineering, not AI/ML development.

What you'd actually do

  1. Architectural Leadership: Partner deeply with infrastructure and engineering teams to embed security into development workflows, leading high-level technical discussions to guide security efforts and strategic priorities.
  2. Multi-Cloud Engineering: Design, implement, and continuously improve Sigma Cloud Security across AWS, GCP, and Azure environments with architect-level technical depth.
  3. Threat Modeling & IR: Conduct cloud threat modeling and demonstrate hands-on experience in Cloud Incident Response, including investigating and remediating malicious activity within cloud environments.
  4. Identity & Access: Build IAM and privileged access strategy (RBAC/ABAC, federation, least privilege, cross-account access), eliminating standing privilege and long-lived credentials. Develop and enforce IAM best practices, including zero-trust models and privileged access controls across IaaS and SaaS.
  5. Drive cloud data security controls including classification, encryption/KMS, masking/tokenization, access governance, retention/deletion, and exfiltration risk reduction across APIs and data pipelines.

Skills

Required

  • Cloud security engineering
  • IAM
  • Data security
  • AWS
  • GCP
  • Azure
  • Infrastructure-as-code (Terraform)
  • Container security
  • Kubernetes
  • Secure CI/CD pipeline design
  • Incident response
  • Cloud network security
  • Python
  • Go
  • PowerShell
  • CNAPP
  • WAF
  • SASE

Nice to have

  • Data platforms (Snowflake, Databricks, BigQuery)
  • High-growth SaaS or data platforms organizations
  • Platform Engineering
  • DevSecops
  • Professional-level cloud certifications

What the JD emphasized

  • builds security solutions—not just manages tools
  • automates aggressively
  • scale cloud security
  • Minimum 7+ years in Security roles with at least 5+ years focused on Cloud security engineering,IAM, and Data security
  • Deep technical expertise in cloud architectures AWS/Azure/GCP
  • Strong infrastructure-as-code skills
  • Proven ability to demonstrate incident response experience specifically related to cloud-based malicious activity and breach remediation.
  • Advanced Cloud IAM expertise
  • Strong background in cloud network security
  • Strong proficiency in scripting languages (e.g., Python, Go, PowerShell) for automation, data analysis, and security tooling development.