Senior Security Engineer II – Cloud & Data Security

Sigma Computing Sigma Computing · Data AI · New York, NY · Security / GRC / IT

Senior Security Engineer focused on securing a large-scale, cloud-native SaaS platform, with responsibilities spanning cloud security architecture, multi-cloud environments (AWS, GCP, Azure), threat modeling, incident response, IAM, data security controls, and automation. The role involves building security solutions, embedding controls into infrastructure-as-code, and developing automated guardrails. While the company offers an AI platform, this role is primarily about securing the infrastructure and data, not building AI models.

What you'd actually do

  1. Architectural Leadership: Partner deeply with infrastructure and engineering teams to embed security into development workflows, leading high-level technical discussions to guide security efforts and strategic priorities.
  2. Multi-Cloud Engineering: Design, implement, and continuously improve Sigma Cloud Security across AWS, GCP, and Azure environments with architect-level technical depth.
  3. Threat Modeling & IR: Conduct cloud threat modeling and demonstrate hands-on experience in Cloud Incident Response, including investigating and remediating malicious activity within cloud environments.
  4. Identity & Access: Build IAM and privileged access strategy (RBAC/ABAC, federation, least privilege, cross-account access), eliminating standing privilege and long-lived credentials. Develop and enforce IAM best practices, including zero-trust models and privileged access controls across IaaS and SaaS.
  5. Drive cloud data security controls including classification, encryption/KMS, masking/tokenization, access governance, retention/deletion, and exfiltration risk reduction across APIs and data pipelines.

Skills

Required

  • Cloud security architecture
  • Multi-cloud environments (AWS, GCP, Azure)
  • IAM
  • Data security
  • Infrastructure-as-code (Terraform)
  • Threat modeling
  • Incident Response
  • Network security
  • Scripting languages (Python, Go, PowerShell)
  • Container security
  • Kubernetes
  • CI/CD pipeline design

Nice to have

  • Experience securing data platforms (Snowflake, Databricks, BigQuery)
  • Experience in high-growth SaaS or data platforms Organizations
  • Prior experience in Platform Engineering, DevSecops
  • Professional-level cloud certifications

What the JD emphasized

  • builds security solutions—not just manages tools
  • automates aggressively
  • Minimum 7+ years in Security roles with at least 5+ years focused on Cloud security engineering,IAM, and Data security
  • Deep technical expertise in cloud architectures AWS/Azure/GCP
  • Strong infrastructure-as-code skills
  • Proven ability to demonstrate incident response experience specifically related to cloud-based malicious activity and breach remediation.
  • Advanced Cloud IAM expertise
  • Strong background in cloud network security
  • Strong proficiency in scripting languages (e.g., Python, Go, PowerShell) for automation, data analysis, and security tooling development.