Staff Cloud Security Engineer

Peloton Peloton · Consumer · Headquarters, NY · Security & Risk

Staff Cloud Security Engineer role focused on driving organization-wide cloud security strategy, architecting and implementing security controls across the SDLC, operationalizing multi-cloud hardening (AWS, GCP), securing Kubernetes clusters, and implementing real-time runtime defense. The role involves continuous monitoring, threat detection, incident response, and serving as a technical mentor.

What you'd actually do

  1. Drive organization-wide cloud security strategy by partnering with product and platform engineering teams to deliver mission-critical initiatives protecting end-user data.
  2. Serve as the primary escalation point for complex cloud security risks, architectural decisions, and high-risk findings, ensuring timely and effective remediation.
  3. Architect, implement, and enforce cloud security controls across the full SDLC, defining and evolving standards, reference architectures, and guardrails covering identity and access management, network segmentation, encryption, logging, and secrets management.
  4. Lead secure cloud migration and modernization efforts, operationalize multi-cloud hardening in AWS (Security Reference Architecture, Guard Duty, AWS Organizations, KMS CMK lifecycle) and GCP (Workload Identity Federation, VPC Service Controls), and ensure the security posture of Kubernetes/EKS clusters through Pod Security Standards, fine-grained RBAC with OIDC short-lived tokens, default-deny Network Policies, and Service Mesh enforcement (Istio).
  5. Implement real-time runtime defense using eBPF-based monitoring of syscalls, processes, and network connections at the kernel level.
  6. Drive continuous monitoring, threat detection, incident response, and forensic investigations.
  7. Serve as a technical mentor and thought leader, influencing the long-term cloud security roadmap while balancing security, reliability, developer experience, and operational scalability.

Skills

Required

  • CI/CD: Jenkins, TeamCity, GitHub, Argo CD, Spinnaker
  • Containers: Kubernetes, Docker, EKS, AKS
  • IaC: Terraform, CloudFormation, Chef, Ansible
  • AWS/Security: EC2, S3, Lambda, VPC, IAM
  • Vulnerability management
  • Programming languages: Python, Shell, PHP, PowerShell, Ruby
  • High Availability: Disaster recovery, DR Setup, High availability

Nice to have

  • GCP (Workload Identity Federation, VPC Service Controls)
  • Service Mesh enforcement (Istio)
  • eBPF-based monitoring

What the JD emphasized

  • cloud security strategy
  • architect, implement, and enforce cloud security controls
  • operationalize multi-cloud hardening
  • security posture of Kubernetes/EKS clusters
  • real-time runtime defense
  • continuous monitoring, threat detection, incident response