Cloud Security Engineer
Job Description
Our Security team is growing and we have an immediate opening for a Cloud Security Engineer with a strong focus on cloud-native security architecture and design. In this role, you will lead the effort to design, build, and secure our cloud infrastructure, establish robust cloud architecture security standards, and implement infrastructure-as-code (IaC) security controls directly across our cloud environments. Reporting to the Director of IT and IS, this role will be a multi-faceted function that assists in maintaining cloud posture, executing core cloud security functions, and acting as a technical expert in architecting secure, scalable cloud systems. The ideal candidate is a self-motivated individual that is great at task and time management, and is excited to build cloud security directly into our infrastructure from the ground up.
What would I be doing?
As a key member of the Security team, you will collaborate closely with engineering and security leadership to design, build, and maintain secure cloud architecture. You will drive cloud-native security initiatives by embedding infrastructure-as-code (IaC) security controls, automated compliance scanning, and cloud configuration hardening across all environments, serving as a cross-functional partner to ensure robust security throughout our cloud ecosystem.
On any given day you could be:
Monitor and analyze cloud-specific threat landscapes; proactively identify and mitigate risks related to public cloud service misconfigurations.
Maintain cloud security posture by monitoring and triaging alerts from CSPM (Cloud Security Posture Management) and cloud-native security tools; conduct forensic investigations.
Work in a cross function capacity with our DevOps team to automate security monitoring and alerting solutions directly into the CI/CD pipeline using Infrastructure-as-Code.
Integrate automated vulnerability scanning and security testing directly into the development lifecycle to ensure continuous security feedback for engineering teams.
Coordinate cross-functional teams for vulnerability remediation efforts.
Design and audit cloud-native security controls to ensure continuous compliance and adherence to regulatory frameworks (HIPAA, HITRUST, SOC).
Proactively monitor and evaluate security configurations of systems and applications for continuous improvement and compliance.
Participate in the full security incident response lifecycle, including containment, eradication, and recovery.
Partner with software engineering teams to provide security design consultation, embedding secure-by-design principles into cloud architecture and application features.
Qualifications
5 to 8+ years of dedicated Security Engineering experience with a strong focus on AWS security, cloud-native architecture, and DevSecOps
Demonstrated experience building and architecting security infrastructure from the ground up, serving as the primary architect and functional owner of the security domain
Proven track record implementing cloud-native security tooling (e.g., CSPM, CWPP) and embedding automated security controls into CI/CD deployment pipelines
Proficiency in Python, Terraform, and Containerization strategies such as Kubernetes and Docker
Strong understanding of SaaS risk management and hardening processes as well as experience in DLP implementations and management
Previous experience working within a startup environment, with excellent verbal and written communication skills to address security concerns across internal stakeholders
Impress us more
CISSP, CNAPP, or related certifications
Experience in development or implementation of new tooling using the latest available resources or technologies
Experience implementation or use of CSPM tools such as Wiz, Orca, or AWS security tools suite
Experience with implementation and tuning of SIEM and event management tools
Experience in the digital healthcare industry
The base salary range for this role varies by location and is aligned to market benchmarks.
Candidates located in higher-cost labor markets, including California, Washington, New York, New Jersey, Connecticut, Massachusetts, and Washington, DC represent the middle to high end of the range, while candidates located in all other U.S. locations represent the low to middle end of the range.
Final compensation is determined based on location, experience, skills, and internal equity.
This role is eligible for a 10% target annual bonus, resulting in the following base salary and Total Target Compensation (TTC) ranges:
Base Salary: $120,000 - $135,000
*Total Target Compensation (TTC): Total Cash Compensation (including base pay, variable pay, commission, bonuses, etc.) Additionally, stock options, paid benefits, and employee perks are part of your total rewards.