Senior Engineer, Cloud Security
Workstreet - United States
Hiring: Senior Engineer, Cloud Security Company: Workstreet Location: United States Job Posted Time: 2026-09-16 17:26:40 Employment Type: Remote Target Skills & Keywords : ABAC, AWS, Azure, Azure DevOps, Azure Functions, CPT, CloudFormation, DAST, Encryption, FedRAMP, GCP, GDPR, GitHub Actions, IAM, Infrastructure as Code, LLM, Lambda, OIDC, Okta, Penetration Testing, Python, RBAC, SAML, SAST, SIEM, SOC 2, Terraform, Vault About the job Required Skills: •Engineer security via Infrastructure as Code - design and maintain reusable Terraform and CloudFormation modules for IAM, networking, and logging to build drift-resistant cloud environments. •Build enterprise cloud architectures - deploy and manage AWS multi-account structures including Organizations and SCPs, alongside Azure Hub-Spoke and Landing Zone architectures. •Architect identity and access management - implement least-privilege IAM using RBAC, ABAC, permission boundaries, JIT or PIM automation, and federated identity via Okta or Entra ID. •Execute direct vulnerability remediation - remediate cloud misconfigurations through active engineering changes, automated patching, and configuration drift correction. •Automate security operations and pipelines - build automated remediation workflows using Lambda, Azure Functions, and Python, integrating SAST, DAST, and secret scanning into GitHub Actions or Azure DevOps pipelines. •Configure native cloud security stacks - deploy and tune AWS GuardDuty, Security Hub, AWS Config, Azure Sentinel, and Defender for Cloud to build native logging pipelines for SIEM ingestion. •Manage network and encryption engineering - design VPCs, security groups, network segmentation, WAFs, and full-lifecycle encryption using AWS KMS and Azure Key Vault. •Implement technical NIST 800-53 controls - translate NIST 800-53, FedRAMP, and CMMC compliance criteria into hands-on technical controls across cloud environments. Qualifications: •Hands-on security builder - proven track record of deploying security infrastructure, writing OPA policies, and managing secrets in Vault or AWS Secrets Manager. •Cloud-native technical specialist - deep expertise in Azure and AWS nuances, capable of distinguishing compliance maps from functional technical controls. •Infrastructure as Code expert - proficient in Terraform, with demonstrated expertise in module versioning, state management, and provider security controls. •Identity and access authority - deep technical understanding of SAML, OIDC, cross-account IAM roles, and enforcing least privilege without disrupting developer workflows. •Articulate technical communicator with a strong verbal presence, able to lead technical workshops and clearly explain complex architecture to engineering teams. •Multi-account portfolio operator - thrives in fast-paced startup environments, balancing multiple client priorities and executing rapid remediation without perfect documentation. •What Will Help You Succeed •Active cloud security credentials - hold technical certifications such as AWS Certified Security Specialty, Azure Security Engineer Associate, or GCP Professional Security Engineer. •FIPS 140 encryption implementation: practical experience configuring and enforcing FIPS 140 standards across cloud services. •Federal enclave build experience - hands-on history building CMMC-compliant enclaves or FedRAMP security architectures. Compensation: •Flexible work environment (work from home / hybrid options) •Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!