We are seeking a proactive, hands-on Cloud Security Engineer to serve as the primary security partner for our Engineering and DevOps teams. In this role, you will be the \"North Star\" for secure cloud configuration, moving beyond simple alert triaging to building sustainable security foundations. You will bridge the gap between high-level security architecture and daily engineering execution, ensuring our AWS and Azure environments are resilient, compliant, and automated.
Key Responsibilities
Lead the deployment and optimization of AWS Control Tower, Security Hub, and AWS WAF to establish a secure multi-account strategy.
Own cloud security outcomes across AWS (primary), Azure (secondary), and limited GCP, including secure landing zone standards, guardrails-as-code, detection coverage, and remediation automation.
Design and implement reusable, secure-by-default cloud patterns that allow engineering teams to deploy safely without constant security intervention.
Collaborate with the AppSec Architect to secure EKS and ECS environments, focusing on runtime protection, image scanning, and least-privilege orchestration.
Perform a comprehensive baseline assessment of the current cloud environment to identify gaps and provide actionable, prioritized recommendations.
Lead design and enforcement of least-privilege IAM architecture across AWS accounts and workloads.
Develop and maintain secure configuration standards, documentation, and operational procedures that enable engineering teams to consistently deploy and operate cloud services securely.
Partner with security operations to ensure security telemetry from AWS environments is complete, centralized, and actionable (CloudTrail, GuardDuty, VPC Flow logs, etc.).
Ensure cloud configurations and controls align with internal security standards and external compliance requirements (ISO 27001, SOC 2, etc.).
Manage secure access and configuration for security vendor tools (vulnerability scanners, assessment platforms, etc.) within the cloud environment.
Participate in an on-call rotation for one week at a time and serve as primary SME for cloud security incidents (IAM compromise, exposed keys, misconfigurations, etc.).
Build and run the cloud vulnerability management program for AWS and Azure workloads, container images, and base AMIs.
Own onboarding, coverage validation, and tuning of CSPM and MDR integrations across AWS, Azure and GCP.
Design and enforce secure secrets management patterns (AWS Secrets Manager/Parameter Store/Vault), automated rotation, and least-privilege secret access.
Secure the software delivery pipeline end-to-end, including identity federation for CI/CD, policy-as-code enforcement for Terraform and Kubernetes, artifact integrity controls (signing/provenance), and secure dependency/source controls.
Build cloud-native incident playbooks (IAM compromise, crypto-mining, data exposure, suspicious network activity) and run periodic tabletop exercises.
Establish minimum viable security baselines for Azure and GCP (identity, logging, storage, network, key management) and ensure telemetry parity into centralized detection.
Define and report on key cloud security metrics (coverage, misconfiguration trends, MTTR, control adoption, vulnerability SLAs).
Mentor other engineers and raise baseline security literacy in platform/DevOps teams through patterns, reviews, and internal enablement.
Required Qualifications
5–8+ years of experience in Information Security, with at least 3+ years focused specifically on AWS Cloud Security.
AWS Deep Dive: Deep hands-on experience designing and securing AWS environments, core services (IAM, VPC, S3, KMS) and security-specific services (GuardDuty, Inspector, Config).
IaC Proficiency: Strong hands-on experience with Terraform for managing cloud infrastructure.
Please let Workwave know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.