Staff Cloud Security Engineer

Posted 14hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Staff Cloud Security Engineer hardening AWS infrastructure and CI/CD for Beyond Finance, helping Americans escape crippling debt. Owning Wiz-based cloud security and vulnerability management.

Responsibilities:

  • Harden the security posture of the AWS environment and software development pipeline
  • Own cloud security posture across AWS using Wiz and AWS-native services, reducing risk across IAM, network segmentation, container security, secrets, and data exposure
  • Establish secure defaults in Infrastructure as Code through reusable modules, guardrails, and policy as code
  • Harden CI/CD pipelines in partnership with DevOps
  • Run vulnerability management across cloud and application findings, including intake, prioritization, SLA tracking, and remediation
  • Build scalable automation for ingestion, deduplication, prioritization, and developer-facing workflows
  • Instrument telemetry, alerting, and runbooks for owned systems
  • Operate and tune the WAF, including managed and custom rules, rate limiting, and bot mitigation
  • Partner with DevOps, Engineering, and the Application Security Engineer on preventative controls and application security work

Requirements:

  • 8+ years of hands-on security engineering across cloud security and vulnerability management
  • Strong AWS security background, including IAM, networking, container orchestration, and logging and audit
  • Hands-on experience securing CI/CD pipelines and Infrastructure as Code
  • Terraform required
  • Experience running or substantially contributing to a vulnerability management program
  • Working knowledge of OWASP Top 10 and threat modeling
  • Experience with Wiz, Cloudflare, GitHub Advanced Security, Spacelift, or AWS-native services is nice to have
  • Production WAF experience is nice to have
  • AI/ML security exposure is nice to have
  • Experience with secrets management platforms is nice to have
  • Identity security experience is nice to have
  • PCI-regulated or financial services experience is nice to have
  • Familiarity with Ruby on Rails, Python, or Go is nice to have
  • Ability to operate independently and drive projects without day-to-day oversight

Benefits:

  • Considerable employer contributions for health, dental, and vision programs
  • Generous PTO, paid holidays, and paid parental leave
  • 401(k) matching program
  • Merit advancement opportunities
  • Career development & training
  • Annual bonus eligibility