The Cloud & Application Security Engineer will design, implement, validate, and operate security controls across our cloud infrastructure, applications, and software delivery pipelines. This role will partner with DevOps, various Engineering, and Security teams to build secure-by-default platforms that enable developers while reducing organizational risk.
This is a hands-on role requiring strong experience in cloud security architecture, application security testing, CI/CD pipeline hardening, and infrastructure-as-code security.
What will you do? - Design, implement, and mature secure cloud architectures across AWS, Azure, and GCP, with a primary focus on GCP.
- Develop, audit, and harden cloud infrastructure, including IAM, networking, organization policies, logging, and Terraform-based Infrastructure-as-Code.
- Provide security architecture reviews and guidance for cloud applications, APIs, infrastructure, DevOps, and AI-assisted development.
- Perform application security assessments, secure code reviews, and hands-on testing of web applications, APIs, and cloud services using automated and manual techniques to identify vulnerabilities and drive remediation.
- Identify, prioritize, and remediate cloud and application vulnerabilities, including critical and zero-day threats.
- Lead evaluations, proof-of-concepts, and implementation of cloud and application security technologies.
- Secure AI platforms and AI-assisted development by implementing appropriate security controls and reviewing AI-assisted applications for security risks.
- Partner with Security Operations to improve cloud detection, monitoring, incident response, and security visibility.
- Provide exceptional experiences for our guests, partners, and team members, including by adhering to our appearance and presentation guidelines while on-site.
What do you need to succeed? - 4-6 years of related experience.
- Bachelor's degree, or equivalent combination of education and experience.
- Experience securing enterprise cloud environments across AWS, Azure, and/or GCP, including Kubernetes.
- Strong understanding of cloud architecture, IAM, networking, cloud security controls, and Infrastructure-as-Code.
- Experience integrating security into CI/CD pipelines using Terraform and modern DevOps platforms.
- Proficiency in Python, PowerShell, Bash, Go, or a similar language, or demonstrated ability to leverage AI-assisted engineering tools to develop automation and security solutions.
- Hands-on experience with Wiz or a comparable CSPM/CNAPP platform.
- Experience with application security, including secure SDLC, threat modeling, secure code reviews, SAST, DAST, SCA, secret scanning, vulnerability management, remediation, and web application security testing.
- Strong understanding of web application security, REST APIs, authentication (OAuth/OIDC/JWT), and OWASP Top 10.
- Familiarity with AI security concepts and securing enterprise AI platforms or AI-assisted applications.
- Security certifications (e.g., CISSP, CCSP, AWS Security Specialty, Google Professional Cloud Security Engineer, AZ-500, CSSLP, or GWAPT) are a plus.
Pay Range (Burbank): $130,000-$155,000
Pay Range (Las Vegas): $120,000-$140,000
#LI-Onsite
Pay Range
$120,000-$140,000 USD
At MSG, we recognize the importance of upskilling employees' talents and strengths so they can drive their careers forward. We are proud to offer a robust set of tools and resources to help employees understand their interests and purpose, harness their talents and obtain the skills they need to reach the next step in their careers. Growth and longevity for our employees are top priorities here.
We value diversity and are looking for extraordinary employees of all backgrounds!