Cloud Security Engineer

Brinc Drones Inc

$120K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-8 years of security engineering experience with a focus on AWS
  • Hands-on experience with AWS security services like GuardDuty and IAM
  • Demonstrated experience with SOC 2 or ISO 27001 compliance
  • Proficient in at least one SIEM platform such as Splunk or Elastic
  • Scripting skills in Python or Bash
  • Experience in Google Workspace security
  • Strong written communication skills for policies and reports

Responsibilities

  • Conduct a full AWS security posture assessment and deliver a remediation roadmap
  • Activate and tune AWS Security tools across all accounts
  • Enforce least-privilege IAM and audit roles
  • Enable AWS Config Rules for automated remediation of misconfigurations
  • Design a secrets management strategy
  • Establish a vulnerability management program
  • Own cloud infrastructure incident response processes

Benefits

  • Comprehensive medical, dental, and vision plans for employees and families
  • 401K plan
  • Maternity and paternity leave
  • Flexible Time Off for exempt employees
  • Flexible work environment
  • Orca pass available for those in the Puget Sound
  • Free parking at Seattle office
  • Free snacks, drinks, and espresso at Seattle office
Full Job Description

About this Role:

We are seeking a Cloud & Security Engineer to own and mature the security posture of BRINC's AWS environment and corporate infrastructure. This is a hands-on, high-ownership role for a strong individual contributor who thrives on building - someone who wants to shape how security is done at a growing company, not maintain what someone else already built. You will be the primary security practitioner at Brinc, responsible for turning passive AWS tooling into active threat detection, strengthening our SOC 2 program, and scaling our security posture alongside the business. From tuning GuardDuty and locking down IAM to implementing Google Workspace DLP and authoring the policies that govern how we protect data - this role spans cloud and corporate security with meaningful impact across both. You'll work closely with our IT Support, Network Engineering, and Engineering leadership.

Key Responsibilities:
  • Conduct a full AWS security posture assessment - IAM, S3 bucket policies, VPC security groups, exposed endpoints, and logging gaps - and deliver a prioritized remediation roadmap
  • Activate and tune AWS Security tools across all accounts and regions
  • Enforce least-privilege IAM - eliminate wildcard permissions, audit all existing roles, and implement role-based access patterns
  • Enable AWS Config Rules and automated remediation for common misconfigurations - public S3 buckets, unencrypted volumes, unrestricted security groups
  • Design and implement a secrets management strategy
  • Establish a vulnerability management program for cloud workloads
  • Own cloud infrastructure incident response - detection, triage, containment, and post-incident review
  • Implement DLP policies - data classification, external sharing controls, and external forwarding restrictions
  • Manage and mature the Zero Trust / VPN solution
  • Own SIEM selection and deployment; configure alerting and on-call
  • Implement phishing-resistant MFA (hardware keys or passkeys) for privileged accounts
  • Conduct annual security awareness training and quarterly phishing simulations
  • Maintain security policies: Acceptable Use, Access Control, Incident Response, Vulnerability Management, and Data Classification
  • Own SOC 2 Type II continuous compliance and conduct a controls gap assessment
  • Partner with Engineering to implement security controls in the SDLC - SAST, dependency scanning, and secrets detection in CI/CD pipelines
  • Own the vendor security review process - evaluate third-party tools for risk before procurement
  • Maintain a risk register and report quarterly
  • Build and own the Incident Response Plan - define severity levels, escalation paths, and communication templates
Qualifications:
  • 5-8 years of security engineering experience with a strong AWS focus
  • Hands-on experience with AWS security services - GuardDuty, Security Hub, CloudTrail, Config, IAM, and Service Control Policies
  • Demonstrated SOC 2 or ISO 27001 readiness experience - ideally as primary technical lead
  • Proficiency in at least one SIEM platform - Splunk, Elastic, Panther, or equivalent
  • Scripting/automation ability in Python or Bash
  • Google Workspace security and administration experience
  • Strong written communication - security policies, runbooks, and executive summaries
Preferred Skills
  • Relevant certifications: AWS Security Specialty, CISSP, CCSP, or CISM
  • Experience with IaC security scanning (Checkov, tfsec) and CI/CD pipeline security integration
  • Familiarity with compliance automation platforms such as Drata or Vanta
  • Experience at a startup scaling from Series A to Series C
  • Familiarity with network segmentation and OT/corporate network boundary design

If you're interested in this role and in joining BRINC, we hope you'll apply. We'd love to review your application and get to know more about you!

Benefits and perks listed below may vary based on the nature of your employment with BRINC and/or the country within which you work

  • Comprehensive medical, dental and vision plans for our employees and their families
  • 401K plan
  • Maternity and paternity leave
  • Flexible Time Off (Exempt) / Paid time off (Non-Exempt)
  • Flexible work environment
  • Orca pass (for those in Puget Sound)
  • Free parking (Seattle office)
  • Free snacks, drinks and espresso (Seattle office)

Similar Jobs

More Jobs at Brinc Drones Inc

  • Electrical Engineer, RF
    $90K — $130K *
    Seattle, WA 98115 (King County)
    Telecommunications & Hardware
    In-Person
  • Manufacturing Engineer
    $70K — $95K *
    Seattle, WA 98115 (King County)
    Manufacturing & Automotive
    In-Person
  • Cloud Security Engineer
    $120K — $150K *
    Seattle, WA 98115 (King County)
    Information Technology
    In-Person
  • Sales Engineer
    $134K — $164K *
    Remote
    Technical Services
    Remote in United States

More Information Technology Jobs

Find similar Cloud Security Engineer jobs: