Job DescriptionWe are seeking a skilled security engineer with a strong cloud and application security background to lead and support the secure design, deployment, and governance of cloud-based systems. This role will serve as a key bridge across IT Risk, Cloud Security, Cloud Engineering, and Application Development teams, ensuring cloud services are implemented securely within a regulated financial environment.
What will you do:- Identify, assess, and mitigate security risks associated with cloud systems and services
- Implement controls aligned to OWASP guidance for cloud-native applications and NIST frameworks
- Perform threat modeling for cloud-enabled applications
- Propose and validate technical guardrails to prevent unauthorized cloud access and support secure cloud development
- Identify and assess risk from unsanctioned cloud tool usage across the enterprise
- Evaluate third-party cloud tools for risk and compliance
- Design and secure cloud-based workloads
- Integrate security into CI/CD pipelines
- Partner with IT Risk, Cloud Security, and Engineering teams
- Support incident response for cloud-related threats
- Develop security standards, runbooks, and architecture documentation
- Support audits and regulatory compliance activities
What you will have:- 3+ years of experience in cloud security, application security, or a combination of both
- Hands-on experience securing cloud-native infrastructure and applications
- Experience with DevSecOps practices and integrating security into CI/CD pipelines
- Understanding of cloud architecture concepts (IaaS/PaaS/SaaS) and the ability to apply security principles across cloud environments
- Familiarity with OWASP (including guidance for cloud-native applications) and NIST frameworks
- Experience in regulated environments (financial services or FINRA preferred)
- Strong communication skills across technical and non-technical stakeholders
Preferred Qualifications:- Experience with AWS, Azure, or other major cloud platforms
- Certifications such as AWS Security Specialty, CISSP, or CCSP
- Experience with SAST/DAST tools
- Exposure to cloud governance and risk frameworks
- Familiarity with cloud-specific threats such as misconfiguration, data exfiltration, and identity/access compromise
What we give you in return:Not many teams can say that they support people's dreams coming to life. We happen to do that every day. And as important as we know your career is, we recognize that there's a whole lot more to life. To ensure that our employees can make the most of their time outside of working hours, we offer a competitive salary and for full-time roles, a benefits package including:
- Inclusive health, dental, vision, and life insurance plans built to support diverse lifestyles, offer preventative care, and protect against hardship.
- Easy access to mental health benefits to meet our team members and their families where they are.
- 20+ days of paid time off (PTO), paid holidays, and 2 paid wellness days to give our employees the time they need to stay close with their loved ones, recharge, and give back to their communities.
- 401(k) savings plan with a generous company contribution (up to 5%), and access to a financial professional to offer our employees the opportunity to plan-ahead for a strong financial future well beyond their working years.
- Paid parental leave to support all team members with birth, adoption, and fostering.
- Health Savings and Flexible Spending Account options to help you save money on healthcare, daycare, commuting, and more.
- Employee Assistance Program (EAP), LifeLock, Pet Insurance and more.
- Paid caregiver leave to provide time away from work when caring for an ill or recovering family member.
- Additional benefits such as an Employee Assistance Program (EAP), identity theft protection (LifeLock), pet insurance, and other voluntary benefits to provide extra peace of mind