Full Job Description
Job Description
The Cybersecurity Engineer - Cloud is responsible for designing, implementing, and operating security controls that protect cloud-native platforms and workloads across public cloud environments (AWS, Azure, GCP). The role partners closely with engineering, DevOps, and architecture teams to ensure cloud services are secure by design, compliant with regulatory requirements, and resilient at scale.
This position combines hands-on engineering, security architecture, and risk-based decision-making within complex, distributed, and regulated environments.
In addition to cloud security responsibilities, this role provides security oversight and engineering support for AI-enabled capabilities used across the Pismo platform. The engineer ensures that adoption of Artificial Intelligence and Large Language Models (LLMs) is aligned with Visa security controls, Pismo data-protection principles, and global regulatory expectations.
This is a remote position. A remote position does not require job duties be performed within proximity of a Visa office location. Remote positions may be required to be present at a Visa office with scheduled notice.
Visa requires at least 3 days in office, expectations of these days will be confirmed by your Hiring Manager.
Qualifications
Basic Qualifications
• 2+ years of relevant work experience and a Bachelors degree, OR 5+ years of relevant work experience
Preferred Qualifications
• 3 or more years of work experience with a Bachelor's Degree or more than 2 years of work experience with an Advanced Degree (e.g. Masters, MBA, JD, MD)
• 5+ years of experience in cybersecurity, with hands-on responsibility for cloud or platform security.
• Demonstrated experience securing production workloads across multiple cloud providers (AWS, Azure, and/or GCP).
• Experience operating in regulated or high-availability environments is strongly preferred.
• Multicloud Security Expertise (Core Requirement)
Proven ability to design, review, and implement security controls across multicloud environments, including:
• Cloud Identity and Access Management (IAM), least-privilege access, and workload identity
• Network segmentation, service-to-service authentication, and mTLS
• Cloud encryption models and key management (KMS, HSM, certificate authorities)
• Experience with Cloud Security Posture Management (CSPM) and misconfiguration detection.
• Understanding of cloud-native logging, monitoring, and detection capabilities
• Infrastructure, Container & Platform Security
Hands-on experience securing:
• Kubernetes and container platforms
• Container image scanning and runtime security
• Infrastructure-as-Code (Terraform, CloudFormation, ARM)
• Ability to embed security controls into CI/CD pipelines and platform guardrails.
• Familiarity with configuration-drift detection and continuous compliance.
• Application & Data Protection
Strong understanding of:
• API security (OAuth/OIDC, token-based auth)
• Application-level encryption, tokenization, and hashing
• Data protection across storage, database, and file-system layers
• Ability to support secure software development lifecycle (SSDLC) practices, including SAST, SCA, and SBOM
Risk, Compliance & Governance:
• Working knowledge of security and compliance frameworks such as PCI DSS, ISO 27001, SOC 2, GDPR, or NIST.
• Ability to translate security findings into risk-based recommendations for engineering and leadership.
• Experience partnering with architecture, risk, and compliance teams
Tools, Technologies & Certifications (Preferred):
• Experience with cloud-security tooling (e.g., CSPM, container security, IAM platforms).
Cloud or security certifications are preferred but not mandatory, including:
• CCSK / CCSP
• AWS, Azure, or GCP Security certifications
• CISSP or equivalent
• Continuous learning mindset aligned with evolving multicloud security practices.
• Deep Knowledge of LLM Platforms (Mandatory)
Demonstrated hands-on and architectural knowledge of enterprise-grade AI and LLM platforms, including:
• Anthropic Claude
• OpenAI (ChatGPT, GPT APIs, enterprise offerings)
• Comparable LLM providers and managed AI services
This includes understanding:
• Platform security models and shared-responsibility boundaries
• API-based consumption vs managed SaaS usage
• Enterprise controls for data handling, logging, and access enforcement
U.S. Applicants Only
The estimated salary range for this position is $123,700.00 to $ 191,300.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity.Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program.
Work Hours
Varies upon the needs of the department.
Travel Requirements
This position requires travel 5-10% of the time.
Mental/Physical Requirements
This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers.