PowerPlan

Senior Cloud Security Engineer

PowerPlan$130K — $155K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in cloud security or security engineering with in-depth AWS and Azure experience.
  • Experience implementing security frameworks (CIS, NIST, SOC 2) at scale and driving remediation.
  • Strong background in IAM design (SAML, OIDC), RBAC, ABAC, and privileged access management.
  • Proficient in Python and PowerShell for automation and writing Terraform modules.
  • Track record of integrating security requirements into CI/CD pipelines as infrastructure-as-code guardrails.
  • Experience developing a risk-based or IAM program from early or fragmented stages.
  • Excellent communication skills for presenting to technical and executive audiences.
  • Experience leading incident response and post-incident corrective actions.

Responsibilities

  • Conduct a full assessment of cloud security compliance within the first 30 days and develop a prioritized remediation roadmap by day 90.
  • Map the current IAM landscape and present a phased maturity roadmap within 90 days, with initial implementation in 6 months.
  • Transform security framework requirements into automated, enforceable production code using Terraform and scripts.
  • Serve as the security expert in architecture reviews and train teams on cloud security best practices.
  • Lead incident response for cloud security events, ensuring thorough resolutions and lessons learned are documented.

Benefits

  • Hybrid work model with flexibility to work from home and office hours as needed.
  • Opportunities for professional growth and skills development in cloud security.
  • Impact on shaping compliance and security practices from the ground up.
Full Job Description
Overview

This role offers a rare chance to build cloud security and IAM maturity programs from the ground up rather than caretake an existing one, with the Senior Cloud Security Engineer owning compliance, identity strategy, and security automation across both AWS and Azure as a senior individual contributor. Success here means shaping the roadmap leadership acts on, not just executing someone else's plan, with visible influence across Cloud Engineering, Information Security, and executive stakeholders within the first 90 days.

Responsibilities

KEY PERFORMANCE OBJECTIVES (FIRST 12 MONTHS)

1: Cloud Security Framework Compliance (First 90 Days, Ongoing Through Year One)

Outcome: Complete an assessment of current security framework compliance across AWS and Azure in the first 30 days, deliver a prioritized remediation roadmap by day 90, and keep compliance scores improving through the first 6 months and beyond.

Impact: Closes framework gaps before they surface as audit or compliance findings, and gives leadership a clear, prioritized view of security posture instead of an ad hoc issue list.

How: By running structured assessments against framework benchmarks, maintaining security baselines and hardening guides, and translating framework requirements into Terraform modules and IaC guardrails that get enforced automatically.

IAM Maturity Roadmap (First 90 Days, Phase 1 By 6 Months)

Outcome: Map the current state of IAM across AWS, Azure, and integrated tooling in the first 30 days, present a phased IAM maturity roadmap to leadership by day 90, and deliver Phase 1 (least-privilege enforcement, access reviews in place) within the first 6 months.

Impact: Moves the organization from fragmented, ad hoc access to one governed by least-privilege and centralized oversight, closing off a major source of unmanaged access risk before it becomes an incident.

How: By assessing current IAM architecture end-to-end, then building out role-based and attribute-based access, federation, and access review processes essentially from the ground up.

Security-as-Code and Automation (Ongoing, Established Within First 6 Months)

Outcome: Turn security framework requirements and IAM controls into enforced, production-grade code, Terraform modules and Python/PowerShell automation, so compliance and access control are checked and enforced automatically rather than tracked in manual checklists.

Impact: Eliminates the gap between documented policy and actual environment state, and frees the security function from re-doing the same manual checks every cycle.

How: By writing Terraform modules that enforce controls as code integrated into CI/CD pipelines, and by building Python and PowerShell automation for assessments, remediation workflows, and compliance reporting.

4: Security Governance and Cross-Functional Partnership (Ongoing)

Outcome: Serve as the security subject matter expert in cloud architecture reviews and change advisory processes, and mentor Cloud Operations and Engineering teams on security best practices, so security judgment shapes decisions before they ship rather than gatekeeping after the fact.

Impact: Embeds security into how the organization designs and changes its cloud environment, and builds security capability across other teams rather than making the security function a bottleneck.

How: By reviewing architecture and change proposals as the security voice in the room, coaching Cloud Operations and Engineering on secure defaults and practices, and presenting security strategy in terms both technical and executive audiences can act on.

5: Cloud Security Incident Response Leadership (Ongoing)

Note: this objective is derived primarily from the job description rather than the hiring manager's intake answers.

Outcome: Lead incident response for cloud security events end-to-end, from detection through resolution, and drive the post-incident review process to convert findings into concrete follow-up actions.

Impact: Shortens the time from detection to containment during real security events, and turns each incident into a source of durable improvement rather than a one-off fire drill.

How: By acting as incident commander or lead responder for cloud security events, coordinating with Cloud Operations and Engineering during response, and documenting and tracking corrective actions after each incident closes.

Qualifications
  • 8+ years of experience in cloud security, infrastructure security, or security engineering, with deep hands-on experience across both AWS and Azure.
  • Demonstrated experience implementing security frameworks such as CIS, NIST, or SOC 2 at scale, including running assessments and driving remediation to closure.
  • Strong IAM design and implementation background, including federation (SAML, OIDC), RBAC, ABAC, and privileged access management.
  • Proficiency in Python and PowerShell for security automation, and hands-on experience writing Terraform modules that enforce controls as code.
  • A track record of translating security requirements into infrastructure-as-code guardrails integrated into CI/CD pipelines.
  • Experience building or maturing a risk-based or IAM program from an early or fragmented state.
  • Excellent written and verbal communication skills, comfortable presenting security strategy to both engineers and executive leadership.
  • Experience leading incident response for security events and driving post-incident corrective action.

Please note that this is a hybrid role that involves a combination of onsite work from our corporate office as well as work from home. While we strive to accommodate flexible working arrangements when sensible, there will be times when onsite work is required. This could include scheduled office days, team meetings, client meetings, or special events.

 

About PowerPlan

PowerPlan is a software company that provides financial management solutions for the energy industry. Their products include asset management software, tax management software, and budgeting and forecasting tools. The company was founded in 1994 and is headquartered in Atlanta, Georgia. PowerPlan's mission is to help energy companies optimize their financial performance through the use of technology.
Learn more about PowerPlan
Size
500 employees
Industry
Net Income
$5 million
Founded
1994
5 Year Trend
+20%
Revenue
$50 million
NASDAQ

Similar Jobs

More Jobs at PowerPlan

More Information Technology Jobs

Find similar Senior Cloud Security Engineer jobs: