Senior Engineer, Cloud Security

Workstreet

$120K — $145K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in cloud security engineering, with hands-on work in Azure and AWS.
  • Proven expertise in Infrastructure as Code, particularly with Terraform and CloudFormation.
  • Deep understanding of identity and access management, including RBAC and federation.
  • Strong skills in vulnerability remediation and cloud security operations automation.
  • Excellent communication abilities for technical discussions with clients and engineering teams.

Responsibilities

  • Develop and maintain reusable Terraform and CloudFormation modules.
  • Construct and manage multi-cloud enterprise architectures in AWS and Azure.
  • Implement IAM solutions based on least-privilege principles.
  • Remediate vulnerabilities through engineering changes and patching.
  • Automate security operations and DevOps pipelines for cloud environments.
  • Deploy and fine-tune native cloud security tools for logging and monitoring.
  • Design and manage network security and encryption configurations.

Benefits

  • Career development with mentorship and training opportunities.
  • Reimbursement for approved training and certification courses.
  • Competitive compensation with performance reviews and bonuses.
  • Significant growth opportunities in an early-stage company.
  • Remote-first culture allowing collaboration from anywhere.
Full Job Description
The Opportunity

Workstreet is seeking a Senior Engineer, Cloud Security who is a builder at heart with deep technical expertise in cloud infrastructure engineering, with a strong emphasis on Azure and multi-cloud architectures. This is a hands-on, high-impact engineering role focused on designing and deploying security infrastructure, building hardened landing zones, automating identity lifecycles, and authoring reusable Terraform modules rather than performing audit assessments.

The successful candidate will integrate rapidly into client environments, taking direct ownership of cloud security engineering tasks, vulnerability remediation, and client engagements within their first 15 days. Working directly with client engineering leads during U.S. Eastern Time business hours, you will lead technical discussions, execute automated security operations, and ensure every environment achieves drift-resistant, code-defined security excellence.

What You'll Do

  • Engineer security via Infrastructure as Code - design and maintain reusable Terraform and CloudFormation modules for IAM, networking, and logging to build drift-resistant cloud environments.
  • Build enterprise cloud architectures - deploy and manage AWS multi-account structures including Organizations and SCPs, alongside Azure Hub-Spoke and Landing Zone architectures.
  • Architect identity and access management - implement least-privilege IAM using RBAC, ABAC, permission boundaries, JIT or PIM automation, and federated identity via Okta or Entra ID.
  • Execute direct vulnerability remediation - remediate cloud misconfigurations through active engineering changes, automated patching, and configuration drift correction.
  • Automate security operations and pipelines - build automated remediation workflows using Lambda, Azure Functions, and Python, integrating SAST, DAST, and secret scanning into GitHub Actions or Azure DevOps pipelines.
  • Configure native cloud security stacks - deploy and tune AWS GuardDuty, Security Hub, AWS Config, Azure Sentinel, and Defender for Cloud to build native logging pipelines for SIEM ingestion.
  • Manage network and encryption engineering - design VPCs, security groups, network segmentation, WAFs, and full-lifecycle encryption using AWS KMS and Azure Key Vault.
  • Implement technical NIST 800-53 controls - translate NIST 800-53, FedRAMP, and CMMC compliance criteria into hands-on technical controls across cloud environments.
  • Drive client-facing technical ownership - interface directly with client engineering teams, lead architectural workshops, and manage multiple client engagements simultaneously.

Who You Are

  • Hands-on security builder - proven track record of deploying security infrastructure, writing OPA policies, and managing secrets in Vault or AWS Secrets Manager.
  • Cloud-native technical specialist - deep expertise in Azure and AWS nuances, capable of distinguishing compliance maps from functional technical controls.
  • Infrastructure as Code expert - proficient in Terraform, with demonstrated expertise in module versioning, state management, and provider security controls.
  • Identity and access authority - deep technical understanding of SAML, OIDC, cross-account IAM roles, and enforcing least privilege without disrupting developer workflows.
  • Articulate technical communicator with a strong verbal presence, able to lead technical workshops and clearly explain complex architecture to engineering teams.
  • Multi-account portfolio operator - thrives in fast-paced startup environments, balancing multiple client priorities and executing rapid remediation without perfect documentation.

What will help you succeed

  • Active cloud security credentials - hold technical certifications such as AWS Certified Security Specialty, Azure Security Engineer Associate, or GCP Professional Security Engineer.
  • FIPS 140 encryption implementation: practical experience configuring and enforcing FIPS 140 standards across cloud services.
  • Federal enclave build experience - hands-on history building CMMC-compliant enclaves or FedRAMP security architectures.
  • Container runtime security mastery - experience implementing runtime security controls and vulnerability scanning across containerized environments.

What We Offer

  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.

What You'll Need to Thrive

  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM-5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.

Hiring and Selection Process

  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet's operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.

Similar Jobs

More Jobs at Workstreet

More Information Technology Jobs

Find similar Senior Engineer, Cloud Security jobs: