Active listing
Senior Security Engineer - Cloud Security
About the role
Senior Security Engineer – Cloud Security at Cyara will lead the design, implementation, and optimization of security controls across AWS, Azure, and GCP environments. Working closely with infrastructure, product, and engineering teams, the role focuses on secure-by-default cloud architecture, IAM strategy, policy-as-code, and automation using Terraform, OPA, and AWS native services. Responsibilities include hardening cloud resources, securing the software supply chain, managing alerts from CSPM and SIEM tools, and leading incident response for cloud incidents. The engineer will also drive vulnerability management, logging, audit readiness, and advisory across cross-functional teams. Candidates must hold a bachelor’s degree in computer science or related field, have 8+ years of cloud security experience, deep knowledge of CIS Benchmarks, CSA CCM, NIST 800-53, and hands‑on experience with CSPM/CNAPP tools such as Wiz, Prisma Cloud, and AWS Security Hub. Proficiency in AWS security services, Kubernetes, serverless, IaC security, and CI/CD pipeline security is required. Certifications like AWS Certified Security – Specialty, CCSP, CCSK, or CISSP are highly desirable.
What you’ll do
- Design secure-by-default cloud architectures and integrations, ensuring all new infrastructure meets rigorous security standards before deployment.
- Design and review cloud IAM strategies by defining roles, least-privilege policies, service accounts, and access boundaries across AWS, Azure, and GCP.
- Lock down storage buckets, network security groups, load balancers, databases, and managed services to prevent accidental exposure and ensure compliance.
- Secure the software supply chain by reviewing pipeline permissions, secrets handling, and artifact signing to prevent unauthorized deployments to production.
- Manage intake of alerts from CSPM, SIEM, and cloud-native tools (GuardDuty, Defender, SCC), distinguishing real threats from operational noise.
- Lead investigations into cloud-specific incidents, including compromised credentials, suspicious API calls, crypto-mining activity, or exposed resources.
What you’ll bring
- Bachelor's degree in computer science, Information Security, or related field; advanced degree preferred.
- Minimum 8 years of experience in information security focused on Cloud Security Architecture, Engineering, and Posture Management.
- In-depth knowledge of CIS Benchmarks, CSA CCM, and NIST 800-53 for cloud environments.
- Extensive experience with CSPM and CNAPP tools (e.g., Wiz, Prisma Cloud, AWS Security Hub) and AWS security services (IAM, GuardDuty, KMS, SCPs, WAF).
- Proven experience implementing IaC security scans and Policy-as-Code using Terraform, OPA, or CloudFormation; securing Kubernetes (EKS) and serverless architectures.
Nice to have
- AWS Certified Security – Specialty
- ISC2 CCSP (Certified Cloud Security Professional)
- CSA CCSK
- CISSP
Skills
Education
Bachelor's