Staff Cloud Security Engineer

Emploi pas sur LinkedIn

🕒 il y a 1 mois

🇺🇸 États-Unis – Télétravail

💵 $137 275 - $190 000 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Hotel Engine

Hotel Engine

201 - 500 employés

Fondée en 2018

🛍️ eCommerce

🚗 Transport

💰 €65 000 000 Series B en 2021-12

eCommerce • Transport • Travel

Hotel Engine est une plateforme performante qui simplifie les voyages d'affaires en permettant aux entreprises de réserver, gérer et économiser facilement sur leurs besoins de déplacement. La plateforme offre un accès à plus de 750 000 hôtels dans le monde entier, permettant des réservations fluides pour divers groupes, des petites équipes aux grands événements corporatifs. Avec des fonctionnalités telles que des rapports centralisés, des options de paiement flexibles et un support dédié, Hotel Engine vise à rationaliser l'expérience de voyage pour les organisations et les voyageurs individuels, garantissant des économies considérables de temps et d'argent.

Description

• Cloud Security Architecture & Hardening: Lead security hardening across AWS and GCP environments, including identity and access management, network segmentation, logging, monitoring, configuration hygiene, and secure cloud architecture patterns. You will help define standards that scale across teams and cloud platforms. • Cloud Risk Ownership: Own and mature Engine’s approach to identifying, prioritizing, and remediating cloud security risks. You will assess systemic risk, separate high-priority issues from low-value noise, and drive practical remediation in partnership with infrastructure and engineering teams. • Orca Findings Management: Own the end-to-end lifecycle of Orca findings, including monitoring new alerts, triaging severity, identifying root cause, tracking remediation, and driving findings to closure with the appropriate technical owners. • Cloud Alert Response: Serve as a primary responder for cloud-specific security alerts. You will help improve detection quality, reduce response time, and ensure cloud-originated threats are investigated and addressed effectively. • Infrastructure-as-Code Security: Partner with teams using Terraform and related infrastructure-as-code workflows to review, improve, and harden cloud configurations before risk reaches production. • AI Cloud Security: Help secure Engine’s expanding AI-related cloud footprint by identifying risks related to sensitive data, elevated IAM permissions, new service integrations, model/data access patterns, and infrastructure configurations. • Cross-Functional Collaboration: Partner closely with infrastructure, platform, engineering, SecOps, and security leadership to move security work forward. You will adapt your messaging across audiences, build trust with technical teams, and influence decisions without relying on direct authority. • Cloud-Native Threat Detection: Collaborate with SecOps to improve cloud telemetry, cloud-specific detection logic, SIEM signal quality, and response workflows for threats such as credential abuse, lateral movement, misconfigured storage, and data exfiltration. • Security Standards & Advocacy: Build clear, actionable cloud security guidelines, guardrails, and best practices for engineering teams. You will help create the paved paths that allow Engine to move quickly while reducing cloud security risk.

🎯 Exigences

• Cloud Security Expertise: Deep hands-on experience securing modern cloud environments, especially AWS, with strong knowledge of cloud-native security controls, services, risks, and remediation patterns. • Multi-Cloud Capability: Experience with GCP security or the ability to quickly ramp in a multi-cloud environment spanning AWS and GCP. • IAM & Access Control: Strong understanding of cloud IAM, privilege reduction, identity boundaries, service permissions, key management, and common access-control failure modes. • Cloud Architecture Judgment: Ability to evaluate architecture decisions, identify systemic risk, and recommend scalable security patterns that balance risk reduction with engineering velocity. • CSPM / CNAPP Tooling: Experience with cloud security platforms such as Orca, Wiz, Prisma Cloud, Lacework, or similar tools, including triage, prioritization, remediation tracking, and reduction of alert noise. • Infrastructure-as-Code: Hands-on experience reviewing and securing Terraform or other infrastructure-as-code configurations. • Cloud Detection & Response: Experience investigating cloud security alerts and improving telemetry, logging, monitoring, and detection logic across cloud environments. • Engineering Partnership: Proven ability to earn credibility with infrastructure, platform, and engineering teams through practical recommendations, clear communication, and strong technical depth. • Analytical Problem Solving: Ability to assess complex, ambiguous cloud security issues, identify root causes, prioritize risk, and make sound decisions with incomplete information. • Security Program Maturity: Experience building or improving cloud security standards, guardrails, operating rhythms, remediation processes, or security review practices. • AI / Emerging Technology Awareness: Understanding of how AI workloads can expand cloud attack surface through sensitive data usage, elevated permissions, new integrations, and infrastructure complexity. • Compliance & Frameworks: Familiarity with cloud security concepts as they relate to compliance frameworks such as SOC 2, PCI, or similar standards.

🏖️ Avantages

• Compensation: Competitive base pay tied to role and experience, with opportunities for bonuses, commissions, and equity. • Benefits: Check out our full list at http://engine.com/culture. • Environments for Success: Different roles have different needs in terms of the environments that drive success which is why we have a hybrid-hub model. Whether you are in one of our amazing offices or fully remote, we’ll make sure you have what you need to succeed.

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

Spreedly

51 - 200

💳 Fintech

☁️ SaaS

🛍️ eCommerce

Cybersecurity Architect responsible for designing security architectures at Spreedly, focusing on payment systems and evolving cyber threats. Working closely with engineering and product teams to integrate security controls.

🇺🇸 États-Unis – Télétravail

💰 €75 000 000 Private Equity Round en 2019-11

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

CloudWave, Healthcare IT Solutions

51 - 200

🔒 Cybersecurity

Marketing Manager focused on demand generation and pipeline marketing for cybersecurity services. Leading campaigns and sales enablement initiatives to drive business growth.

🇺🇸 États-Unis – Télétravail

💰 Venture Round en 2014-05

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Red Cup IT

11 - 50

🔒 Cybersecurity

☁️ SaaS

Staff Security Engineer at Red Cup IT maintaining multi-tenant security architectures and leading incident response for sophisticated breaches. Advising key accounts on technical compliance and risk management.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Anomaly

11 - 50

⚕️ Assurance santé

🤖 Intelligence artificielle

☁️ SaaS

Head of Security operating the information security program at Anomaly. Focused on enabling rapid product development while maintaining security and compliance.

🇺🇸 États-Unis – Télétravail

💰 €13 066 211 Venture Round - Anomaly en 2024-11

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Managing Principal specializing in information security for AHEAD. Leading client engagements and business development in Security and Compliance.

🇺🇸 États-Unis – Télétravail

💵 $300 000 - $365 000 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis