Cloud Security Engineer
Job Description
Establish and maintain security standards for cloud environment governance, including identity management, network architecture, compute resources, storage solutions, container orchestration, and managed cloud services. Serve as an expert in threat modeling, analyzing attack vectors, assessing risks, and prioritizing security measures based on business impact. Collaborate with platform and infrastructure teams to integrate security into cloud architecture from inception, automating security controls and compliance processes. Design, implement, and manage security controls across leading cloud platforms, covering Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and serverless compute environments in multi-cloud setups. Deploy and optimize cloud security tools such as Cloud Security Posture Management (CSPM), Cloud Workload Protection Platforms (CWPP), and Cloud Infrastructure Entitlement Management (CIEM) to detect misconfigurations and thwart threats in real-time. Integrate security checks directly into Continuous Integration/Continuous Deployment (CI/CD) pipelines and version control workflows, enabling automated vulnerability assessments and comprehensive code-to-cloud visibility. Ensure security programs align with recognized industry frameworks like NIST Cybersecurity Framework and CIS Controls. Translate security policies into detailed technical controls that withstand audit scrutiny.
Key Responsibilities
- Develop and enforce security standards for cloud identity and access management, network segmentation, encryption, and key management in AWS, Azure, and multi-cloud environments.
- Lead threat modeling exercises and conduct risk assessments to identify attack paths, vulnerabilities, and business impacts.
- Partner with cloud engineers to embed security best practices into cloud architecture design, automation, and infrastructure provisioning.
- Architect and manage security controls for both IaaS and PaaS deployments, including serverless applications and container environments (Kubernetes, Docker).
- Deploy, configure, and fine-tune cloud security tools such as CSPM, CWPP, CIEM, CloudTrail, Security Hub, Azure Security Center, GuardDuty, and Azure Defender.
- Automate security controls and compliance checks within CI/CD pipelines leveraging tools such as GitHub Actions, Jenkins, and Terraform.
- Monitor and respond to security alerts, perform incident investigation, and implement mitigation strategies in cloud platforms.
- Lead security awareness and training initiatives to promote Secure Software Development Lifecycle (Secure SDLC) and DevSecOps practices.
- Prepare security documentation, technical controls, and audit-ready reports in accordance with industry standards and frameworks.
Core Qualifications & Requirements
- 7+ years experience in information security, with at least 3 years focused on cloud security architecture.
- Hands-on experience securing large-scale enterprise AWS and Azure cloud environments.
- Deep expertise in cloud IAM, federation, network segmentation, cloud-native firewalls, encryption strategies, and key management solutions (KMS, HSM).
- Proven ability to implement secure container orchestration, Kubernetes security, and cloud workload protection.
- Strong knowledge of security frameworks such as NIST (National Institute of Standards and Technology), CIS Controls, and compliance standards.
- Demonstrated success in driving Secure SDLC, DevSecOps, and automation initiatives, especially within GitHub workflows.
- Relevant certifications (preferred): CISSP, GIAC Security Certifications, AWS Security Specialty, Azure Security Engineer Associate.
- Excellent communication skills, capable of influencing technical teams and leadership regarding security posture and risk mitigation.
Nice-to-Have Qualifications
- Experience with security automation platforms and scripting (Python, PowerShell, Shell scripting).
- Knowledge of vulnerability management and threat intelligence platforms.
- Familiarity with data encryption, HSM integration, and encryption key lifecycle management.
Core Technical Skills
- Cloud Platforms: AWS, Microsoft Azure, GCP (Google Cloud Platform)
- Security Tools: CSPM, CWPP, CIEM, Security Hub, GuardDuty, Azure Security Center, Defender, CloudTrail, CloudWatch
- Configuration Management: Terraform, CloudFormation, ARM templates
- CI/CD & Automation: GitHub Actions, Jenkins, Jenkins Pipelines, DevSecOps tools
- Security Frameworks: NIST, CIS, ISO 27001, SOC 2
- Protocols & Technologies: IAM, federation, VPC, VPN, firewalls, encryption (KMS, HSM), Kubernetes security
Career Impact
This role offers the opportunity to shape and secure complex multi-cloud environments, directly influencing enterprise security posture and resilience.
Compensation and Benefits
Competitive salary commensurate with experience; comprehensive benefits package including health, dental, vision, paid time off, and professional development allowances.
Apply Today!
Join a forward-thinking security team committed to protecting enterprise cloud infrastructure—apply now to advance your cloud security career.
The Phoenix Group Advisors is an equal opportunity employer. We are committed to creating a diverse and inclusive workplace and prohibit discrimination and harassment of any kind based on race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. We strive to attract talented individuals from all backgrounds and provide equal employment opportunities to all employees and applicants for employment.
Meet Your Recruiter
Leonard Bellezza
VP of Recruiting
Leonard is a graduate from Montclair State University with a degree in Marketing with a concentration in Sports, Events and Tourism. He has been with The Phoenix Group since 2018. He was brought into the recruiting industry by a friend who previously worked at TPG. In his free time, he enjoys playing golf and watching sports.