Cloud & Application Security Engineer
RSC Solutions · New York, NY · 4 wk ago
On-siteInformation TechnologyOther
Responsibilities
- Design, implement, and mature secure cloud architectures across AWS, Azure, and GCP, with a primary focus on GCP.
- Develop, audit, and harden cloud infrastructure, including IAM, networking, organization policies, logging, and Terraform-based Infrastructure-as-Code.
- Provide security architecture reviews and guidance for cloud applications, APIs, infrastructure, DevOps, and AI-assisted development.
- Perform application security assessments, secure code reviews, and hands-on testing of web applications, APIs, and cloud services using automated and manual techniques to identify vulnerabilities and drive remediation.
- Identify, prioritize, and remediate cloud and application vulnerabilities, including critical and zero-day threats.
- Lead evaluations, proof-of-concepts, and implementation of cloud and application security technologies.
- Secure AI platforms and AI-assisted development by implementing appropriate security controls and reviewing AI-assisted applications for security risks.
- Partner with Security Operations to improve cloud detection, monitoring, incident response, and security visibility.
Requirements
- Bachelor's degree in computer science, Cybersecurity, a related field, or equivalent practical experience.
- 5+ years of hands-on experience in cybersecurity, cloud engineering, DevOps, application security, or related discipline.
- Experience securing enterprise cloud environments across AWS, Azure, and/or GCP, including Kubernetes.
- Strong understanding of cloud architecture, IAM, networking, cloud security controls, and Infrastructure-as-Code.
- Experience integrating security into CI/CD pipelines using Terraform and modern DevOps platforms.
- Proficiency in Python, PowerShell, Bash, Go, or a similar language, or demonstrated ability to leverage AI-assisted engineering tools to develop automation and security solutions.
- Hands-on experience with Wiz or a comparable CSPM/CNAPP platform.
- Experience with application security, including secure SDLC, threat modeling, secure code reviews, SAST, DAST, SCA, secret scanning, vulnerability management, remediation, and web application security testing.
- Strong understanding of web application security, REST APIs, authentication (OAuth/OIDC/JWT), and OWASP Top 10.
- Familiarity with AI security concepts and securing enterprise AI platforms or AI-assisted applications.