Jobs · Engineering

Cloud Security Engineer

F2Onsite · California, United States · Yesterday
RemoteRemoteEngineeringContract

Position Overview

We are seeking an experienced Cloud Security Engineer to lead the design, implementation, and operationalization of a cloud security program across a complex, multi-cloud and SaaS-heavy enterprise environment. This is a 12-14 week contract-to-hire opportunity supporting a rapidly evolving IT Security organization.

What You'll Do

  • Cloud Security Program Development
    • Build an authoritative inventory of all cloud properties across AWS, Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI), and material SaaS applications.
    • Reconcile cloud assets into the ServiceNow CMDB using the appropriate cloud asset classes.
    • Develop and implement a scalable cloud security program across a multi-cloud enterprise environment.
  • Cloud Security Assessments
    • Conduct cloud security posture assessments against industry frameworks, including:
      • CIS Benchmarks
      • Cloud Security Alliance (CSA)
      • NIST Cybersecurity Framework (CSF) 2.0
    • Assess and document:
      • IAM security gaps
      • Network exposure risks
      • Logging and monitoring deficiencies
      • Cryptography and key management controls
      • Risk-rank findings, assign ownership, and surface results through ServiceNow posture dashboards.
  • ServiceNow Engineering
    • Design and build cloud account onboarding and monitoring workflows within ServiceNow.
    • Develop automated onboarding processes to support mergers and acquisitions (M&A) and rapid cloud expansion.
    • Integrate cloud assets into the CMDB and support ServiceNow SecOps workflows.
  • Security Platform Integration
    • Onboard cloud telemetry into:
      • CrowdStrike Falcon Cloud Security
      • CrowdStrike NG-SIEM
      • Obsidian SSPM
      • Varonis DSPM
    • Configure cloud log forwarding through Cribl into NG-SIEM.
    • Tune detections and ensure alerts are routed appropriately into Security Operations.
  • Documentation & Operations
    • Develop operational runbooks and standard operating procedures.
    • Operate the cloud security program in steady-state following implementation.
    • Support continuous onboarding of new cloud environments in a fast-paced acquisition environment.
  • AI-Driven Security Engineering
    • Utilize frontier AI models such as ChatGPT Enterprise and Claude to accelerate:
      • Cloud inventory analysis
      • Security posture assessments
      • Workflow development
      • Runbook creation
      • Documentation
    • Apply AI responsibly while following enterprise governance and security best practices.

    Required Qualifications

    • Must-Have Skills:
      • Hands-on experience securing multi-cloud environments including: AWS, Microsoft Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI).
      • Strong knowledge of: Cloud Security Posture Management (CSPM), Identity & Access Management (IAM), Cloud networking and exposure management, Encryption and key management, Cloud logging, monitoring, and telemetry.
      • Strong technical writing and documentation skills.
      • Ability to work independently from discovery through operational maturity with minimal oversight.
    • Preferred Qualifications:
      • Experience with the following technologies is highly desired: CrowdStrike Falcon Cloud Security, CrowdStrike NG-SIEM, Obsidian SSPM, Varonis DSPM, Cribl, Okta, Terraform or other Infrastructure-as-Code (IaC) platforms.

    Preferred Certifications

    • Include AWS Security Specialty, Microsoft Azure Security Engineer, Google Professional Cloud Security Engineer, CCSP, CISSP, GIAC Cloud Security certifications.

    Technology Environment

    • You Will Be Supporting And Working With:
      • AWS
      • Microsoft Azure
      • Google Cloud Platform (GCP)
      • Oracle Cloud Infrastructure (OCI)
      • ServiceNow (CMDB & SecOps)
      • CrowdStrike Falcon Cloud Security
      • CrowdStrike NG-SIEM
      • Obsidian SSPM
      • Varonis DSPM
      • Zscaler (ZIA/ZPA)
      • Cribl
      • Okta
      • Terraform or other Infrastructure-as-Code (IaC) platforms

    Work Environment

    • Full-time remote position.
    • Collaborative IT Security Engineering team operating within a SAFe Agile framework.
    • ServiceNow is utilized for ITSM and Security Operations.
    • Zoom is used for collaboration and team communication.
    • AI-forward culture where frontier AI models are actively incorporated into engineering workflows.
    • Fast-paced, acquisition-driven environment requiring flexibility, adaptability, and strong execution.

Similar jobs