Cloud Security Engineer
Recology · California, United States · 1 wk ago
Information TechnologyFull-time
Essential Responsibilities
- Designs, implements, and manages security controls across Recology’s cloud environments (Azure, AWS, GCP), ensuring secure configurations, access controls, and compliance with company standards.
- Supports the organization’s transition from on-prem infrastructure to cloud platforms by embedding security into architecture, migration, and deployment processes.
- Establishes and maintains cloud security baselines, guardrails, and configuration standards (CSPM, identity, networking, and data protection).
- Configures and manages native cloud security services (Microsoft Defender for Cloud, Azure Security Center, AWS Security Hub, etc.).
- Acts as a cloud security SME supporting IT and engineering teams through design reviews, threat modeling, and security validation.
- PARTNERS WITH INFRASTRUCTURE, APPLICATION, AND DATA TEAMS TO INTEGRATE SECURITY INTO SYSTEM DESIGN AND PROJECT DELIVERY.
- IDENTIFIES AND REMEDIATES SECURITY GAPS IN CLOUD AND HYBRID ARCHITECTURES.
- IMPLEMENTS AND MANAGES SECURE IDENTITY AND ACCESS CONTROLS USING AZURE AD AND RELATED TECHNOLOGIES (RBAC, CONDITIONAL ACCESS, LEAST PRIVILEGE PRINCIPLES).
- SUPPORTS THE DESIGN AND IMPLEMENTATION OF IDENTITY STRATEGIES ACROSS CLOUD AND ON-PREM ENVIRONMENTS.
- DEVELOPS AND ENHANCES THREAT DETECTION CAPABILITIES ACROSS CLOUD AND ENTERPRISE ENVIRONMENTS USING SIEM AND CLOUD-NATIVE TELEMETRY.
- PARTICIPATES IN INCIDENT RESPONSE ACTIVITIES, INCLUDING INVESTIGATION, CONTAINMENT, AND POST-INCIDENT REVIEWS.
- BUILDS AND MAINTAINS AUTOMATION WORKFLOWS FOR SECURITY MONITORING, ALERTING, AND RESPONSE.
- Improves security processes through scripting and integration with existing tools and platforms.
- Develops and tracks KPIs and metrics to measure cloud security posture and program effectiveness.
- SUPPORTS SECURITY AUDITS AND ENSURE COMPLIANCE WITH REGULATORY FRAMEWORKS INCLUDING NIST CSF, PCI DSS, ISO 27001, AND CCPA.
- DEVELOPS AND MAINTAINS CLOUD-SPECIFIC SECURITY STANDARDS, PROCEDURES, AND DOCUMENTATION.
- CONTRIBUTES TO VULNERABILITY MANAGEMENT AND RISK REMEDIATION EFFORTS ACROSS CLOUD AND ENTERPRISE SYSTEMS.
- WORKS CLOSER WITH IT, SECURITY, AND BUSINESS STAKEHOLDERS TO ALIGN SECURITY INITIATIVES WITH ORGANIZATIONAL GOALS.
- PROVIDES GUIDANCE ON EMERGING CLOUD THREATS, RISKS, AND BEST PRACTICES.
- SUPPORTS DISASTER RECOVERY AND BUSINESS CONTINUITY PLANNING FOR CLOUD SYSTEMS.
Qualifications
- 10+ years of progressive experience in information security or cybersecurity, with hands-on experience securing Azure cloud environments and enterprise infrastructure.
- 5+ years of experience with GCP, AWS, Azure.
- Experience operating and deploying tools within regulatory frameworks such as NIST CSF, PCI DSS, ISO 27001, and CCPA.
- Strong technical experience with cloud security controls, identity and access management, endpoint security, and device compliance.
- Proven ability to collaborate across IT operations, engineering, and business teams to embed security into system design, implementation, and ongoing operations.
- Experience with vulnerability management, incident response, and threat detection.
- Strong analytical and problem-solving skills with the ability to translate risk into actionable recommendations.
- Experience supporting cloud migrations or transformation initiatives.
- Familiarity with security tooling such as SIEM, EDR, CSPM, and IAM platforms.
- Experience with scripting or automation (PowerShell, Python, etc.).
- Customer-focused mindset with a commitment to delivering high-quality service and solutions.
- Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field, or equivalent practical experience in cybersecurity and cloud security roles preferred.
- High School Diploma or GED required.