Security Engineer, Cloud Security
Saronic Technologies · San Diego, CA · 4 days ago
On-siteInformation TechnologyFull-time
Responsibilities
- Own continuous cloud security posture management (CSPM) across all cloud accounts, detect misconfigurations and drift, and drive remediation with the teams that own the resources.
- Map technical controls to both government and commercial frameworks (CMMC, NIST SP 800-171, FedRAMP/IL baselines) and keep controls evidence current and audit-ready.
- Run cloud vulnerability management at scale, find issues, prioritize them by real attack path and exposure rather than raw CVSS, and drive remediation to closure.
- Use tooling such as Prowler and automate remediation wherever possible.
- Build reusable Terraform modules, Service Control Policies, permission boundaries, and policy-as-code that make the secure path the easy path, so whole classes of misconfiguration disappear before they reach production.
- Replace manual security gates with automated, self-service guardrails.
- Design least-privilege IAM across accounts and workloads, hunt privilege-escalation and cross-account trust paths, govern secrets management, and standardize encryption and key-management patterns.
- Build and tune cloud-native detections (CloudTrail, GuardDuty, Config, Security Hub) and automated remediation, and support the Security Operations team as they investigate, triage, and remediate cloud-related cases across our infrastructure, including credential compromise, exposed resources, and data exfiltration, reconstructing activity from logs and automating containment.
- Feed every incident back into new guardrails and detections.
Qualifications
- 3+ years of hands-on cloud security, infrastructure security, or DevSecOps experience, or an equivalent combination of experience and demonstrated ability.
- Depth in AWS security services and architecture (IAM, Organizations/SCPs, CloudTrail, Config, GuardDuty, Security Hub, KMS, VPC).
- Strong infrastructure-as-code (Terraform) and policy-as-code experience.
- Hands-on cloud vulnerability management and CSPM tooling (e.g., Prowler), with a track record of driving cloud findings to remediation.
- A track record of building guardrails or patterns that other teams adopted without friction.
- Ability to obtain and maintain a U.S. security clearance.
Physical Demands
- Prolonged periods of sitting at a desk and working on a computer.
- Occasional standing and walking within the office.
- Manual dexterity to operate a computer keyboard, mouse, and other office equipment.
- Visual acuity to read screens, documents, and reports.
- Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies.
- Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages).