Security Engineer, Infrastructure
Inclusively · United States · 2 wk ago
RemoteRemoteEngineering$80k–$120k/yrFull-time
We're seeking an experienced Infrastructure Security Engineer to design and operate security controls across our cloud platforms and edge infrastructure. You'll work at the intersection of cloud security and modern network access, implementing Cloudflare WAF and SASE solutions, zero-trust network access controls, and cloud security posture management across AWS, GCP, and Azure.
Responsibilities
- Design, implement, and maintain cloud security solutions across AWS, GCP, and Azure environments
- Lead the design and deployment of Cloudflare WAF and related edge security controls across production infrastructure
- Implement and optimize SASE (Secure Access Service Edge) architecture and controls to replace traditional perimeter security
- Develop and maintain cloud access policies and zero-trust network access controls
- Conduct security reviews and threat modeling of cloud infrastructure and data flows
- Implement cloud security posture management (CSPM) and identify/remediate misconfigurations
- Design, implement, and maintain infrastructure-as-code security configurations
- Contribute to the creation and maintenance of runbooks and playbooks for cloud security incident response
- Assist with proof-of-concept builds for new cloud security and SASE solutions
- Contribute to detection rule tuning and security monitoring in cloud environments
- Participate in the Security Engineering Team on-call rotation
Requirements
- Minimum of 3 years' experience in cloud security engineering, DevSecOps, or site-reliability engineering
- Advanced knowledge of at least two major cloud platforms (AWS, GCP, Azure)
- Hands-on experience implementing and optimizing WAF solutions, with Cloudflare strongly preferred
- Demonstrated experience designing or implementing SASE/zero-trust network access solutions
- Working knowledge of Privileged Access Management (PAM) solutions and principles (BeyondTrust or similar)
- Familiarity with secrets management and privileged credential storage (Keeper or similar)
- Advanced knowledge of Linux and/or Windows operating systems
- Experience with one or more scripting languages (PowerShell, Python, Bash, Go)
- Experience with infrastructure-as-code technologies (Terraform, Ansible, Pulumi)
- Working knowledge of traditional networking and software-defined networking (SDN) concepts
- Strong understanding of cloud networking models (VPC, security groups, network policies)
- Knowledge of encryption in transit and at rest, certificate management
- Experience with cloud logging, monitoring, and alerting (CloudWatch, Stackdriver, Azure Monitor, etc.)
- Demonstrated ability to work with systems at scale
- Excellent written and verbal communication skills
- Strong problem-solving abilities and attention to detail
We encourage military members and their spouses as well as candidates without a degree or a background in tech to apply.
Pay
Annual Salary Range: $80,000 - $120,000