Senior Cloud Security Engineer
Semperis · Addison, TX · 4 days ago
HybridInformation TechnologyFull-time
About the role
As we continue to scale our cloud footprint and regulated offerings, we are expanding our Cloud Security team with a Senior Cloud Security Engineer who thrives at the intersection of cloud platforms, security engineering, networking, and automation.
Responsibilities
- Own the security architecture, guardrails, and automation patterns, while partnering with platform and infrastructure teams on implementation.
- Own and evolve Cloud Security Posture Management (CSPM) capabilities, including policies, guardrails, and automated remediation.
- Engineer and maintain cloud network security controls, including network segmentation and isolation, cloud-native firewalls and security groups, Application Gateway / WAF configurations, and secure ingress and egress patterns.
- Define and enforce security best practices for Kubernetes environments (AKS/EKS), including RBAC, network policies, workload isolation, and cluster hardening.
- Partner with engineering teams on architecture reviews for new services, platforms, and major changes, helping teams design secure, compliant, and practical solutions.
- Engineer and maintain identity and access security controls for cloud and production environments, including least privilege, workload identity, service principals, and conditional access.
- Develop tooling, automation, and self-service workflows that reduce manual effort and improve consistency across security programs.
- Communicate complex security risks and technical recommendations clearly to engineering teams, leadership, and cross-functional stakeholders.
- Mentor junior engineers and contribute to raising the overall security maturity of the organization.
Requirements
- 6+ years of experience in cloud security, security engineering, or cloud platform engineering roles.
- Hands-on experience securing production AKS/EKS environments, including RBAC, network policies, workload identity, admission controls, image/runtime controls, and cluster hardening.
- Proven experience with cloud network security, including firewalls, WAFs, network segmentation, and secure connectivity patterns.
- Strong understanding of cloud security architecture, including shared responsibility models, secure service design, and defense-in-depth.
- Experience with preventative security controls, including CSPM, policy enforcement, and secure cloud baselines.
- Cloud automation experience using Infrastructure as Code tools such as Terraform, Bicep, or CloudFormation, plus scripting with Python, PowerShell, Bash, or similar languages.
- Ability to operate independently, own complex problem spaces, and deliver practical, scalable solutions.
- Strong communication skills and comfort providing architecture-level guidance to engineering teams.
- Experience working in regulated environments.
Bonus points
- Experience contributing to or supporting compliance programs such as FedRAMP, SOC 2, ISO 27001, or NIST frameworks.
- Familiarity with CI/CD pipelines and DevSecOps practices.
- Experience with identity and access management in cloud environments (RBAC, workload identity, service principals).
Qualifications
- Deep hands-on security experience in Azure or AWS is required; experience across both is strongly preferred.
- Experience with preventative security controls, including CSPM, policy enforcement, and secure cloud baselines.
- Experience with cloud automation using Infrastructure as Code tools such as Terraform, Bicep, or CloudFormation, plus scripting with Python, PowerShell, Bash, or similar languages.
- Experience with cloud network security, including firewalls, WAFs, network segmentation, and secure connectivity patterns.
- Experience with Kubernetes environments (AKS/EKS), including RBAC, network policies, workload isolation, and cluster hardening.
- Experience with identity and access management in cloud environments (RBAC, workload identity, service principals).
Skills
- Security architecture and design.
- Cloud security and compliance.
- Cloud network security.
- Kubernetes security.
- Automation and Infrastructure as Code.
- Identity and access management.
Benefits
At Semperis, we believe that when people feel valued, supported, and empowered, they do their best work. That’s why we focus on creating an employee experience rooted in purpose, growth, and balance.
Pay
Compensation is competitive and commensurate with experience.
Schedule
We offer a flexible hybrid work schedule, allowing employees to work up to three days per week from home and the remaining days in the office.