Senior Cloud Security Specialist
Job Description
About the Role
We're looking for a Senior Cloud Security Specialist to strengthen our cloud security posture. This hands-on role covers cloud security engineering and configuration, backed by a good understanding of GRC to keep controls audit-ready and of code security to engage effectively with application teams. You'll be a senior technical voice able to secure infrastructure while speaking credibly to risk, compliance, and secure development concerns.
Key Responsibilities
Cloud Security
- Design and maintain cloud security controls (IAM, network security, encryption, logging, monitoring) across AWS/Azure/GCP.
- Harden configurations and manage cloud security tooling (CSPM, CWPP, SIEM integrations) to identify gaps and drive continuous detection/prevention improvements.
- Review and secure Infrastructure-as-Code (Terraform, CloudFormation, Ansible) and containerized/serverless workloads (Kubernetes, ECS/EKS/AKS/GKE, Lambda/Functions) pre-deployment.
- Lead incident response for cloud security events — investigation, containment, remediation.
- Embed security guardrails into provisioning/deployment pipelines with DevOps — security by design.
GRC Alignment
- Maintain working knowledge of compliance frameworks (ISO 27001, SOC 2, NIST CSF/800-53) as applied to cloud environments.
- Translate cloud security controls into audit-ready evidence and documentation, supporting audits with technical context as needed.
- Partner with GRC/risk teams on cloud-related risk assessments, control gap analyses, and remediation plans.
- Assess new cloud projects and architecture changes for compliance impact early in the design phase.
Code Security
- Secure design & coding standards – Security built in from the start (threat modelling, secure patterns, coding guidelines) rather than added later.
- Code review – Manual/peer review to catch logic flaws and risky design choices that automated tools miss.
- Automated testing & CI/CD integration – SAST, DAST, and SCA cover code, running apps, and dependencies; integrated into CI/CD and correlated with infrastructure risk for a holistic view.
- IAM & API security – Least-privilege IAM roles and secure API design (authN/authZ, input validation, rate limiting) as core controls.
- Vulnerability remediation – Prioritizing and fixing issues (injection, broken auth, insecure data handling) based on risk and exploitability.
- Shift-left mindset – Fixing issues as early in the SDLC as possible, since early fixes are cheaper and lower exposure.
Leadership & Collaboration
- Act as a senior technical resource and mentor for cloud security practices across the security team and broader engineering organization.
- Represent cloud security in architecture reviews, design discussions, and project planning.
- Communicate risk, technical findings, and remediation recommendations clearly to both technical teams and leadership/GRC stakeholders.
- Contribute to and help evolve cloud security standards, baselines, and reference architectures.
Required Qualifications
- 6–10+ years in cybersecurity, with 4+ years focused on cloud security engineering or architecture.
- Deep hands-on experience securing at least one major cloud platform (AWS, Azure, or GCP); multi-cloud a plus.
- Good understanding of GRC concepts and at least one major framework (ISO 27001, SOC 2, NIST).
- Conceptual fluency in code security (SAST/DAST/SCA) and how findings apply to cloud-hosted applications.
- Experience with IaC and CI/CD pipeline security, plus familiarity with container/Kubernetes and cloud-native patterns.
- Strong communication skills — translating technical risk into engineering and compliance/business terms.
Preferred Qualifications
- Certifications such as AWS/Azure/GCP Security, CCSP, CISM, or similar.
- Hands-on exposure to SAST tools (Veracode, CodeQL, SonarQube, Snyk Code) and their reporting/triage workflows.
- Experience supporting audits or working with a GRC/compliance function.
- Scripting/automation experience (Python, Go, or similar) for cloud security tooling.
- Background in software development or DevOps prior to moving into security, ideally within regulated industries (finance, healthcare, SaaS).
More Info
Key Skills
SOC 2
Lambda Functions
GKE
NIST CSF 800-53
CWPP
AKS
EKS
