Scribd

Staff Cloud Security Engineer

Scribd
Apply
3 hours ago
Toronto, Canada +10 moreStaff+
H1B sponsor

Base Salary

$147k - $255k/yr

Responsibilities

  • Set and evolve cloud security architecture and guardrails across AWS and GCP, including account and project configuration, network security, and infrastructure standards.
  • Strengthen identity and access management using least privilege, just-in-time access, short-lived workload credentials, and secure cross-account access.
  • Define secrets management, data protection, encryption, workload security, runtime protection, and service-isolation standards.
  • Secure cloud deployment paths, workload identities, registries, Kubernetes environments, and infrastructure supporting CI/CD.
  • Build reusable security capabilities, Terraform modules, and policy-as-code guardrails that prevent noncompliant infrastructure changes.
  • Define cloud telemetry requirements and improve detection coverage for cloud-native threats with Detection & Response teams.
  • Validate controls through threat hunting and attack-path analysis, support incident response, and improve containment and recovery architecture.
  • Lead complex technical initiatives, shape the Cloud Security roadmap, establish standards, evaluate tooling, mentor engineers, and communicate risks and progress to stakeholders.

Requirements

  • 10+ years of experience in cloud or infrastructure security engineering, or an equivalent blend of software and security engineering, with hands-on experience securing production cloud environments at scale.
  • Deep expertise in at least AWS or GCP and sufficient fluency in the other cloud environment.
  • Experience shaping security architecture and leading cross-team initiatives, including influencing engineering teams without formal authority.
  • Deep hands-on IAM experience with least privilege, cross-account access, short-lived workload credentials, service-to-service identity, and authorization.
  • Experience securing Kubernetes and cloud workloads, including container security, runtime protection, and workload isolation.
  • Experience with CSPM/CNAPP platforms, security findings, attack-path analysis, and prioritized security improvements.
  • Experience designing cloud security guardrails, security baselines, policy-as-code, secure infrastructure provisioning, and landing-zone automation.
  • Strong infrastructure-as-code and automation skills using Terraform or equivalent tooling, plus proficiency in Python or Go.
  • Experience with cloud security visibility and response, cloud-native security tooling, detection capabilities, SIEM integration, and incident-learned control improvements.
  • Demonstrated ability to deliver measurable security improvements while balancing technical depth, architectural judgment, and hands-on execution.

Benefits

  • Flexible Scribd Flex work model with occasional in-person attendance required and residence limited to listed metropolitan areas in the United States, Canada, or Mexico.
  • Comprehensive health, dental, and vision coverage, plus mental health support and disability coverage.
  • Paid time off including vacation, sick time, holidays, winter break, volunteer time, and sabbaticals.
  • Paid parental leave and family support benefits.
  • Retirement matching and employee equity.
  • Learning and development programs, professional growth opportunities, wellness and home office stipends.
  • Complimentary access to Scribd, Inc. products and enterprise access to leading AI tools.
Scribd

About Scribd

201-500 employees
Contact me