2 months ago
Sunnyvale, CA, USAStaff+
Base Salary
$169k - $224k/yr
Responsibilities
- Lead the design, implementation, and continuous improvement of cloud security architectures across AWS environments.
- Implement and manage AWS security services including IAM, KMS, GuardDuty, Security Hub, Inspector, Macie, WAF, Shield, CloudTrail, Config, and CloudWatch.
- Develop cloud security standards, guardrails, and governance frameworks for AWS accounts, containers, Kubernetes/EKS, serverless, and hybrid workloads.
- Automate security monitoring, compliance validation, vulnerability management, and incident-response workflows using infrastructure as code, scripting, and cloud-native automation.
- Conduct threat modeling, architecture risk assessments, security reviews, vulnerability assessments, and penetration-testing coordination.
- Secure DevOps platforms and cloud-native environments through access controls, secrets management, network segmentation, encryption, and workload protection.
- Manage cloud security posture management, container security, and runtime protection capabilities.
- Serve as a cloud security subject matter expert during incidents, forensic investigations, root cause analysis, and remediation.
- Define and report cloud security metrics, operational KPIs, and compliance status.
- Mentor and guide engineers on AWS security, DevSecOps, automation, and secure cloud engineering practices.
Requirements
- 8+ years of experience in product security, cybersecurity, cloud security, application security, or related technical security roles.
- Hands-on experience leading threat modeling, security risk assessments, and vulnerability management for complex software products.
- Experience embedding security into modern software development environments, including CI/CD and DevSecOps practices.
- Experience supporting security incident response and conducting root cause analysis in production environments.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent practical experience.
- Preferred experience includes work in regulated environments such as medical devices, healthcare, or life sciences.
- Preferred knowledge includes IEC 62304, ISO 14971, ISO 80001-2, NIST, and FDA pre- and post-market cybersecurity guidance.
- Preferred experience includes securing AI/ML systems, delivering cybersecurity programs and incident simulations, and working with globally distributed teams.
- Preferred certifications include AWS Certified Security – Specialty, AWS Certified Solutions Architect, OSCP, GPEN, GCIH, GWAPT, CISSP, or CCSP.
Benefits
- Flexible hybrid arrangement based in Sunnyvale, California, with at least 60% or 24 hours of the work week on-site and the remainder potentially remote.
- Full-time role with occasional travel based on business needs.
- Annual bonus and/or incentives may be available subject to applicable plans and company discretion.
- Benefits include flexible time off or vacation, a 401(k) retirement plan with employer match, medical, dental, and vision coverage, and mindfulness programs.
