
Cloud Security Engineer
Apex Technology, Inc.3 hours ago
Base Salary
$150k - $200k/yr
Responsibilities
- Design and implement secure cloud architectures across AWS GovCloud, Azure, Google Cloud, and hybrid or multi-cloud environments.
- Implement and maintain cloud security frameworks supporting NIST 800-53, FedRAMP, RMF, DoD Impact Levels, and SCCA requirements.
- Manage IAM, RBAC, JIT access, Key Vaults, Zero Trust principles, encryption, network security, and data protection.
- Deploy and optimize cloud-native security, CSPM/CWPP, SIEM, threat detection, monitoring, and response tools.
- Conduct vulnerability assessments, penetration testing simulations, configuration reviews against STIGs, CIS benchmarks, and NIST controls, and continuous monitoring.
- Develop and maintain SSPs, SARs, POA&Ms, risk reports, compliance documentation, policies, standards, and automated security guardrails.
- Investigate indicators of compromise, threat intelligence, security alerts, and incidents; perform root-cause analysis and coordinate response activities.
- Collaborate with DevSecOps, infrastructure, configuration management, and development teams to integrate security into CI/CD, IaC, migrations, and modernization initiatives.
- Review cloud architectures and designs, recommend security improvements, identify emerging threats, and provide security guidance and training to engineering teams.
Requirements
- U.S. citizenship is required.
- Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, or a related field, or 5+ years of equivalent professional experience in cloud security engineering.
- 5–9+ years of cloud security engineering experience with hands-on AWS GovCloud, Azure, Google Cloud, or multi-cloud work.
- Deep knowledge of cloud platforms, IAM/RBAC, encryption, network security, logging, monitoring, cloud-native security services, and container or Kubernetes security.
- Experience with SIEM platforms, vulnerability scanners, threat intelligence, scripting, infrastructure-as-code, and security automation.
- Experience with NIST, FedRAMP, RMF, Azure Sentinel, NESSUS, Burp Suite, Microsoft Defender, or equivalent tools.
- CISSP, AWS Certified Security-Specialty, AWS Certified Solutions Architect, Microsoft Certified: Security, Compliance & Identity, Security+, CEH, CySA+, GCIH, or related certification is an additional qualification.
- Strong analytical, problem-solving, communication, and collaboration skills are required.
Benefits
- Equity participation, company-paid medical, dental, and vision coverage, and $100,000 of company-paid life insurance are offered.
- Paid time off starts at 15 vacation days and grows to 20 or more annually, with 10 paid holidays.
- The company offers a 401(k) with a stated employer match, eight weeks of paid parental leave, and childcare reimbursement of up to $350 per day for work-related travel.
- Daily catered lunch, unlimited snacks, office socials, recreational activities, family gatherings, and a workspace setup are provided.
- This is a full-time, onsite role requiring five days per week at the Playa Vista, California office, with stated flexibility to integrate work and life.