Staff Cloud Security Engineer
Bloom Energy1 hour ago
San Jose, CA, USAStaff+
Base Salary
$156k - $224k/yr
Responsibilities
- Design, implement, automate, and maintain cloud security architectures, controls, reference patterns, guardrails, and compliance processes across AWS and Microsoft Azure.
- Integrate security baselines, policy-as-code, automated compliance validation, and security controls into CI/CD and Infrastructure-as-Code deployments.
- Review security-sensitive infrastructure and application changes involving IAM, network controls, secrets management, and cloud-native services.
- Define security frameworks and controls for AI/ML systems, including data ingestion, model training, deployment, monitoring, MLOps, and AI governance.
- Secure Amazon SageMaker, Amazon Bedrock, Azure Machine Learning, OpenAI APIs, and other enterprise AI tooling against emerging AI security risks.
- Implement Data Security Posture Management and controls for databases, data lakes, warehouses, object storage, and analytics platforms.
- Drive encryption, tokenization, data classification, retention, and access governance across cloud data environments.
- Lead security assessments and threat modeling for cloud services, AI/ML platforms, enterprise applications, and emerging technologies.
- Support incident response, investigation, and remediation for cloud, AI, and data security events.
- Develop security standards, policies, and operational procedures while partnering with engineering, infrastructure, product, information and OT security, and enterprise architecture teams.
Requirements
- Bachelor's degree in computer science, engineering, information technology, cybersecurity, or a related field.
- 10+ years of experience in security engineering, cloud security architecture, or cybersecurity operations.
- Strong hands-on expertise with AWS and/or Microsoft Azure security services and cloud-native architectures.
- Experience implementing security automation in CI/CD and Infrastructure-as-Code environments.
- Deep understanding of IAM, network security, encryption, secrets management, logging, monitoring, and threat detection.
- Experience securing enterprise data platforms and modern cloud-native applications.
- Knowledge of NIST, CIS, Zero Trust, and secure SDLC principles.
- Preferred experience securing AI/ML platforms, generative AI services, or MLOps pipelines.
- Preferred familiarity with AI governance, AI security risks, emerging regulatory frameworks, DSPM, CSPM, CNAPP, SIEM, SOAR, and modern cloud security tooling.
- Security certifications such as CISSP, CCSP, CCSK, AWS Certified Security Specialty, or Microsoft Certified: Azure Security Engineer Associate are preferred.
- Additional AI security or data privacy/security training or certifications, such as CDPSE, CIPP, or AI security certifications, is preferred.
Benefits
- Fully on-site, in-office role in San Jose, California, five days per week.
- Full-time position with company benefits.
- Medical, dental, and vision plans with a large employer contribution.
- 401(k) retirement plan with company match.
- Mental health support, legal services, virtual physical therapy, and fertility and family-forming benefits.
- Compensation is based on relevant skills and experience.