This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Principal Cloud Security Engineer role is responsible for leading the architecture of public, private and hybrid clouds. This role will lead and advise on advanced secure cloud infrastructure supporting business needs and requires deep technical knowledge of cloud computing architecture, security principles and cybersecurity best practices. The position will design secure infrastructure and applications that align with business and cybersecurity strategy to support a fast-paced environment. This engineer will work in a cross-disciplinary role and plan comprehensive, full-stack security architecture and resilient applications to support the needs of the business. You will provide timely, secure and cost-efficient solutions that elevate the company’s cloud security posture and security rigor.
Job Responsibility:
Architect and articulate a scalable and resilient vision for secure public, private and hybrid clouds
Lead security architecture design with SaaS, PaaS and IaaS
Provide guidance and direction on secure design, build, testing and deployment across cloud infrastructure
Collaborate with security, architecture and engineering leadership to support business objectives
Identify and enforce enterprise standards to support secure, resilient and compliant solutions
Serve as a subject matter expert and escalation point of contact for problem resolution, including incident response
Able to perform testing and evaluations of security controls and device configuration/security
Secure container platforms and workloads from build through runtime
Advise on identity and access management best practices: Azure AD, role-based access control, managed identities, conditional access, and least privilege
In coordination with infrastructure peers, define and monitor network segmentation, private connectivity, and secure service-to-service communication patterns
Lead architecture reviews for cloud-native applications and infrastructure
Monitor, detect, and respond to security incidents affecting cloud and container environments
integrate cloud-native logging and SIEM tools
Establish configuration management, and hardening standards as applicable
Stay current with cybersecurity threats, AI, risks and vulnerabilities with potential impact to services
Mentor and coach staff on secure development, cloud security patterns, container security, and operational best practices
Evaluate, pilot, and operate cloud security tools and managed services (CNAPP, CSPM, CWPP, vulnerability scanners, WAF, API security)
Collaborate on budgeting, procurement, and lifecycle management of cloud security tooling and services
Requirements:
Bachelor’s degree preferred
Eight years minimum experience securing an enterprise environment
Hands-on experience securing Azure and AWS environments
Experience securing container platforms and orchestration: container image hardening, runtime security, network policies, and service mesh considerations
Experience with cloud-native detection and monitoring: designing logging, alerts, and playbooks
working with SIEMs and SOAR
Knowledge of application and data protection mechanisms: encryption at rest/in transit, key management, secret management patterns
Strong understanding of identity and authentication protocols (OAuth2, OIDC, SAML) and secure API authentication/authorization
Experience with vulnerability management for cloud infrastructure and container images
patch management strategies
Solid scripting/automation skills (PowerShell, Python, Bash) and familiarity with APIs/SDKs for automation
Knowledge and experience in using and managing Unix/Linux
Proven track record conducting security architecture reviews
Exceptional communication skills with the ability to explain technical issues to engineers and non-technical stakeholders
Strategic thinker with a pragmatic, risk-based approach to security decisions
Self-starter who takes ownership and drives initiatives to completion
Comfortable in fast-paced, agile environments and able to balance strategic projects with operational response
Nice to have:
Experience with CNAPP/CSPM/CWPP tools
Experience with Zero Trust architectures and implementing micro-segmentation
Strong collaborator and influencer
able to build consensus across engineering and product teams
What we offer:
Highly competitive salary and benefits package
discretionary year-end merit bonus based on performance