Jobs and Careers
AC

Senior Cloud Security Engineer

Acrisure
Oklahoma City, United Statesfull_timeVerifiedPosted 6 Nov 2025

About the role

Department: Information SecurityReports to: Senior Director, Information Security

Role Summary

You will be a hands-on cloud security engineer who builds, automates, and scales controls across AWS and Azure environments. You’ll design paved-road patterns for secure infrastructure, codify guardrails as policy-as-code, and partner with platform and application teams to make secure deployment the default.Success in this role means building trust in the cloud through automation, ensuring every workload is observable, compliant, and resilient — without slowing innovation.

What You’ll Do (Core Responsibilities)
 

Architect and Automate Secure Cloud Foundations

  • Design and maintain secure-by-default landing zones and paved road templates for AWS and Azure (network segmentation, IAM baselines, encryption, logging, monitoring, backup, and key management).
  • Build infrastructure-as-code (IaC) modules with embedded controls (Terraform, ARM/Bicep, CloudFormation) and enforce them through CI/CD policy gates.
  • Implement and manage CSPM/CWPP controls using tools such as Wiz, Prisma Cloud, or Defender for Cloud to continuously assess misconfigurations, exposure, and drift.
  • Develop policy-as-code automation with tools like Open Policy Agent (OPA), Conftest, or Terraform Sentinel to enforce enterprise standards during build and deploy.

Secure Access, Identity, and Network Boundaries

  • Engineer and maintain least-privilege IAM and federated access patterns across AWS IAM, Azure AD, and hybrid workloads.
  • Implement zero-trust network and private connectivity architectures using Private Link, VPC Peering, Transit Gateways, and Azure Virtual WAN.
  • Integrate secrets and key management (AWS KMS, Azure Key Vault) into developer workflows and CI/CD pipelines.
  • Establish consistent patterns for cross-account role assumptionconditional access, and machine identity lifecycle management.

Defend and Detect in Cloud Environments

  • Build and tune cloud-native detections for suspicious activity (CloudTrail, GuardDuty, Security Hub, Azure Defender, and Sentinel analytics).
  • Create threat detection-as-code pipelines to codify detections, alert thresholds, and response actions.
  • Partner with SOC and IR teams to provide enriched telemetry, context, and runbooks for cloud-specific threats (e.g., key misuse, persistence techniques, data exfiltration).
  • Implement data protection controls for object and block storage (encryption at rest and in transit, DLP policies, cross-region replication hardening).

Enablement and Governance

  • Translate complex cloud security risks into actionable engineering guidance; contribute to secure coding and IaC standards.
  • Act as a trusted advisor to platform, DevOps, and engineering teams during architecture and design reviews.
  • Drive adoption of continuous compliance frameworks (NIST 800-53, CIS, ISO 27001, SOC 2) using automation and evidence collection.
  • Publish dashboards and metrics for coverage, control health, and SLA performance.

Vulnerability and Risk Management

  • Integrate container and image scanning into CI/CD and runtime (ECR, ACR, GitHub, or Harness pipelines).
  • Own triage for cloud misconfiguration findings and ensure risk-based prioritization using exposure, exploitability, and asset criticality.
  • Escalate KEV or autowormable vulnerabilities as emergency response;

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Acrisure

View company profile →