Engineer Cloud Security
EmpowerAbout the role
Our vision for the future is based on the idea that transforming financial lives starts by giving our people the freedom to transform their own. We have a flexible work environment, and fluid career paths. We not only encourage but celebrate internal mobility. We also recognize the importance of purpose, well-being, and work-life balance. Within Empower and our communities, we work hard to create a welcoming and inclusive environment, and our associates dedicate thousands of hours to volunteering for causes that matter most to them.
Chart your own path and grow your career while helping more customers achieve financial freedom. Empower Yourself.
***Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time, including CPT/OPT.***
The Cloud Security Engineer will manage and secure cloud infrastructure environments by implementing and maintaining secure, reliable, and scalable cloud network architectures. This role focuses on AWS and Azure, applying strong expertise in cloud security controls, networking, and firewalls to protect systems against evolving threats while supporting operational performance and resilience.
What you will do:
Implement and manage secure cloud network infrastructure to support performance, security, scalability, and reliability.
Partner with development teams to integrate security measures and best practices into the development lifecycle.
Architect secure and resilient AWS and Azure environments aligned with industry standards and compliance requirements.
Design and implement security controls and policies to reduce unauthorized access, data breaches, and related risks.
Collaborate with cross-functional teams to support timely resolution of security incidents and security-related issues.
Create and maintain Terraform scripts to provision and manage infrastructure resources using Infrastructure-as-Code (IaC).
Stay current on security best practices, network technologies, and cloud services, and apply improvements to the environment.
Train and guide junior team members on security practices and technologies.
What you will bring:
Bachelor’s degree in Computer Science, Information Technology, or a related field.
Proven experience designing, implementing, and managing network infrastructure, particularly in innovation lab or cloud development environments.
Extensive knowledge of security controls, protocols, and best practices across on-premises and cloud environments.
Strong expertise in AWS and Azure, including architecture, security, and automation capabilities.
Hands-on experience with IaC tools with a focus on Terraform.
Proficiency in Python.
Experience building, tuning, and operating detections using cloud-native tools (GuardDuty, Security Hub) and SIEM platforms (Splunk).
Ability to investigate cloud logs (CloudTrail, VPC Flow Logs, audit logs).
Strong understanding of least privilege IAM design, role-based access, service accounts, and federated identity.
Strong problem-solving, communication, and teamwork skills, with the ability to collaborate with technical and non-technical stakeholders across Cloud Platform, DevOps, SRE, and Engineering teams.
What will set you apart:
Relevant certifications such as CISSP, AWS Certified Security, or similar credentials.
3+ years managing security controls, including defining security policies and guardrails (preferred).
4+ years of technical experience working with security solutions and conducting security operations (preferred).
4+ years of cloud network security experience, including reviewing tools and making recommendations on utilization and strategy (preferred).
4+ years of experience with network protocols, data flows, and attacks within an IP environment (preferred).
3+ years building configurations for security devices and building automated processes to support large-scale deployment (preferred).
Extensive experience with security software, firewalls, intrusion detection systems, and network monitoring (preferred).
Extensive hands-on technical knowledge of network systems, protocols, and standards such as TCP/IP (preferred).
2+ years performing network and application security administration and threat assessments; CISSP or GIAC certification(s) (preferred).
2+ years programming or scripting experience in one or more of Java, Perl, PHP, Python, or shell (preferred).
This jo
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s