Jobs and Careers
RE

Principal, Cloud & Infrastructure Security Engineer

Releady
California, United StatescontractVerifiedPosted 10 Mar 2026
💰 $200,000/yr($170,000/yr$200,000/yr)

About the role

OVERVIEW

We are partnering with a leading healthcare technology company to hire a Principal, Cloud & Infrastructure Security Engineer. This organization — launched in January 2025 — provides the technology backbone and digital capabilities for nonprofit, community, and regional health plans nationwide. It is part of a family of companies under a nonprofit parent entity that also includes a major California-based health plan and a clinical services company. You codify the trust boundary, identity fabric, and encryption posture of an Azure-centric platform. Operating with a full-stack developer mindset, you ensure infrastructure security is delivered exclusively through Terraform (IaC) and GitOps, enforcing zero manual changes and zero environment drift. As a senior technical leader on a small, elite team you will act as a cross-functional powerhouse—architecting scalable cloud infrastructure while seamlessly collaborating with and backing up Product & Data Security initiatives. You will play a critical role in accelerating security maturity from "crawl" to "run" as they containerize health plans into a subscription model.

*Must be eligible to work on W2 without sponsorship. Not eligible for C2C.

  • Pay Rate: $85 – $100/hr
  • Duration: 6-month contract-to-hire
  • Location: Hybrid; 2x/week in office — San Diego, Long Beach, Sacramento, Rancho Cordova, or Oakland (SF Bay Area)
  RESPONSIBILITIES
  • Infrastructure as Code (IaC) & GitOps Mastery: Design, author, and maintain infrastructure guardrails using Terraform and GitOps principles. Enforce programmatic policies that prevent insecure infrastructure from being provisioned in Azure.

  • Identity & Access (IAM) Automation: Codify code-based access and author golden IAM modules enforcing least privilege. Implement workload identity federation and Just-In-Time (JIT) access with absolutely no standing credentials, specifically tailored for Azure environments.

  • Container & Network Security: Secure our containerized health plan architectures (e.g., Azure Kubernetes Service) through default-deny micro-segmentation, service mesh mTLS, and declarative network policies.

  • Cryptographic Operations & Data Protection: Define KMS/HSM policies-as-code (e.g., Azure Key Vault). Enforce Customer Managed Keys (CMKs) by default to protect modern data workloads across Azure Synapse, Snowflake, and AI-driven platforms.

  • Cross-Functional Security Operations: Break down traditional security silos. Apply a practical security lens to CI/CD pipelines and application development, acting as a technical backup for AppSec and Data Security functions to ensure continuous team velocity.

  QUALIFICATIONS
  • 10+ years of progressive cloud security, platform engineering, or Kubernetes security experience.

  • Terraform & IaC Dominance: Deep, programmatic expertise in Terraform, infrastructure automation, and GitOps frameworks. Must have a proven track record of completely replacing traditional "click-ops" with code.

  • Azure Cloud Ecosystem Mastery: Illustrated, hands-on experience securing cloud-native apps and pipelines within Azure to limit the learning curve. Strong understanding of Azure-native security controls, containerization, and modern data platforms (Synapse, Snowflake).

  • Advanced Identity & Cryptography: Demonstrated background in codifying complex IAM architectures, automated PKI (certificate lifecycle), and KMS policy enforcement at an enterprise scale.

  • Cross-Functional Agility: Broad understanding of the entire SDLC, CI/CD pipeline security, and AI integrations. Must possess the versatility to stretch beyond pure infrastructure to support Application and Data Security initiatives within a small, highly collaborative team.

Success Measures:
• 100% IAM and network changes via GitOps
• 100% internal service traffic encrypted with mTLS
• 100% storage and secrets protected by CMKs   We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other non-merit factor. We are committed to creating a diverse and inclusive environment for all employees.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Releady

View company profile →