Jobs and Careers
GE

Cloud Security Engineer/DevSecOps Engineer

Get Well
United States - Remote, United StatesRemotefull_timeVerifiedPosted 11 Jun 2026
💰 $170,000/yr($140,000/yr$170,000/yr)

About the role

Title: Cloud Security Engineer/DevSecOps Engineer
 

Location: This position can be based remotely within the US; EST Preferred
 

Opportunity

We are looking for a Cloud Security Engineer / DevSecOps Engineer to help strengthen and mature security across our AWS and Azure environments, software delivery workflows, vulnerability management processes, compliance operations, and security monitoring platforms.

This is a mid-level individual contributor role for someone who can work independently on defined security initiatives, partner directly with engineering and IT teams, and contribute to cloud security architecture decisions. The ideal candidate is hands-on, practical, and comfortable translating security and compliance requirements into actionable technical improvements.

This role will work across cloud security, DevSecOps, vulnerability management, detection support, and audit readiness using platforms such as AWS, Microsoft Azure, Vanta, Compyl, Rapid7, Wazuh, and InsightIDR.
 

Responsibilities

  • Review, improve, and help design secure architectures across AWS and Microsoft Azure environments.
  • Implement and maintain cloud security controls related to IAM, network segmentation, encryption, logging, key management, backups, secure configuration, and access control.
  • Identify and remediate cloud misconfigurations, excessive permissions, insecure storage, public exposure, weak logging, and missing security controls.
  • Partner with engineering and infrastructure teams to integrate security checks and DevSecOps practices into CI/CD workflows.
  • Operate and improve vulnerability management processes, including scanning, validation, prioritization, remediation tracking, reporting, and exception review.
  • Use security monitoring and telemetry platforms to support alert triage, endpoint visibility, log review, investigation, and detection improvement.
  • Support compliance monitoring, evidence collection, control mapping, and audit readiness activities using Vanta and Compyl.
  • Map technical controls to compliance requirements, internal policies, customer security expectations, and audit evidence needs.
  • Participate in threat modeling and security reviews for new applications, infrastructure changes, cloud deployments, and third-party integrations.
  • Support incident response activities, including alert investigation, log analysis, evidence gathering, containment recommendations, and post-incident improvements.
  • Improve identity and access management practices, including least privilege, MFA, conditional access, service principals, role reviews, privileged access controls, and access certification support.
  • Create and maintain security documentation, cloud security standards, control narratives, runbooks, remediation procedures, and architecture diagrams.
  • Support implementation and maintenance of security benchmarks and frameworks such as CIS, NIST, SOC 2, ISO 27001, HIPAA, FedRAMP Moderate, and HITRUST.
  • Translate security and compliance requirements into practical technical tasks for engineering, IT, and infrastructure teams.

Requirements

  • 3–5 years of experience in cybersecurity, cloud security, DevOps, infrastructure, systems administration, security operations, compliance operations, or a related technical role.
  • Hands-on experience with AWS and/or Microsoft Azure, with the ability to work across both platforms.
  • Working knowledge of cloud security concepts, including IAM, network controls, encryption, logging, monitoring, workload security, and shared responsibility models.
  • Experience with common AWS security services such as IAM, CloudTrail, CloudWatch, GuardDuty, Security Hub, KMS, Config, S3 security, or VPC controls.
  • Experience with common Azure security services such as Microsoft Entra ID, Azure Policy, Defender for Cloud, Key Vault, Network Security Groups, Log Analytics, Sentinel, or related services.
  • Experience with vulnerability management tools such as Rapid7 InsightVM, Nexpose, InsightCloudSec, InsightIDR, or similar platforms.
  • Experience with SIEM, endpoint monitoring, log analysis, or security telemetry tools such as Wazuh, Rapid7 InsightIDR, Microsoft Sentinel, or similar platforms.
  • Familiarity with compliance automation, GRC, or audit readiness platforms such as Vanta, Compyl, or similar tools.
  • Ability to interpret vulnerability, cloud posture, endpoint, and compliance findings and prioritize remediation based on risk.
  • Working knowledge of secure configuration, patch management, asset inventory, evidence collection, vulnerability remediation, and exception management workflows.
  • Basic to intermediate scripting or automation experience using Python, PowerShell, Bas

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Get Well

View company profile →