Jobs and Careers
IN

Principal Cloud Security Engineer

Invesco
United Statesfull_timeVerifiedPosted 4 Mar 2026

About the role

About Invesco

As one of the world’s leading independent global investment firms, Invesco is dedicated to rethinking possibilities for our clients. By delivering the combined power of our distinctive investment management capabilities, we provide a wide range of investment strategies and vehicles to our clients around the world. If you're looking for challenging work, intelligent colleagues, and exposure across a global footprint, come explore your potential at Invesco.

What’s in it for you?

Our people are at the very core of our success. Invesco employees get more out of life through our comprehensive compensation and benefit offerings including: 

  • Flexible paid time off

  • Hybrid work schedule 

  • 401(K) matching of 100% up to the first 6% with a discretionary supplemental contribution 

  • Health & wellbeing benefits 

  • Parental Leave benefits 

  • Employee stock purchase plan

Job Description

The Department

Our Information Security department is to protect Invesco’s information and Information assets from all internal and external, deliberate, or accidental threats. The information security team will protect data from unauthorized access while maintaining the confidentiality, integrity, and availability of information. In addition, designing and maintaining the Security Policies and Standards while adhering to legislative and regulatory requirements, providing information security training for all employees, and ensuring the business continuity of Invesco.

Your Role

Principal Engineer Cloud Security will work closely with technology and application teams to help them secure their cloud environment.  In this role, you will partner with Infrastructure teams to provide secure cloud requirements, and ensure the solutions and infrastructure are securely designed, developed, and implemented, while enforcing conformity with technical standards and approved cloud security architectures that align to regulatory and compliance standards.

You will be responsible for:

  • Designing, configuring, and implementing secure solutions for the firm’s global cloud infrastructure in partnership with architects and engineering teams.

  • Defining cloud security technical requirements, including IAM, network segmentation, data protection, container security, workload protection, CI/CD security, Kubernetes, microservices, SIEM integrations, and more.

  • Developing security patterns and controls for Data Loss Prevention (DLP) across cloud, endpoint, and SaaS environments—including policies, detection tuning, and data governance alignment.

  • Driving SaaS Security strategy, including secure configuration baselines, CASB/CSPM integrations, continuous monitoring, and thirdparty SaaS risk assessment.

  • Strategizing and maturing cloud security solutions to improve compliance with the NIST Cybersecurity Framework, Cloud Security Alliance guidance, and Invesco policies.

  • Developing and deploying infrastructureascode to automate and optimize cloud security controls.

  • Providing technical support for patches, upgrades, incident response, and operational improvements.

  • Performing security threat modeling and design reviews for emerging cloud and SaaS technologies.

The experience you bring:

  • 10+ years of information security experience supporting enterprise‑scale security engineering and architecture programs.

  • 5+ years designing and implementing enterprise cloud security solutions across AWS, Azure, Oracle, and other major cloud providers.

  • Experience with Terraform for deployment automation, orchestration, and security configuration management.

  • Proficiency in scripting (Python, PowerShell, JSON).

  • Experience developing and institutionalizing security standards, blueprints, and patterns aligned to frameworks such as SOX, CSA-CCM, DORA, NIST, ISO, GDPR, and SOC1/2.

  • Hands‑on experience with Data Loss Prevention programs, including policy creation, tuning, incident handling, and integrating DLP with cloud and SaaS platforms.

  • Experience with SaaS Security technologies, such as CASB, SSPM (SaaS Security Posture Management), and SaaS risk assessment frameworks.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Invesco

View company profile →