Cloud Security Manager
BoeingAbout the role
Job Description
At Boeing, we innovate and collaborate to make the world a better place. We’re committed to fostering an environment for every teammate that’s welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us.
The Boeing Company is looking for a Cloud Security Manager to join the team in Seattle, WA; North Charleston, SC; Chicago, IL; El Segundo, CA; Mesa, AZ; Berkeley, MO; or Hazelwood, MO.
We’re looking for a Cloud Security & Policy-as-Code Manager to lead a team of approximately 20 engineers and contractors. This team translates security, regulatory, and compliance requirements into automated, enforceable guardrails across multi-cloud and Kubernetes environments. This isn’t a compliance management role — it’s a technical leadership position. You’ll own the platform and the people that build, test, and deploy security policies as code. You’ll guide AI-powered policy tooling, drive threat modeling, and ensure your team delivers reliable guardrails at scale. You set direction, remove blockers, and provide architectural guidance so delivery teams can move quickly while meeting their security obligations. This role reports to the Sr Manager of Cloud Platform & Developer Experience.
Position Responsibilities:
Cloud Environments: AWS Commercial; AWS GovCloud; Azure Commercial; Azure Government; Google Cloud Platform (GCP)
Policy-as-Code development & lifecycle: Authoring, testing, versioning, staged rollout, and deprecation across all environments
Admission control: Kubernetes and cloud-native policy enforcement
Terraform guardrails: Preventive controls integrated into Infrastructure as Code (IaC) pipelines
Encryption & key management enforcement: Automated data protection controls across providers
Continuous compliance automation: Evidence collection, attestations, and remediation workflows
Security posture reporting: Coverage, violation trends, and compliance status
Drift detection: Automated identification of configuration gaps and misalignment against the policy repository
Policy & Guardrails: Define and operate a unified guardrail framework across all five cloud environments using policy-as-code, admission controllers, and Terraform guardrails. Drive continuous compliance automation that reduces manual audit effort through automated evidence collection and reporting. Own drift detection, automated daily comparison of active cloud configurations against the policy repository, flagging gaps and triggering remediation
AI-Assisted Policy Engineering: Guide the development of AI-assisted policy generation using large language models to propose policies, identify control gaps, and draft Merge Requests with rationale. Oversee Large Language Model (LLM) regression testing to validate accuracy when models are upgraded or swapped. Establish monitoring for new Cloud Service Provider (CSP) service releases and documentation changes that triggers automated policy gap analysis
Threat Modeling: Lead threat modeling for new platform capabilities, multi-cloud integrations, and Artificial Intelligence (AI) tooling. Own Threat Model Review (TMR) approvals for system changes. Maintain and extend threat models as new CSP integrations and AI components are introduced
People & Delivery: Lead, mentor, and grow a team spanning policy engineering, AI/ML tooling, and security automation. Set engineering standards by code review, testing coverage, CI/CD quality gates, and documentation norms. Build a culture where policies are treated as production software. Manage contractor relationships, capacity planning, and delivery across multiple workstreams. Collaborate cross-functionally with Cloud Foundations, Platform Acceleration, DevEx, Runtime SRE, and Enterprise Security
Basic Qualifications (Required Skills/Experience):
5+ years experience with Development Operations (DevOps) and/or Development Security Operations (DevSecOps)
5+ years experience leading or managing integrated or technical projects or teams across multiple computing platforms and organizations
3+ years experience implementing Policy As Code (Azure Policy, OPA/Gatekeeper, Rego, or equivalent)
3+ years experience with Infrastructure as Code tools such as Terraform, AWS CloudFormation, or ARM templates
Preferred Qualifications (Desired Skills/Experience):
Experience automating security and compliance controls in IaC and CI/CD pipelines (Terraform policy checks, pre-commit scanning, pipeline gates
Coding profi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s