Cloud Security Engineer

RISCPoint • United State
Remote
Apply
AI Summary

Lead the design, implementation, and governance of secure Infrastructure-as-Code (IaC) environments. Focus on building scalable, automated, and security-first cloud solutions. Collaborate with client engineering and compliance teams.

Key Highlights
CI/CD Pipeline Ownership
Automation-First Engineering
Secure IaC Development
Key Responsibilities
Design, implement, and maintain CI/CD pipelines
Identify manual, error-prone, or repetitive processes and replace them with reliable, scalable automation
Build and maintain a library of secure, reusable Terraform modules
Technical Skills Required
Terraform AWS Azure GCP Python Bash Linux IAM Networking Secrets Management Encryption Monitoring Observability SAST/DAST Containerization Kubernetes Cloud Governance CSPM
Benefits & Perks
Base Salary + Bonus
Company Paid Health Insurance
Company Paid Dental Insurance
Company Paid Vision Insurance
401k with 3% Company Contribution
Generous Vacation Policy
Nice to Have
Experience with observability platforms
Experience with cloud governance frameworks and CSPM tools
Cloud certifications at an intermediate level or higher

Job Description


Overview

We are seeking a Cloud Security Engineer to lead the design, implementation, and governance of secure Infrastructure-as-Code (IaC) environments. This is a fully remote role on a small, senior team. Your decisions will carry real weight and directly impact our team and the outcomes we deliver for clients. We are seeking engineers who own objectives and outcomes, not just tasks. This role will focus on building scalable, automated, and security-first cloud solutions that align with best practices, regulatory frameworks, and organizational security requirements across AWS, Azure, and/or GCP. This role reports to the Director of FedRAMP Engineering and works directly with our compliance and assessment teams.


About the Company

RISCPoint is a cybersecurity consulting firm specializing in helping organizations navigate complex compliance frameworks such as FedRAMP, SOC 2, ISO 27001, and HITRUST. Our team is made up of former assessors, auditors, and industry experts who deliver tailored, high-quality engagements designed to meet each client’s unique needs. With rapid growth and a reputation for trusted expertise, RISCPoint partners with leading cloud service providers, technology companies, and enterprises across industries. Join us and be part of a team that is shaping the future of cybersecurity compliance.


Key Responsibilities

• CI/CD Pipeline Ownership: Design, implement, and maintain CI/CD pipelines that enforce automated security gates, policy-as-code checks, and compliance validation before deployment.

• Automation-First Engineering: Identify manual, error-prone, or repetitive processes and replace them with reliable, scalable automation making the team faster and processes more consistent.

• Secure IaC Development: Build and maintain a library of secure, reusable Terraform modules that encode compliance requirements (SOC 2, ISO 27001, FedRAMP, and others) directly into infrastructure.

• Security-by-Design Implementation: Own security architecture decisions across cloud deployments, including IAM design, network segmentation, secrets management, logging and monitoring pipelines, and encryption controls.

• Client Collaboration: Partner directly with client engineering and compliance teams to translate regulatory and security requirements into executable infrastructure solutions. Document and communicate architectural decisions clearly to both technical and non-technical stakeholders.

• Continuous Improvement: Evaluate and implement emerging IaC security tools, frameworks, and methodologies to advance cloud security posture.

• Practice Development: As an early member of a growing team, actively shape how we approach cloud security engagements. Contribute to internal tooling, methodology, and standards that will define the future of the practice.


Qualifications

• 3+ years of professional experience in cloud infrastructure or DevSecOps, with a focus on Terraform and reusable module creation in at least one major cloud platform (AWS/GCP/Azure).

• 1+ year of hands-on experience with Terraform in enterprise environments, including integrating Terraform with CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, etc.).

• Strong expertise in cloud security including IAM, networking, secrets management, encryption, and monitoring. 

• Experience with observability platforms (Datadog, etc.).

• Solid understanding of compliance requirements (FedRAMP, FISMA, CMMC Level 2, 

SOC 2, ISO 27001, HIPAA, or similar).

• Experience with SAST/DAST tooling (SonarQube, Snyk, Burp Suite, Tenable/Nessus, etc.).

• Experience with containerization, Kubernetes, and secure hardening.

• Familiarity with cloud governance frameworks and CSPM tools (e.g., Prisma Cloud, Wiz, Lacework, AWS Security Hub, AWS Inspector).

• Highly comfortable in scripting languages such as Python or Bash.

• Experience working with and securely configuring Linux operating systems (DISA STIG etc.).

• Excellent communication skills with the ability to translate security requirements into actionable engineering tasks and convey technical concepts to non-technical audiences.

• Cloud certifications at an intermediate level or higher. AWS Solutions Architect Associate required. AWS Solutions Architect Professional, Security Specialty, GCP, and Azure equivalents preferred.


Compensation & Benefits 

• Base Salary + Bonus 

• Company Paid Health Insurance 

• Company Paid Dental Insurance 

• Company Paid Vision Insurance 

• 401k with 3% Company Contribution (Traditional & Roth Options) 

• Generous Vacation Policy


Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

the brixton group

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Associate

Akvelon, Inc.

United State
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

Brooksource

United State

Subscribe our newsletter

New Things Will Always Update Regularly