Featured Job

Senior Security Engineer

None Full-time Hybrid 09/10/2026 Job ID: 000160
Apply Now
Cloud Security Engineering Terraform CloudFormation IAM Networking

Summary

What you’ll impact

Our company is seeking a Senior Engineer, Cloud Security to design and deploy security infrastructure across Azure and AWS, focusing on Terraform modules, hardened landing zones, and automated identity lifecycles. The role involves direct client engagement, vulnerability remediation, and leading technical discussions to achieve drift‑resistant, code‑defined security excellence.

Responsibilities

What you'll do

  • Design and deploy security infrastructure, build hardened landing zones, automate identity lifecycles, and author reusable Terraform modules.
  • Integrate rapidly into client environments, taking direct ownership of cloud security engineering tasks, vulnerability remediation, and client engagements within the first 15 days.
  • Work directly with client engineering leads during U.S. Eastern Time business hours, lead technical discussions, execute automated security operations, and ensure every environment achieves drift-resistant, code-defined security excellence.
  • Engineer security via Infrastructure as Code - design and maintain reusable Terraform and CloudFormation modules for IAM, networking, and logging to build drift-resistant cloud environments.
  • Build enterprise cloud architectures - deploy and manage AWS multi-account structures including Organizations and SCPs, alongside Azure Hub-Spoke and Landing Zone architectures.
  • Architect identity and access management - implement least-privilege IAM using RBAC, ABAC, permission boundaries, JIT or PIM automation, and federated identity via Okta or Entra ID.
  • Execute direct vulnerability remediation - remediate cloud misconfigurations through active engineering changes, automated patching, and configuration drift correction.
  • Automate security operations and pipelines - build automated remediation workflows using Lambda, Azure Functions, and Python, integrating SAST, DAST, and secret scanning into GitHub Actions or Azure DevOps pipelines.
  • Configure native cloud security stacks - deploy and tune AWS GuardDuty, Security Hub, AWS Config, Azure Sentinel, and Defender for Cloud to build native logging pipelines for SIEM ingestion.
  • Manage network and encryption engineering - design VPCs, security groups, network segmentation, WAFs, and full-lifecycle encryption using AWS KMS and Azure Key Vault.
  • Implement technical NIST 800-53 controls - translate NIST 800-53, FedRAMP, and CMMC compliance criteria into hands-on technical controls across cloud environments.
  • Drive client-facing technical ownership - interface directly with client engineering teams, lead architectural workshops, and manage multiple client engagements simultaneously.

Requirements

What you’ll bring

  • Hands-on security builder - proven track record of deploying security infrastructure, writing OPA policies, and managing secrets in Vault or AWS Secrets Manager.
  • Cloud-native technical specialist - deep expertise in Azure and AWS nuances, capable of distinguishing compliance maps from functional technical controls.
  • Infrastructure as Code expert - proficient in Terraform, with demonstrated expertise in module versioning, state management, and provider security controls.
  • Identity and access authority - deep technical understanding of SAML, OIDC, cross-account IAM roles, and enforcing least privilege without disrupting developer workflows.
  • Articulate technical communicator with a strong verbal presence, able to lead technical workshops and clearly explain complex architecture to engineering teams.
  • Multi-account portfolio operator - thrives in fast-paced startup environments, balancing multiple client priorities and executing rapid remediation without perfect documentation.
  • Active cloud security credentials - hold technical certifications such as AWS Certified Security Specialty, Azure Security Engineer Associate, or GCP Professional Security Engineer.
  • FIPS 140 encryption implementation: practical experience configuring and enforcing FIPS 140 standards across cloud services.
  • Federal enclave build experience - hands-on history building CMMC-compliant enclaves or FedRAMP security architectures.
  • Container runtime security mastery - experience implementing runtime security controls and vulnerability scanning across containerized environments.
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.

Ready to Move Forward?

Apply now and our recruiting team will reach out with next steps, interview guidance, and client insights tailored to this role.