Featured Job

Staff Security Engineer, Cloud

Palo Alto, CA Full-time On-site $205k — $240k per year 08/24/2026 Job ID: 000021
Apply Now
Cloud security AWS IAM AWS VPC AWS network design AWS KMS

Summary

What you’ll impact

The Staff Security Engineer for Cloud at ALSO will own end‑to‑end cloud security for a connected EV platform, shaping strategy, architecture, implementation, and operations across AWS, Kubernetes, and microservices. They will build security controls in Go, harden containers, secure the software supply chain, and serve as the go‑to expert for all security questions while contributing to core backend development.

Responsibilities

What you'll do

  • Own cloud security end to end — strategy, architecture, implementation, and operations across AWS, Kubernetes, and our microservices platform — including threat modeling new systems in architecture reviews before the code exists
  • Design and implement identity and access at scale: workload identity, org-wide IAM, least privilege by default, secrets management, and certificate/key lifecycle, including mutual TLS between services and between cloud and vehicle
  • Harden containers and orchestration: image provenance, admission control, runtime and network policy, service mesh configuration, and clean isolation across microservices
  • Secure the software supply chain: SBOM generation, dependency and image scanning, signed artifacts, and CI/CD pipelines that fail closed on what matters and stay quiet on what doesn't
  • Build the controls in Go — authorization services, policy enforcement, provisioning and rotation tooling — and serve as the DevSecOps function, writing guardrails and policy as code so other engineers move fast without routing every decision through security
  • Run detection and response: security logging and telemetry, meaningful alerting, runbooks, on‑call for security incidents, and blameless postmortems that produce real fixes
  • Secure the vehicle‑to‑cloud boundary: device identity and provisioning, fleet‑wide certificate rotation, secure OTA update paths, and anomaly and tamper detection at scale
  • Contribute to core backend work alongside the team, and own assurance — penetration tests, vulnerability management, evidence collection, and proportionate standards work that strengthens the product instead of slowing it down

Requirements

What you’ll bring

  • 10+ years in backend and infrastructure engineering, with a substantial portion spent owning security in production
  • Expert, hands‑on AWS: IAM, VPC and network design, KMS, Secrets Manager, GuardDuty, Security Hub, CloudTrail, Config, and org‑level guardrails (SCPs), alongside core compute and data services (EKS, ECS, ECR, Lambda, DynamoDB, S3)
  • Deep Kubernetes and container security — RBAC, admission controllers, pod security standards, network policy, secrets handling, runtime detection, and image hardening — with real experience operating clusters, not just reading about them
  • Fast, fluent Go: you design, review, and ship production Go code today, not several years ago
  • Microservices and distributed systems security: service‑to‑service authentication and authorization, API gateway patterns, rate limiting, tenant isolation, and event‑driven pipeline security
  • Identity protocols and applied cryptography in practice: OAuth2, OIDC, JWT, SAML, mutual TLS, and PKI with certificate lifecycle management at scale
  • Infrastructure and policy as code, with security gating built into CI/CD
  • Threat modeling and secure architecture review as routine practice, with specific examples of designs you've changed, plus incident response you've personally led from detection through postmortem
  • Demonstrated 0 to 1 ownership: you've stood up a security function or program where none existed, without a large team behind you

Ready to Move Forward?

Apply now and our recruiting team will reach out with next steps, interview guidance, and client insights tailored to this role.