ABOUT THE ROLE
We're seeking an experienced Security Engineer to help secure our cloud infrastructure and container environments. In this role, you'll build and enforce security controls through infrastructure as code, manage governance across cloud accounts, and strengthen the security posture of our Kubernetes environments.
This is a great opportunity for someone who enjoys solving security problems through automation and code rather than manual processes, and who wants to have a direct hand in how security is baked into infrastructure from the ground up.
KEY RESPONSIBILITIES
- Design, implement, and maintain Terraform modules that embed security best practices into infrastructure provisioning
- Develop and manage Service Control Policies (SCPs) to enforce guardrails across cloud accounts and organizational units
- Build and maintain policy as code using tools such as Open Policy Agent (OPA), Sentinel, or Conftest to automate compliance checks
- Harden Kubernetes clusters and workloads, including RBAC, network policies, pod security standards, and admission controls
- Integrate security scanning and policy enforcement into CI/CD pipelines to catch misconfigurations before deployment
- Conduct security reviews of infrastructure changes and provide remediation guidance to engineering teams
- Monitor cloud environments for policy violations, drift, and emerging threats
- Collaborate with DevOps, platform, and compliance teams to align security controls with business and regulatory requirements
- Maintain documentation for security policies, standards, and infrastructure security architecture
- Stay current on cloud security, container security, and infrastructure as code best practices
QUALIFICATIONS
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent experience
- 3+ years of experience in security engineering, cloud security, or DevSecOps
- HashiCorp Certified: Terraform Associate certification
- Hands-on experience writing and managing Terraform for cloud infrastructure
- Practical experience with AWS Service Control Policies (SCPs) or equivalent guardrail mechanisms in Azure or GCP
- Experience implementing policy as code for automated compliance and governance
- Kubernetes security training or hands-on experience securing containerized environments
- Strong analytical and problem-solving skills, with the ability to communicate security risk clearly to technical and non-technical stakeholders
PREFERRED EXPERIENCE
- Certified Kubernetes Security Specialist (CKS) or equivalent Kubernetes security certification
- Experience with policy as code frameworks such as OPA/Gatekeeper, Kyverno, or HashiCorp Sentinel
- Familiarity with infrastructure scanning tools such as Checkov, tfsec, or Trivy
- Experience with AWS Organizations, Azure Policy, or GCP Organization Policy
- Additional certifications such as AWS Certified Security – Specialty, CKA, or CISSP
- Experience with runtime security and threat detection tools such as Falco
- Familiarity with CI/CD platforms (GitHub Actions, GitLab CI, Jenkins) and integrating security gates into pipelines