Cloud Security Engineer (Senior to Staff)
Public customer engagement SaaS, NYC HQ, global team
About the role
The security org here reports to the CISO and runs as a real security engineering team, separate from DevOps and infrastructure. This seat is the top cloud security IC on that team. You will define secure-by-default architecture for AWS and GCP, own threat modeling as a repeatable practice, and build the controls yourself in Terraform and Python rather than managing security through vendor consoles. It is a builder role for a true security engineer, not a DevSecOps or platform seat. On-call rotation, mostly remote, NYC office about once a month. Visa sponsorship and transfers are available.
What you will own
- Cloud security strategy, standards, and reference architectures across AWS (primary) and GCP, including IAM, control-plane security, and policy-as-code guardrails.
- Security for self-managed Kubernetes clusters, container workloads, and the CI/CD supply chain.
- High-signal SIEM detections for cloud telemetry, plus cloud forensics and incident response.
- Vulnerability management workflows and the security tooling stack (EDR, CSPM, cloud-native services).
- Cross-functional security initiatives end to end, and mentoring the other security engineers on cloud.
What we are looking for
- Roughly five or more years owning production cloud security on AWS inside a dedicated security org, including on-call for security incidents.
- Hands-on with self-managed Kubernetes (cluster, control plane, workloads), not only EKS or GKE.
- Writes production Terraform and Python and has personally built controls, detections, and automation.
- Has led cloud forensics and IR, and delivered threat modeling and supply chain security work with engineering teams.
- Based in the NYC area and able to be in the office roughly monthly.
Nice to have
- Securing AI agents, LLM-driven systems, or agentic workflows.
- GCP alongside AWS, and supply chain security (artifact signing, SBOMs, secrets management).
- Came up through SRE or platform engineering and moved fully into security years ago.
What working with Satoriq is like on this search
We are working this search directly with the hiring manager. Expect a real conversation about fit before anything gets submitted, honest feedback at every stage, and a clear read on comp early.
Similar roles
Senior Security Engineer, Enterprise Security
Public customer engagement SaaS, NYC HQ, global team
Cloud Security Engineer, São Paulo
Public customer engagement SaaS, US HQ, São Paulo office
Corporate Security Engineer, São Paulo
Public customer engagement SaaS, US HQ, São Paulo office