Job Closed
This listing is no longer active.
We empower students & institutions to create meaningful connections to achieve their goals.
Cloud Security Engineer
Location
United States
Posted
132 days ago
Salary
0
Seniority
Senior
Job Description
Cloud Security Engineer
Encoura
• Risk & compliance tracking against government standards (e.g. CCPA, NIST, SOCII). • Tracking and remediation management of vulnerability issues and system patches. • Review and recommend additional or changes to existing AWS security-minded services. • Work with managed security service provider to triage and respond to potential security events. • Grow, as needed, the data fed to SIEM to provide visibility into potential security events. • Develop security-minded reports and dashboards for the Exec team, and for techies. • Develop and deploy security system alerting and monitoring strategy. • Systems access level inventory and auditing. • Provide as-needed security-minded operational support of our applications and platforms. • Partner with development teams on security architecture decisions. • Implement tagging and reporting strategy to measure security event risk/impact. • Gain functional knowledge of all Encoura applications. • Serve in an on-call rotation for security, or potential security-related issues.
Job Requirements
- Experience securely delivering in a complex AWS-based micro-services application environment.
- Strong understanding of the AWS-based security tooling and services.
- Strong understanding of AWS-based IAM roles and accounts.
- Strong understanding of AWS CloudWatch/Athena.
- Proficiency and understanding of the AWS console and CLI.
- 3+ years experience securing a similarly complex AWS-based environment.
- 5+ years of IT experience designing and implementing security solutions.
- Strong automation skills – you believe you can automate everything.
- Hands-on experience with troubleshooting, securing, and improving AWS environments.
- As related to security, familiar with the concepts of microservice architecture and how those concepts are implemented in AWS.
- Experience installing, configuring, and managing and patching cloud-based and on-prem systems.
- A solid security foundation – you’re always thinking, “what happens if this system is compromised?”
- Experience working with application development teams who work in Agile/Scrum/Kanban.
- Able to balance security requirements with budgetary requirements.
- Experience working with SaaS-based solutions that integrate with AWS is a plus.
- Experience with Linux and Windows administration.
- Information Security experience preferred.
- BS in Computer Science, Software Engineering or equivalent, or a Bachelor’s in an unrelated field with at least 5 years of professional technology-based experience.
- AWS Security – Specialty certification (strongly preferred).
- Additional AWS certifications are a plus, as are other relevant certifications.
- A detail-oriented, data-driven decision-maker with a strong appreciation for simplicity in system architecture.
- A collaborative team player, comfortable mentoring others and cross-functionally communicating.
Benefits
- Mission driven culture
- Comprehensive health and benefits package
- 401k company match that vests immediately upon participation
- Paid holidays and a generous PTO policy
- Paid parental leave
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
The Ewing Internship Experience Video Develop the skills and experience you need to succeed in the workplace while making the world a little greener at Ewing, the largest family-owned supplier of landscape and irrigation products in the U.S. During an internship at Ewing, you can expect to grow your skills, knowledge, and experience in wholesale distribution by working in several different job functions in our rotational program. You will gain operations experience working alongside our Branch Service Professionals learning counter sales, shipping, and receiving. Shadowing and performing the duties of a Branch Manager exposes interns to strategic planning and operations of running a branch. Interns will gain sales experience working alongside some of our Account Managers performing sales calls and activities to grow the business. Lastly, interns are exposed to high-level leadership through the mentoring from Regional and Divisional Managers allowing exposure to the strategic development of the business and our employees. All interns will be given the opportunity to work on a Capstone Project, where interns use their knowledge, skills, and interests to develop process improvement strategies for Ewing! Examples of projects include but not limited to… - Customer churn outreach - Conducting employee “stay” interviews - Social media outreach - Customer satisfaction exploration - Learning & Development activity effectiveness - And more! At the completion of the project, you will get the opportunity to present your findings and show off your hard work to a group of company executives. A great experience throughout!
Security GRC Program Manager
VanillaMaking Estate Planning Simple for Financial Advisors. Built for advisors, loved by clients.
• Lead customer due diligence questionnaire (DDQ) and RFP response process and third-party risk management process; track and manage high volume of DDQ and RFP requests. Coordinate and collaborate with internal teams to meet tight deadlines. Handle a high volume of requests and interactions in a fast-paced environment • Support enterprise sales with technical customer security discussions • Lead SOC 2 Type II audit preparation, evidence collection, and remediation • Conduct third party vendor security assessments, collaborate on third party risk management processes • Implement and manage third party tool and new processes to create efficiencies • Develop the security narrative and conduct security reviews for new product functionality to enable GTM • Review and negotiate security and compliance language in customer contracts in collaboration with Legal team • Build and manage Trust Center integrations and public-facing security documentation in collaboration with Legal team • Build customer-facing compliance artifacts (security whitepapers, certifications)
• Performs a variety of routine project tasks applied to specialized information assurance problems. • Tasks involve integration of electronic processes or methodologies to resolve total system problems, or technology problems as they relate to IA requirements. • Analyzes information security requirements. • Applies analytical and systematic approaches in the resolution of problems of workflow, organization, and planning. • Provides security engineering support for planning, design, development, testing, demonstration, and integration of information systems.
Information Security Engineer – Application Security Focus
Mechanical OrchardMechanical Orchard combines software development and managed cloud operations in one offering.
• Build Security into Development: Work alongside engineering teams to integrate security throughout the SDLC; from design reviews and threat modeling to secure coding practices. Conduct security assessments of applications, APIs, and cloud infrastructure. Guide developers on secure authentication, authorization, cryptography, and data protection. Champion security best practices while maintaining developer velocity and trust. • Implement Security Tooling & Automation: Deploy and manage application security tools including SAST, DAST, SCA, and container scanning. Build automation for security testing in CI/CD pipelines. Implement and improve secrets management solutions. Create dashboards and metrics to track security posture. • Drive Security Initiatives: Lead application vulnerability management programs including triage, prioritization, and driving remediation. Support security compliance efforts (SOC 2, ISO 27001, or similar frameworks). Contribute to incident response and security event investigation. Develop security training and documentation for engineering teams. • Collaborate Across Teams: Partner with infrastructure and DevOps teams on cloud security controls. Perform risk assessments for new features, technologies, and third-party integrations. Participate in architecture reviews and provide security guidance.




