Build invincible apps.
Staff Cloud Security Engineer
Location
United States
Posted
1 day ago
Salary
$225K - $275K / year
Seniority
Lead
Job Description
Staff Cloud Security Engineer
Temporal Technologies
• Collaborate with product and engineering teams to integrate security principles into the design and architecture of cloud infrastructure across multiple clouds (AWS, GCP, Azure, and others). • Secure Temporal's core platform components, including the workflow engine, task queue architecture, and worker execution model - identifying attack surfaces unique to durable, stateful distributed systems. • Conduct threat modeling and risk assessments to identify vulnerabilities and potential attack vectors across our multi-cloud environment, with particular focus on workflow execution, task queue integrity, and client-server trust boundaries. • Secure Temporal's gRPC-based communication layer, including mTLS certificate management, service mesh configuration, and API authentication. • Manage cloud security posture using tools such as Wiz, including misconfiguration detection, compliance monitoring, and remediation across all three cloud providers. • Stay current on emerging cloud security standards and guidance (e.g. CSA Cloud Controls Matrix, CIS Benchmarks) and translate these into actionable internal policy. • Able to participate in on-call rotation.
Job Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
- 5+ years in cloud security or a related role.
- Proven partnership with engineering teams, bringing security expertise to infrastructure access and security posture.
- Kubernetes security posture management and auditing, including workload hardening, RBAC design, and admission control.
- Demonstrated experience with multi-tenant security architecture, including data plane isolation, control plane hardening, and cross-tenant data leakage prevention.
- Strong opinions on the use of AI in different areas (assessments, threat models, penetration testing, etc).
- A deep understanding of application architecture and design principles, ability to effectively identify vulnerabilities across multiple programming languages
- Experience with secrets management at scale (e.g. HashiCorp Vault, AWS Secrets Manager) and payload encryption patterns such as codec servers for protecting sensitive workflow data.
- Proficiency in Go; familiarity with Python. Go is Temporal's primary server and SDK language.
- Strong command of gRPC security, mTLS, and service mesh architectures (Istio, Envoy).
- Excellent communication and ability to explain complex security concepts to non-technical stakeholders.
- Excellent collaboration and communication skills.
Benefits
- Unlimited PTO, 12 Holidays + 2 Floating Holidays
- 100% Premiums Coverage for Medical, Dental, and Vision
- AD&D, LT & ST Disability, and Life Insurance (Standard & Supplemental Available)
- Empower 401K Plan
- Additional Perks for Learning & Development, Lifestyle Spending, In-Home Office Setup, Professional Memberships, WFH Meals, Internet Stipend and more!
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Utilising knowledge of pen test and red teaming engagements and techniques to plan, write and improve offensive security labs, challenges and online learning content on the Immersive One platform. • Produce multi-format content utilising various teaching methods; practical exercises, questions & gamification • Test Red Team labs and ranges to ensure they function as expected • Research vulnerabilities, tools and offensive tactics and compile this research to deliver practical and theory labs to users • Compile technical research into understandable concise content for both technical and non-technical audience • Work with the wider Product team on new projects and product innovations and how best to deploy them
Role Description Sigma Defense is seeking a Cybersecurity Lead Engineer to support an enterprise DevSecOps platform. - Support DevSecOps and Software Engineers in developing secure platforms and effectively communicating regarding the risk posture of the platforms. - Support of full RMF lifecycle for authorization and re-authorization of existing and novel capabilities including regular communication with stakeholders and authorizing personnel. - Identification and reduction of system vulnerabilities to achieve compliance objectives. - Mentorship and proliferation of cybersecurity culture within team. Qualifications - 8-10 years of Cybersecurity experience. - Experience with DoW RMF policy. - Experience maintaining cybersecurity on an enterprise DevSecOps platform. - Registered DoW RMF Practitioner (RDRP) is preferred. - Must be a U.S. citizen. Requirements - Mandatory Certifications: CISSP - Personnel Clearance Level: Candidate must possess or have the ability to obtain an active Secret security clearance or higher. Clearance may be sponsored for the right candidate. - Education Requirements: Bachelor's degree from an accredited college or university in Cyber Security, Information Technology, Information Systems, Computer Science, Computer Engineering, Mathematics, or related field of study. Degree may be substituted for comparable additional industry experience and/or industry accepted training and certification. Benefits - Salary Range: $135,000 - $145,000 annually. - Dental and Vision Insurance - Medical Insurance to Include HSA, FSA, and DFSA Plans - Life and AD&D coverage - Employee Assistance Program (EAP) - 401(k) Plan with Company Matching Contributions - 160 Hours of Paid Time Off (PTO) - 12 (Floating) Holidays - Educational Assistance - Highly Competitive Salary
• We are seeking a highly motivated Senior Security Engineer with a strong passion for Identity and Access Management (IAM) to join our Enterprise Security & Infrastructure (ESI) organization. • The ideal candidate brings hands-on experience designing, engineering, implementing, and supporting enterprise-scale identity solutions across hybrid environments (on-premises and cloud). • This role requires a deep understanding of modern identity technologies, along with the ability to secure and optimize identity platforms that support critical business operations. • A successful engineer in this role will maintain awareness of new security and identity trends, research, evaluate, design, and recommend technical security solutions for the enterprise. • This role is critical in ensuring the secure, efficient, and compliant management of identities and access across the organization, helping to protect enterprise assets while enabling business productivity. • The Senior Security Engineer, Identity & Access Management is responsible for designing, implementing, and maintaining secure, scalable IAM solutions across hybrid environments, while driving modernization toward Zero Trust and cloud-based identity models. • This role focuses on engineering automated identity processes, strengthening access governance and privileged access controls, and integrating AI-enabled capabilities to enhance security and operational efficiency. • The engineer partners closely with cross-functional teams to assess and mitigate identity-related risks, implements monitoring and automated response for identity threats, and contributes to technology evaluation and innovation. • Additionally, the role ensures compliance with regulatory requirements, supports audit readiness, and establishes standards and best practices to continuously improve enterprise identity security.
Security Consultant
ProArchConsulting and technology- enabled by cloud, guided by data, fueled by apps, and secured by design.
Role Description A Security Consultant is a client-focused role responsible for leading and supporting ProArch customers in building, operating, and continuously improving a comprehensive security program. This position blends security advisory, service delivery, and operational oversight, using ProArch standard playbooks, tooling, and reporting to reduce risk and improve security outcomes. Security Consultants leverage ProArch’s security platforms to detect and prevent cyber threats, onboard clients into managed security services, maintain solution health, and communicate risk and remediation priorities to technical and executive stakeholders. Ongoing training and professional certifications are part of the job requirements. Job Responsibilities - Client Advisory & Program Leadership - Lead security strategy development and roadmap planning aligned to business priorities. - Produce and deliver executive security reporting (risk, trends, outcomes, and next steps). - Provide security assessments, vulnerability management guidance, and awareness program support as part of managed services and professional services engagements. - Service Delivery & Operational Oversight - Own solution implementation and program onboarding, including documentation, handoffs, and acceptance criteria. - Implement and manage SIEM/XDR architecture (e.g., Microsoft Sentinel and Microsoft Defender XDR) including configuration, tuning, and workflows. - Maintain solution health and integrations (connectors, data sources, agents, and alert fidelity). - Perform account/permission management and governance for security solutions. - Provide guidance and escalation support for Security Specialists; coordinate incident and service issue escalations to resolution. - Pre-sales & Practice Contribution - Support presales meetings, proof-of-value/proof-of-concept efforts, and security program cost & scope modeling. - Deliver vendor and ProArch workshops; contribute to presentations, webinars, and approved marketing initiatives. - Research and evaluate emerging technologies; contribute to solution design and service evolution. - Standardization & Continuous Improvement - Deliver services using ProArch standard playbooks, templates, quality gates, and reporting packs. - Improve programs through automation and security engineering (where appropriate) to increase repeatability and reduce manual effort. Qualifications - Minimum of 4 years of experience in cybersecurity with additional background in security consulting or managed security services. - Hands-on capability in core security platforms. - Ability to translate technical findings into business risk. - Strong client communication skills. Requirements - Required (hands-on) - SIEM/XDR delivery and operations, particularly Microsoft Sentinel and Microsoft Defender XDR. - Kusto Query Language (KQL) for detection, investigation, and reporting (SPL is a plus). - SOAR and automation concepts and process design. - Identity and endpoint security fundamentals (e.g., Entra ID, Identity Protection, Defender for Endpoint). - Strong client-facing communication: security report analysis, remediation recommendations, and executive-ready storytelling. - Working knowledge - Microsoft security platform components (Defender for Office 365, Defender for Identity, Defender for Cloud Apps, Defender for Cloud, Intune, Entra ID). - Managed Detection and Response (MDR) experience in a managed services model. - Vulnerability management tooling and process (e.g., Qualys) and remediation strategy development. - Scripting/automation using PowerShell, Python, and/or Azure CLI. - Preferred - Microsoft Purview (IRM, DLP, Insider Risk) and governance concepts. - CrowdStrike Endpoint/Identity/XDR experience. - Cloud security exposure beyond Microsoft (AWS/GCP) and related security services. - Experience with Azure DevOps and process-driven delivery. - Microsoft Foundry, Microsoft 365 Copilot, and Microsoft Security Copilot familiarity. Education and Certification - BS or MS in Computer Science / Engineering or significant demonstrable experience in Microsoft Cloud Security. - Must have the following Certifications. If not held at time of hire, must be attained within 6 months after hire: - Microsoft: AZ-900 - Microsoft: SC-300 - Microsoft: AZ-500 - ISC: CISSP - Preferred certifications: ISC2 CISSP; Microsoft SC-200; and/or certifications such as CEH, CCSP, CISM. Benefits - Empower employees to develop at their own pace through Career Pathways. - Culture of positivity, inclusivity, and respect. - Flexible work schedules to prioritize work-life harmony. - Opportunities for volunteer efforts and charitable initiatives. - Recognition programs for extraordinary efforts.



