Senior Cloud Security Engineer

Security Engineer · Senior · Full Time · Remote

Remote (United States) · RemoteUSD 123k – 181k2w ago
Apply for this role

Opens Rescale's application page

Role

What you'll do.

Senior Cloud Security Engineer at Rescale, a leader in digital engineering and HPC solutions. This hands-on role focuses on securing cloud infrastructure (AWS), identity systems (Okta), and internal AI-assisted tooling through infrastructure-as-code automation, compliance monitoring, and emerging threat research. The position requires 5+ years of cloud-native security expertise, deep AWS proficiency, and practical experience with IAM, Terraform, and modern DevSecOps practices.

Responsibilities

  • Cloud Infrastructure and Identity System Hardening: Design, build, and harden cloud infrastructure on AWS and identity systems using Okta, establishing secure baselines and implementing defense-in-depth controls. Develop Infrastructure-as-Code through Terraform to codify security controls, identity provisioning, compliance-relevant configurations, and automated monitoring to maintain consistent security posture across environments.
  • Security Automation and Detection Pipeline Development: Architect and maintain security automation and detection pipelines that proactively identify anomalies and threats. Build automated responses to security events and create data-driven dashboards using tools like CloudTrail Lake, Athena, and Superset to provide real-time visibility into security metrics and compliance status.
  • AI-Assisted and Agentic Tooling Security Assessment: Evaluate, design security controls for, and implement safeguards around the growing ecosystem of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation). Research emerging AI security attack techniques and translate findings into practical, enforceable controls and internal guidance.
  • Security Incident Investigation and Response: Investigate and respond to security findings with hands-on technical depth: triage authentication anomalies, analyze access logs, review historical CloudTrail data, and query security telemetry via data warehousing tools. Develop and maintain runbooks and playbooks to scale incident response practices across the security team.
  • Enterprise Customer Secure Deployment Support: Partner with engineering and customer-facing teams to design secure network and cloud deployment architectures for enterprise customer environments. Define security requirements, validate architecture compliance, and provide tactical guidance on access controls, encryption, and network isolation patterns for customer-specific infrastructure needs.
  • Emerging Cloud-Native and AI Security Research: Conduct ongoing research into emerging cloud-native security capabilities, AI-enabled attack vectors, and advanced threat landscapes. Translate technical research findings into actionable internal security guidance, training content, and control enhancements that raise organizational security awareness and maturity.
  • Security Documentation and Knowledge Transfer: Author and maintain comprehensive internal documentation, runbooks, playbooks, and architectural guides that enable team members and cross-functional stakeholders to implement and maintain security practices. Create clear operational procedures that scale security practices across engineering teams and support incident response efficiency.

Qualifications

What we look for.

Technical

  • AWS Cloud Security and Architecture

    Deep, hands-on expertise with AWS services including IAM, VPC, CloudTrail, CloudWatch, KMS, Secrets Manager, and security-focused services. Proficiency in designing secure network architectures, implementing least-privilege access models, and hardening AWS infrastructure against cloud-native attack vectors.

  • Infrastructure-as-Code with Terraform

    Advanced Terraform expertise to codify infrastructure, security policies, compliance controls, and monitoring configurations. Ability to design modular, reusable Terraform modules that enforce security best practices, enable repeatability, and support audit trails for compliance requirements.

  • Identity and Access Management (IAM)

    Deep understanding of identity architecture, OAuth 2.0, SAML, token-based authentication, and modern identity platforms. Hands-on experience with Okta (or similar identity providers like Azure AD) including provisioning, policy enforcement, conditional access, and federation management.

  • Bash and Python Scripting

    Proficiency in Bash and Python (3+ years minimum) to automate security workflows, parse logs, build detection logic, query cloud APIs, and develop security tooling. Ability to write clean, maintainable scripts that integrate with CI/CD pipelines and security tools.

  • Cloud-Native Security and DevSecOps

    Comprehensive understanding of cloud-native security principles, containerization security (Docker/Kubernetes if applicable), secrets management, supply chain security, and DevSecOps practices. Ability to integrate security into infrastructure deployment pipelines and enforce security controls at build-time.

  • Security Logging, Monitoring, and Analytics

    Expertise in collecting, aggregating, and analyzing security logs at scale using CloudTrail, CloudTrail Lake, Athena, and data warehousing tools like Superset. Proficiency in building detection queries, creating security dashboards, and translating log data into actionable threat intelligence.

  • AI/LLM Security and Emerging Threat Landscape

    Real-world exposure to securing AI-assisted and agentic tools, understanding of LLM attack vectors (prompt injection, data exfiltration), and knowledge of AI-driven security threats. Ability to evaluate risks associated with autonomous workflows and implement guardrails for LLM-powered systems.

  • Operating Systems and Networking Fundamentals

    Solid grasp of Linux/Unix operating system internals, authentication and authorization mechanisms, network protocols, DNS, encryption, and network segmentation. Ability to troubleshoot security issues at the OS and network layer and design secure network topologies.

Education

  • Bachelor's Degree in Computer Science or Related Field

    Formal education in Computer Science, Cybersecurity, Computer Engineering, or related field preferred. However, equivalent practical experience in cloud security, DevSecOps, or infrastructure security is valued equally or more highly.

Experience

  • 5+ Years Cloud-Native Security or DevSecOps

    Minimum 5 years of hands-on experience in cloud-native security, DevSecOps, or infrastructure security roles. Demonstrated ability to design and implement security controls in production environments, mature understanding of cloud security architecture, and proven track record of reducing risk.

  • 3+ Years Bash or Python Programming

    Minimum 3 years of professional experience writing and maintaining Bash or Python code for automation, tooling, or infrastructure management. Demonstrated ability to write production-grade scripts that are maintainable, efficient, and well-documented.

  • Hands-On Cloud Platform Experience

    Deep, practical experience with at least one major cloud provider (AWS, Azure, GCP, or OCI) in a security or infrastructure role. Demonstrated ability to design and troubleshoot cloud infrastructure, understand platform-specific security models, and stay current with platform security updates.

  • OAuth, AI Security, or Agentic Workflow Exposure

    Real exposure to at least one of: OAuth/OIDC token architecture and implementation, securing AI/LLM-assisted tools, or designing security controls for agentic workflows and autonomous systems. Ability to articulate security risks and implement controls in these emerging areas.

Skills

Required

  • AWS Platform Services

    IAM policies and role-based access control, VPC networking and security groups, CloudTrail logging and monitoring, KMS encryption key management, Secrets Manager for credential rotation, Security Hub for compliance monitoring

  • Terraform Infrastructure-as-Code

    Terraform HCL syntax, state management, module design patterns, provider configuration, variable organization, output design, and integration with CI/CD pipelines for infrastructure deployment

  • Python Programming

    Core language proficiency for security automation, AWS SDK (boto3) for cloud API interaction, log parsing and analysis, building detection logic, data processing, and integration with monitoring platforms

  • Bash Scripting

    Shell scripting for automation, command-line tool integration, log analysis pipelines, scheduled security tasks, and operational runbook implementation

  • Okta or Similar IAM Platform

    User provisioning and deprovisioning workflows, group and role management, policy configuration, MFA and adaptive authentication, SSO and federation setup, audit logging and compliance reporting

  • Cloud Security Best Practices

    Least-privilege access design, defense-in-depth controls, threat modeling for cloud architectures, compliance frameworks (SOC 2, ISO 27001), incident response procedures, and security hardening standards

  • Security Logging and Analysis

    CloudTrail event analysis, CloudTrail Lake querying, Athena SQL for log data queries, Superset dashboard creation, log aggregation patterns, and security metrics visualization

  • Linux/Unix Systems Administration

    Operating system security concepts, file permissions and access controls, authentication mechanisms, network configuration, system hardening, and troubleshooting security-related OS issues

Preferred

  • Kubernetes and Container Security

    Nice to have

    Experience securing containerized environments, implementing pod security policies, managing container image scanning, understanding service mesh security, or designing secure CI/CD pipelines for container deployment

  • OAuth 2.0 and OpenID Connect

    Nice to have

    Deep understanding of OAuth 2.0 grant flows, token-based authentication patterns, OpenID Connect federation, audience/scope management, and implementation of secure authentication architectures

  • LLM and AI Security

    Nice to have

    Practical experience securing large language models, understanding prompt injection attacks, designing guardrails for AI-assisted tools, implementing output filtering, or evaluating safety of agentic automation systems

  • Security Information and Event Management (SIEM)

    Nice to have

    Experience implementing or managing SIEM platforms, writing detection rules, creating alert logic, or designing security data pipelines for real-time threat detection

  • GitHub Enterprise Administration

    Nice to have

    Repository access control, branch protection policies, secret scanning, supply chain security, GitHub Actions security, or organization-wide policy enforcement

  • Cloud Compliance Frameworks

    Nice to have

    Hands-on experience with SOC 2 Type II, ISO 27001, FedRAMP, HIPAA, or PCI-DSS compliance implementation, audit preparation, and ongoing compliance monitoring

  • Incident Response and Forensics

    Nice to have

    Experience responding to security incidents, conducting log-based investigations, performing forensic analysis, or developing post-incident lessons learned and security improvements

  • Advanced AWS Services

    Nice to have

    GuardDuty threat detection, SecurityHub compliance monitoring, WAF deployment for application protection, Organizations for multi-account security, or Config for infrastructure compliance

Tech stack

Languages

Python 3BashHCL (Terraform)SQL

Frameworks

TerraformAWS CloudFormation

Databases

AWS AthenaCloudTrail LakeSuperset

Tools

AWS IAMOktaAWS CloudTrailGitHub EnterpriseAWS CloudWatchAWS KMSAWS Secrets ManagerAWS VPC and Security Groups

Other

OAuth 2.0 and OIDCSecurity Automation and Detection PipelinesDevSecOps PracticesAI and LLM SecurityCloud-Native Threat ModelingInfrastructure Security Hardening

Compensation

Pay and benefits.

Base·USD 123,000 – 181,000

Full posting

Original listing.

About Rescale

Rescale is pioneering the future of engineering and scientific discovery. As the leader in digital engineering, we’re transforming how products are developed—through intelligent automation, applied AI, data management, and the integration of the world’s largest network of engineering and R&D applications. Joining Rescale means becoming part of a diverse, collaborative, and mission-driven team that’s unlocking faster innovation across industries like aerospace, energy, life sciences, and manufacturing. We’re solving complex challenges that traditional HPC can’t—and we’re seeking passionate, curious minds to help build the next wave of breakthroughs.

We're hiring a Senior Cloud Security Engineer to help secure the cloud infrastructure, identity systems, and internal tooling that our platform and our company run on. You'll work across AWS, Okta, GitHub Enterprise, and increasingly AI-assisted and agentic tooling our employees use daily. This is a hands-on role: you'll be writing Terraform, querying logs, and designing IAM policy, not just reviewing other people's work.

What you'll work on:

  • Design, build, and harden cloud infrastructure and identity systems

  • Build and maintain security automation and detection pipelines

  • Evaluate and help secure the growing set of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation)

  • Investigate and respond to security findings, including triaging authentication anomalies, reviewing access logs, and querying data via tools like Athena, CloudTrail Lake, or Superset.

  • Contribute to Infrastructure-as-Code (Terraform) for security controls, identity provisioning, and compliance-relevant configuration and monitoring.

  • Support secure network and cloud deployment designs for enterprise customer environments, partnering with engineering and customer-facing teams on requirements.

  • Research emerging cloud-native and AI security capabilities (including AI-enabled attack techniques) and translate findings into practical controls and internal guidance.

  • Write internal documentation, runbooks, and playbooks to scale security practices across the team.

What we're looking for:

  • 5+ years of experience in cloud-native security or DevSecOps.

  • 3+ years of experience with Bash or Python.

  • Deep, hands-on experience with a major cloud provider (AWS, Azure, GCP, or OCI.

  • Experience with Infrastructure-as-Code (Terraform or similar) and identity/access management platforms (Okta, Azure AD, or similar).

  • Real exposure to at least one of: OAuth/token architecture, AI/LLM-assisted tooling security, or agentic workflow design

  • Solid understanding of operating systems and networking fundamentals.

  • Bachelor's degree in Computer Science or related field, or equivalent practical experience, but not required if you have the experience above.

Rescale is an equal opportunities employer and welcomes applications from all qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age. As part of our standard hiring process for new employees, employment with Rescale will be contingent upon successful completion of a comprehensive background check. Here at Rescale, we are committed to being transparent in our policies around candidate privacy. For more details on the information Rescale collects in your application, please view the Rescale Applicant Privacy Policy here.

Redirects to Rescale's application page.

Other roles

More at Rescale.