Senior Cloud Security Engineer
Security Engineer · Senior · Full Time · Remote
Opens Rescale's application page
Role
What you'll do.
Senior Cloud Security Engineer at Rescale, a leader in digital engineering and HPC solutions. This hands-on role focuses on securing cloud infrastructure (AWS), identity systems (Okta), and internal AI-assisted tooling through infrastructure-as-code automation, compliance monitoring, and emerging threat research. The position requires 5+ years of cloud-native security expertise, deep AWS proficiency, and practical experience with IAM, Terraform, and modern DevSecOps practices.
Responsibilities
- Cloud Infrastructure and Identity System Hardening: Design, build, and harden cloud infrastructure on AWS and identity systems using Okta, establishing secure baselines and implementing defense-in-depth controls. Develop Infrastructure-as-Code through Terraform to codify security controls, identity provisioning, compliance-relevant configurations, and automated monitoring to maintain consistent security posture across environments.
- Security Automation and Detection Pipeline Development: Architect and maintain security automation and detection pipelines that proactively identify anomalies and threats. Build automated responses to security events and create data-driven dashboards using tools like CloudTrail Lake, Athena, and Superset to provide real-time visibility into security metrics and compliance status.
- AI-Assisted and Agentic Tooling Security Assessment: Evaluate, design security controls for, and implement safeguards around the growing ecosystem of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation). Research emerging AI security attack techniques and translate findings into practical, enforceable controls and internal guidance.
- Security Incident Investigation and Response: Investigate and respond to security findings with hands-on technical depth: triage authentication anomalies, analyze access logs, review historical CloudTrail data, and query security telemetry via data warehousing tools. Develop and maintain runbooks and playbooks to scale incident response practices across the security team.
- Enterprise Customer Secure Deployment Support: Partner with engineering and customer-facing teams to design secure network and cloud deployment architectures for enterprise customer environments. Define security requirements, validate architecture compliance, and provide tactical guidance on access controls, encryption, and network isolation patterns for customer-specific infrastructure needs.
- Emerging Cloud-Native and AI Security Research: Conduct ongoing research into emerging cloud-native security capabilities, AI-enabled attack vectors, and advanced threat landscapes. Translate technical research findings into actionable internal security guidance, training content, and control enhancements that raise organizational security awareness and maturity.
- Security Documentation and Knowledge Transfer: Author and maintain comprehensive internal documentation, runbooks, playbooks, and architectural guides that enable team members and cross-functional stakeholders to implement and maintain security practices. Create clear operational procedures that scale security practices across engineering teams and support incident response efficiency.
Qualifications
What we look for.
Technical
AWS Cloud Security and Architecture
Deep, hands-on expertise with AWS services including IAM, VPC, CloudTrail, CloudWatch, KMS, Secrets Manager, and security-focused services. Proficiency in designing secure network architectures, implementing least-privilege access models, and hardening AWS infrastructure against cloud-native attack vectors.
Infrastructure-as-Code with Terraform
Advanced Terraform expertise to codify infrastructure, security policies, compliance controls, and monitoring configurations. Ability to design modular, reusable Terraform modules that enforce security best practices, enable repeatability, and support audit trails for compliance requirements.
Identity and Access Management (IAM)
Deep understanding of identity architecture, OAuth 2.0, SAML, token-based authentication, and modern identity platforms. Hands-on experience with Okta (or similar identity providers like Azure AD) including provisioning, policy enforcement, conditional access, and federation management.
Bash and Python Scripting
Proficiency in Bash and Python (3+ years minimum) to automate security workflows, parse logs, build detection logic, query cloud APIs, and develop security tooling. Ability to write clean, maintainable scripts that integrate with CI/CD pipelines and security tools.
Cloud-Native Security and DevSecOps
Comprehensive understanding of cloud-native security principles, containerization security (Docker/Kubernetes if applicable), secrets management, supply chain security, and DevSecOps practices. Ability to integrate security into infrastructure deployment pipelines and enforce security controls at build-time.
Security Logging, Monitoring, and Analytics
Expertise in collecting, aggregating, and analyzing security logs at scale using CloudTrail, CloudTrail Lake, Athena, and data warehousing tools like Superset. Proficiency in building detection queries, creating security dashboards, and translating log data into actionable threat intelligence.
AI/LLM Security and Emerging Threat Landscape
Real-world exposure to securing AI-assisted and agentic tools, understanding of LLM attack vectors (prompt injection, data exfiltration), and knowledge of AI-driven security threats. Ability to evaluate risks associated with autonomous workflows and implement guardrails for LLM-powered systems.
Operating Systems and Networking Fundamentals
Solid grasp of Linux/Unix operating system internals, authentication and authorization mechanisms, network protocols, DNS, encryption, and network segmentation. Ability to troubleshoot security issues at the OS and network layer and design secure network topologies.
Education
Bachelor's Degree in Computer Science or Related Field
Formal education in Computer Science, Cybersecurity, Computer Engineering, or related field preferred. However, equivalent practical experience in cloud security, DevSecOps, or infrastructure security is valued equally or more highly.
Experience
5+ Years Cloud-Native Security or DevSecOps
Minimum 5 years of hands-on experience in cloud-native security, DevSecOps, or infrastructure security roles. Demonstrated ability to design and implement security controls in production environments, mature understanding of cloud security architecture, and proven track record of reducing risk.
3+ Years Bash or Python Programming
Minimum 3 years of professional experience writing and maintaining Bash or Python code for automation, tooling, or infrastructure management. Demonstrated ability to write production-grade scripts that are maintainable, efficient, and well-documented.
Hands-On Cloud Platform Experience
Deep, practical experience with at least one major cloud provider (AWS, Azure, GCP, or OCI) in a security or infrastructure role. Demonstrated ability to design and troubleshoot cloud infrastructure, understand platform-specific security models, and stay current with platform security updates.
OAuth, AI Security, or Agentic Workflow Exposure
Real exposure to at least one of: OAuth/OIDC token architecture and implementation, securing AI/LLM-assisted tools, or designing security controls for agentic workflows and autonomous systems. Ability to articulate security risks and implement controls in these emerging areas.
Skills
Required
AWS Platform Services
IAM policies and role-based access control, VPC networking and security groups, CloudTrail logging and monitoring, KMS encryption key management, Secrets Manager for credential rotation, Security Hub for compliance monitoring
Terraform Infrastructure-as-Code
Terraform HCL syntax, state management, module design patterns, provider configuration, variable organization, output design, and integration with CI/CD pipelines for infrastructure deployment
Python Programming
Core language proficiency for security automation, AWS SDK (boto3) for cloud API interaction, log parsing and analysis, building detection logic, data processing, and integration with monitoring platforms
Bash Scripting
Shell scripting for automation, command-line tool integration, log analysis pipelines, scheduled security tasks, and operational runbook implementation
Okta or Similar IAM Platform
User provisioning and deprovisioning workflows, group and role management, policy configuration, MFA and adaptive authentication, SSO and federation setup, audit logging and compliance reporting
Cloud Security Best Practices
Least-privilege access design, defense-in-depth controls, threat modeling for cloud architectures, compliance frameworks (SOC 2, ISO 27001), incident response procedures, and security hardening standards
Security Logging and Analysis
CloudTrail event analysis, CloudTrail Lake querying, Athena SQL for log data queries, Superset dashboard creation, log aggregation patterns, and security metrics visualization
Linux/Unix Systems Administration
Operating system security concepts, file permissions and access controls, authentication mechanisms, network configuration, system hardening, and troubleshooting security-related OS issues
Preferred
Kubernetes and Container Security
Nice to haveExperience securing containerized environments, implementing pod security policies, managing container image scanning, understanding service mesh security, or designing secure CI/CD pipelines for container deployment
OAuth 2.0 and OpenID Connect
Nice to haveDeep understanding of OAuth 2.0 grant flows, token-based authentication patterns, OpenID Connect federation, audience/scope management, and implementation of secure authentication architectures
LLM and AI Security
Nice to havePractical experience securing large language models, understanding prompt injection attacks, designing guardrails for AI-assisted tools, implementing output filtering, or evaluating safety of agentic automation systems
Security Information and Event Management (SIEM)
Nice to haveExperience implementing or managing SIEM platforms, writing detection rules, creating alert logic, or designing security data pipelines for real-time threat detection
GitHub Enterprise Administration
Nice to haveRepository access control, branch protection policies, secret scanning, supply chain security, GitHub Actions security, or organization-wide policy enforcement
Cloud Compliance Frameworks
Nice to haveHands-on experience with SOC 2 Type II, ISO 27001, FedRAMP, HIPAA, or PCI-DSS compliance implementation, audit preparation, and ongoing compliance monitoring
Incident Response and Forensics
Nice to haveExperience responding to security incidents, conducting log-based investigations, performing forensic analysis, or developing post-incident lessons learned and security improvements
Advanced AWS Services
Nice to haveGuardDuty threat detection, SecurityHub compliance monitoring, WAF deployment for application protection, Organizations for multi-account security, or Config for infrastructure compliance
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·USD 123,000 – 181,000
Full posting
Original listing.
About Rescale
Rescale is pioneering the future of engineering and scientific discovery. As the leader in digital engineering, we’re transforming how products are developed—through intelligent automation, applied AI, data management, and the integration of the world’s largest network of engineering and R&D applications. Joining Rescale means becoming part of a diverse, collaborative, and mission-driven team that’s unlocking faster innovation across industries like aerospace, energy, life sciences, and manufacturing. We’re solving complex challenges that traditional HPC can’t—and we’re seeking passionate, curious minds to help build the next wave of breakthroughs.
We're hiring a Senior Cloud Security Engineer to help secure the cloud infrastructure, identity systems, and internal tooling that our platform and our company run on. You'll work across AWS, Okta, GitHub Enterprise, and increasingly AI-assisted and agentic tooling our employees use daily. This is a hands-on role: you'll be writing Terraform, querying logs, and designing IAM policy, not just reviewing other people's work.
What you'll work on:
Design, build, and harden cloud infrastructure and identity systems
Build and maintain security automation and detection pipelines
Evaluate and help secure the growing set of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation)
Investigate and respond to security findings, including triaging authentication anomalies, reviewing access logs, and querying data via tools like Athena, CloudTrail Lake, or Superset.
Contribute to Infrastructure-as-Code (Terraform) for security controls, identity provisioning, and compliance-relevant configuration and monitoring.
Support secure network and cloud deployment designs for enterprise customer environments, partnering with engineering and customer-facing teams on requirements.
Research emerging cloud-native and AI security capabilities (including AI-enabled attack techniques) and translate findings into practical controls and internal guidance.
Write internal documentation, runbooks, and playbooks to scale security practices across the team.
What we're looking for:
5+ years of experience in cloud-native security or DevSecOps.
3+ years of experience with Bash or Python.
Deep, hands-on experience with a major cloud provider (AWS, Azure, GCP, or OCI.
Experience with Infrastructure-as-Code (Terraform or similar) and identity/access management platforms (Okta, Azure AD, or similar).
Real exposure to at least one of: OAuth/token architecture, AI/LLM-assisted tooling security, or agentic workflow design
Solid understanding of operating systems and networking fundamentals.
Bachelor's degree in Computer Science or related field, or equivalent practical experience, but not required if you have the experience above.
Rescale is an equal opportunities employer and welcomes applications from all qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age. As part of our standard hiring process for new employees, employment with Rescale will be contingent upon successful completion of a comprehensive background check. Here at Rescale, we are committed to being transparent in our policies around candidate privacy. For more details on the information Rescale collects in your application, please view the Rescale Applicant Privacy Policy here.
Redirects to Rescale's application page.
Other roles