Cloud Security & Automation Engineer

Kpg 99 Inc — United States · Posted ~1 day ago

Mid Full-time Onsite

Skills

cloud security cloud exposure management security automation Azure hybrid cloud container security risk remediation security platform administration AWS Wiz Prisma Cloud containers cloud-native

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A hands-on cloud security engineering role focused on securing public cloud, hybrid, container, and cloud-native environments. You will operate cloud exposure management platforms, onboard cloud accounts, manage policies and integrations, convert identified risks into durable technical controls, and automate measurable remediation in collaboration with security teams.

Highlights

Hands-on full-time cloud security engineering role focused on reducing cloud exposure, automating remediation, operating security platforms, and implementing durable controls across public, hybrid, and container environments.

Description

Job Title: Cloud Security Engineer Location: Wilmington, DE/ Manassas, VA/Urbandale, IO/ Coppell/Dallas, TX Duration: Full Time Summary: The Cloud Security & Automation Engineer is a hands-on engineering role responsible for improving security across public cloud, hybrid, container, and cloud-native environments. The role owns the day-to-day engineering and operation of cloud exposure management capabilities, including platforms such as Wiz or Prisma Cloud, and converts prioritized risk into durable technical controls, automated workflows, and measurable remediation outcomes. The engineer will work closely with Vulnerability Management and AI Security Teams. Cloud exposure management and platform ownership Configure, administer, optimize, and troubleshoot cloud security and exposure management platforms such as Wiz or Prisma Cloud. Manage cloud account and subscription onboarding, connectors, permissions, policies, rules, integrations, dashboards, and platform health across Azure, AWS, and other in-scope cloud services. Required Qualifications: Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering or related discipline 10 or more years of experience in cloud security engineering, security engineering, DevSecOps, cloud platform engineering, or a related technical security role. Hands-on experience securing and operating production environments in Microsoft Azure and/or Amazon Web Services; multi-cloud experience is preferred. Hands-on experience with a CNAPP, CSPM, or cloud exposure management platform such as Wiz or Prisma Cloud, including policy configuration, findings analysis, integrations, reporting, and remediation workflows. Demonstrated experience prioritizing cloud risk using business context, exploitability, attack paths, asset criticality, identity exposure, network exposure, and data sensitivity. Strong scripting and automation skills using Python and/or PowerShell, REST APIs, JSON/YAML, source control, and CI/CD practices. Experience with Infrastructure as Code and policy-as-code technologies such as Terraform, Bicep, ARM templates, CloudFormation, Open Policy Agent, or equivalent controls. Solid understanding of cloud identity and access management, non-human identities, least privilege, network security, workload and container security, secrets management, encryption, logging, monitoring, and incident response. Ability to troubleshoot complex technical issues, communicate risk clearly, and drive remediation across teams without relying solely on direct authority. Ability to produce clear technical documentation, operating metrics, and leadership-ready status or risk updates. Preferred Experience Experience designing or operating a formal CTEM program or exposure management operating model. Experience integrating cloud security platforms with ServiceNow, Azure DevOps, Jira, SIEM/SOAR platforms, messaging platforms, data pipelines, or reporting tools. Experience securing Kubernetes, containers, serverless services, CI/CD pipelines, software supply chains, and cloud-native application architectures. Familiarity with AI/ML security, including AI service architecture, model and data access, agent or workload identities, prompt and data-flow risks, AI security posture management, and governance of AI-enabled services. Working knowledge of cloud and security frameworks such as NIST CSF, NIST 800-53, CIS Benchmarks, CSA CCM, MITRE ATT&CK, OWASP, and relevant regulatory or audit requirements. Relevant certifications such as CCSP, CISSP, CCSK, Microsoft Azure Security Engineer, AWS Certified Security - Specialty, or vendor platform certifications.