Skip to main content
Workstreet

Cloud Security Engineer

RemoteUTC-8…UTC-5
Published
Role
Security
Employment
Full-time
Company size
Startup
Salary not disclosed
Check eligibility

Open to UTC-8…UTC-5. Set where you work from to check your eligibility.

No BS summary

Cloud Security Engineer with hands-on experience in AWS, GCP, and Azure. Must be proficient in IaC (Terraform, CloudFormation), security automation, and GRC frameworks (SOC 2, ISO 27001, GDPR, HIPAA). Requires strong analytical and client consulting skills, with excellent English communication.

Core skills

AWSGCPAzure

Required skills

TerraformAWS CloudFormationPythonBashSOC 2ISO 27001GDPRHIPAASIEMidentity and access management (IAM)data encryptionInfrastructure as Code (IaC)CI/CDDockerKubernetes

Optional skills

AWS Certified Security – SpecialtyGCP Professional Cloud Security EngineerCISSPCISMCISAmicroservice architecturesZero Trust

Required languages

English

What you'll do

  • Deploy and maintain robust cloud security controls across AWS, GCP, and Azure to eliminate system misconfigurations and preserve continuous regulatory alignment.
  • Execute deep-dive architectural risk assessments to surface infrastructure vulnerabilities, evaluate asset exposures, and engineer targeted technical remediation blueprints.
  • Configure and manage enterprise security tool suites , including SIEM platforms, log analytics engines, identity management layers, IDS/IPS tools, and vulnerability scanning infrastructure.
  • Own the client relationship lifecycle as the primary trusted advisor for an assigned portfolio, establishing project milestones, managing communication pathways, and handling technical escalations with calm professionalism.
  • Programmatically enforce security controls by engineering automated, repeatable Infrastructure as Code (IaC) deployment playbooks and configuration scripts.
  • Embed continuous security guardrails into CI/CD pipelines and development workflows to intercept infrastructure vulnerabilities early in the lifecycle.
  • Investigate and contain cloud-related security incidents , rapidly executing technical diagnostics and remediation loops to restore platform integrity.
  • Support continuous audit readiness within GRC frameworks by systematically gathering, testing, and validating multi-cloud configuration evidence.

What they require

  • Proven multi-cloud security engineer - Command direct operational ownership securing infrastructure across AWS, GCP, and Azure environments by implementing strict security baselines and reducing structural risk.
  • Cloud security architecture expert - Mastered advanced identity and access management (IAM) strategies, cloud network zoning, data encryption standards, and systemic risk mitigation workflows.
  • Advanced security automation developer - Highly proficient utilizing Infrastructure as Code (IaC) tools and logic, specifically building automated guardrails through Terraform, AWS CloudFormation, Python, or Bash.
  • GRC infrastructure strategist - Aligned technical, cloud-native configurations directly against global regulatory compliance and audit frameworks, including SOC 2, ISO 27001, GDPR, and HIPAA.
  • Surgical technical problem-solver - Apply rigorous analytical diagnostics to independently isolate cloud infrastructure vulnerabilities, resolve failing controls, and execute zero-disruption remediation.
  • High-impact client consultant - Confidently orchestrate multiple client portfolios concurrently, partnering directly with US-based technology founders, DevOps leads, and executive teams to scale cloud security maturity.
  • Elite technical communicator - Deliver flawless written and verbal English communication that effortlessly translates dense cloud vulnerabilities and risk vectors into actionable business value.
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time (ET) to effectively collaborate with team members, stakeholders, and cross-functional partners while ensuring timely communication and support.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.

Benefits

  • Career Development : Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity : Early-stage company with significant room for career advancement.
  • Remote-First Culture : Flexibility to work from anywhere while collaborating with a global team.

At Workstreet , we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

GRCStartup
Salary not disclosed