3 дня назад
Staff Cloud Security Engineer (Cloud Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Cloud Security Engineer (Cloud Security): Securing Temporal's multi-cloud platform and core workflow infrastructure with an accent on cloud architecture, Kubernetes security, multi-tenant isolation, and gRPC protection. Focus on threat modeling durable distributed systems, hardening workflow execution and task queues, managing security posture across AWS, GCP, and Azure, and enabling engineering teams to ship securely.
Location: Remote-first; most roles are remote in-country, some are remote within a region, and a few teams have an in-office hub. Occasional travel may be required for onboarding and team gatherings.
Company
builds a cloud platform centered on durable workflow orchestration for distributed systems.
What you will do
- Integrate security principles into cloud infrastructure design and architecture across AWS, GCP, Azure, and other cloud environments.
- Secure the workflow engine, task queue architecture, and worker execution model, including attack surfaces in durable, stateful distributed systems.
- Conduct threat modeling and risk assessments across multi-cloud infrastructure, workflow execution, task queue integrity, and client-server trust boundaries.
- Protect the gRPC communication layer through mTLS certificate management, service mesh configuration, and API authentication.
- Manage cloud security posture with Wiz, including misconfiguration detection, compliance monitoring, and remediation.
- Translate cloud security standards such as the CSA Cloud Controls Matrix and CIS Benchmarks into internal policy, while participating in the on-call rotation.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent experience.
- 5+ years of experience in cloud security or a related role, with strong partnership across infrastructure and engineering teams.
- Experience with Kubernetes security posture management and auditing, including workload hardening, RBAC design, and admission control.
- Experience designing multi-tenant security architectures, including data-plane isolation, control-plane hardening, and cross-tenant data leakage prevention.
- Proficiency in Go and familiarity with Python, plus a strong understanding of application architecture and vulnerability identification across multiple programming languages.
- Experience with secrets management at scale, payload encryption patterns, gRPC security, mTLS, and service mesh architectures such as Istio and Envoy.
Nice to have
- Experience with , Cadence, or similar workflow orchestration platforms, including workflow history, replay semantics, and scheduling internals.
- FedRAMP, SOC 2 Type II, or ISO 27001 experience in cloud-native SaaS.
- Open-source automation experience, expertise in AppSec, CorpSec, or GRC, and security conference talks or published research.
Culture & Benefits
- Remote-first work model with occasional onboarding and team-gathering travel.
- Competitive benefits and equity.
- Flexible time off.
- Support for learning, wellness, and home-office setup.
- Some teams share an on-call rotation.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Twilio
6 дней назад
Staff Enterprise Security Engineer (AI Security)
155 520 - 194 400$
6 дней назад
Staff Engineering Manager (Cloud Security)
140 400 - 372 300$
5 дней назад
Staff Cloud Security Engineer
179 900 - 269 900$
7 дней назад
Security Engineer (Cloud Security)
7 дней назад
Lead DevSecOps Engineer (Cloud Security)
7 часов назад