×
Register Here to Apply for Jobs or Post Jobs. X

Cloud Security Engineer

Job in Coos Bay, Coos County, Oregon, 97458, USA
Listing for: Included Health
Full Time position
Listed on 2025-12-27
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Cloud Computing
Job Description & How to Apply Below
Position: Staff Cloud Security Engineer

Overview

The Staff Cloud Security Engineer is a critical, hands-on technical role responsible for engineering, implementing, and automating robust security controls within our cloud environments (AWS primarily, with GCP considerations). This role is pivotal in maturing our cloud security posture, securing Included Health's product infrastructure, and directly contributing to the prevention of unauthorized PHI exfiltration. You will help design and develop advanced security solutions, often through code (primarily Python and Go) and automation (Terraform), to address challenges in access control, development environment security, and infrastructure hardening.

This role requires deep technical expertise in cloud security, strong software development skills for building security tools and automation, and a proactive approach to risk mitigation. You will be a key technical peer to our infrastructure software and engineering teams, driving a culture of security by design and helping to implement solutions that reduce HIPAA incidents. This is a remote role reporting to the Chief Information Security Officer.

Responsibilities
  • Design, develop, and implement a comprehensive authorization framework for cloud resources, addressing user roles, resource-specific restrictions, task-based access, and granular engineering access
  • Lead the technical implementation of Just-In-Time (JIT) access control systems for production environments (systems, secrets, data) to minimize standing privileges for engineering and platform teams
  • Collaborate with engineering to integrate data classification (e.g., safe-harbor annotations) with access control mechanisms, ensuring that data sensitivity directly informs access decisions
  • Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations, vulnerability management, compliance checks, and incident response
  • Write clean, maintainable, and testable code (primarily Python and Go; familiarity with Ruby is a plus) for security automation, building custom security integrations, and developing security-focused tools
  • Implement and champion Infrastructure as Code (IaC) principles, specifically using Terraform, for programmatic definition, enforcement, and auditing of security configurations
  • Contribute to the design and implementation of centralized security controls, such as an engineering-owned Web Application Firewall (WAF), to manage rate limiting, IP blocking, input validation, and request filtering
  • Partner with engineering teams to establish and implement secure practices for managing the development toolchain (code generation utilities, linters, browser extensions, CLI tools, IDE plugins) to mitigate supply chain risks
  • Design and help implement a secure, "blessed" mechanism for webhook testing in local development environments, blocking unauthorized tunneling tools
  • Define, implement, and enforce container security hardening standards (e.g., least privilege, no unnecessary utilities, limited internet access) in collaboration with engineering teams
  • Drive the remediation of legacy cloud environments, particularly in GCP, by inventorying, assessing, and improving security controls
  • Design and implement solutions for granular data access control in cloud environments, particularly addressing compliance requirements for handling sensitive data
  • Collaborate closely with infrastructure software, engineering, Dev Ops, and product teams to co-design and integrate robust, automated security controls into systems, architectures, and CI/CD pipelines
  • Act as a subject matter expert on cloud security (AWS, GCP), providing guidance, code reviews (Python, Go), and technical expertise on secure cloud adoption, secure software development, and access control best practices
  • Support organizational change management efforts related to new security controls and practices by providing technical rationale and assisting in the development of new workflows
  • Conduct security assessments, threat modeling, and contribute to incident response, developing automation for prevention and faster response
  • Develop and maintain comprehensive documentation for security architectures, controls, automation scripts, and incident response playbooks
Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field
  • 5+ years of experience in cloud security, with a strong emphasis on designing, developing (primarily in Python and Go), and implementing security solutions in AWS
  • Proven hands-on software development experience, particularly in Python and Go, for security automation, building security tools, and infrastructure management
  • Demonstrable experience designing and implementing robust authorization and access control frameworks (e.g., RBAC, ABAC, policy-as-code) and Just-In-Time (JIT) access solutions
  • Experience with Infrastructure as Code (IaC) with deep proficiency in writing and maintaining Terraform modules for security
  • Experience with containerization…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary