Cloud Support Engineer - Security
Listed on 2026-05-30
-
IT/Tech
Cybersecurity, Systems Engineer
NOTE TO APPLICANTS
Individual(s) must be legally authorized to work in the United States without the need for immigration support or sponsorship from Milliman now or in the future.
Position SummaryThe Cloud Support Engineer – Security is responsible for the day‑to‑day security posture of cloud platforms and services, with a focus on AWS and Azure and supporting platforms such as M365 and Databricks. This role partners with engineering and operations teams to design secure cloud architectures, implement preventative and detective controls, monitor for threats, respond to incidents, and continuously improve compliance and governance across cloud environments.
Responsibilities- Secure Architecture & Design Reviews:
Provide security guidance for cloud architectures and changes (network segmentation, private connectivity, encryption patterns, key management), and review designs for risk and alignment to standards. - Identity & Access Management (IAM):
Implement and maintain least‑privilege access using AWS IAM/Organizations and Azure Entra /RBAC, including privileged access workflows, role design, service principals, and periodic access reviews. - Security Monitoring & Detection Engineering:
Enable and tune cloud‑native security signals (e.g., Cloud Trail/Config/Guard Duty, Azure Activity Logs/Defender for Cloud/Sentinel) and ensure centralized logging, alerting, and actionable runbooks. - Vulnerability & Configuration Management:
Drive patching and vulnerability remediation for cloud workloads and platform services; enforce secure configuration baselines and continuously assess drift using CSPM/configuration tools. - Security Automation & Dev Sec Ops :
Build guardrails and automate security controls with Infrastructure as Code (e.g., Terraform) and scripting (Python/Bash/Power Shell), including policy‑as‑code, CI/CD checks, and standardized hardened templates. - Compliance, Risk & Governance:
Maintain cloud security standards, support audits (e.g., HITRUST), evidence collection, risk assessments, and exception management; translate control requirements into actionable technical controls. - Stakeholder Partnership:
Collaborate with cloud/platform teams and application owners to prioritize security work, provide guidance, and deliver secure‑by‑default patterns without blocking delivery.
- Cloud Certification (Azure or AWS).
- Minimum 5 years of experience in cloud security, cloud engineering with a primary security focus, or security operations supporting public cloud environments.
- Minimum 3 years of hands‑on security experience in AWS and Azure, including implementing IAM, network security controls, logging/monitoring, and policy enforcement; relevant cloud certifications required (AWS and/or Azure).
- Previous experience operating and improving security controls such as CSPM, vulnerability management, SIEM/SOAR, EDR, and incident response processes.
- Hands‑on scripting/automation experience (Python, Bash, and/or Power Shell) and Infrastructure as Code concepts to automate security checks and guardrails.
- Excellent communication skills (verbal and written), with the ability to translate security risk into clear technical and business recommendations.
- Experience with HITRUST and/or other regulated environments (e.g., SOC 2, ISO 27001), including audit support and evidence collection.
- Experience securing Databricks and data platforms (workspace access controls, secret scopes, logging, network controls).
- Infrastructure as Code (IaC) experience, especially Terraform, including policy‑as‑code/guardrails (e.g., Sentinel/OPA) and standardized secure modules.
- Container/Kubernetes security experience (image scanning, admission controls, runtime protections, and cluster hardening).
This is a remote role. This job posting is expected to close on June 8th, 2026.
CompensationThe overall salary range for this role is $104,900 – $199,065. For candidates residing in Alaska, California, Connecticut, Illinois, Maryland, Massachusetts, New Jersey, New York City, Newark, San Jose, San Francisco, Pennsylvania, Virginia, Washington, or the District of Columbia the salary range is…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).