Cloud Security Operations Engineer
Listed on 2026-08-20
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations, Security Management & Operations
At Cadence, we hire and develop leaders and innovators who want to make an impact on the world of technology.
Job Title:
Cloud Security Operations Engineer
Location:
San Jose, California
Reports to:
Senior Cloud Security Architect
We are seeking a skilled and passionate Cloud Security Operations Engineer to join our dynamic Information Security team. In this role, you will be responsible for designing, implementing, and maintaining robust security controls across our public cloud environments, including AWS, Azure, GCP, and IBM Cloud. As a hands‑on technical expert, you will play a crucial role in enhancing our cloud security posture, with a primary focus on data protection and incident management.
This position offers the opportunity to work in a collaborative environment, where you will contribute to the security and resilience of our cloud infrastructure.
Design and deploy secure reference architectures across multi-cloud environments.
Integrate security into Infrastructure-as-Code (IaC) using tools like Terraform, Cloud Formation, and ARM Templates.
Implement cloud-native security controls: VPCs, WAFs, DDoS, and endpoint protections.
Ensure data protection via encryption, KMS/HSM, and DLP policies.
- Identity and Access Management (IAM)
Design, implement, and audit IAM policies, roles, service accounts, and federation models using least-privilege principles.
Configure MFA, SSO, and PAM solutions for secure cloud access.
- Monitoring, Detection, and Response
Configure and maintain cloud-native security tools (e.g., AWS Security Hub, Microsoft Defender for Cloud, Google Security Command Center).
Integrate cloud logs with SIEM systems for threat detection.
Lead incident response efforts for cloud-related security events.
Continuously monitor cloud environments using CSPM, CNAPP, and cloud-native security tools to identify, prioritize, and remediate security misconfigurations and policy violations.
Track and manage cloud security findings through remediation workflows.
Partner with Cloud Platform, Infrastructure, and Application teams to coordinate remediation of identified security risks and vulnerabilities.
Conduct root cause analysis of recurring cloud security issues and recommend preventive controls and automation improvements.
- Cloud Data Loss Prevention (DLP) Management
DLP Alert Triage and Investigation:
Monitor, triage, and investigate all DLP alerts and events. Differentiate between policy violations, potential insider threats, and false positives, escalating confirmed incidents to the Incident Response team.Tool Optimization and Tuning:
Serve as the subject matter expert (SME) for Cloud DLP tools (e.g., Microsoft Purview, Google DLP, dedicated CASB solutions). Continuously tune policies and rulesets to minimize alert fatigue while maintaining high fidelity.Reporting and Compliance:
Generate regular reports on DLP effectiveness, policy violations, and risk trends for leadership and compliance/audit teams (e.g., SOC 2, HIPAA, GDPR).Data Classification Integration:
Collaborate with Governance, Risk, and Compliance (GRC) teams to ensure DLP policies align with the corporate data classification framework.- Automation and Dev Sec Ops
Develop automation scripts (Python, Power Shell, Bash) and serverless functions (AWS Lambda, Azure Functions, Google Cloud Run).
- Cloud Security Posture Management & Compliance
Continuously assess AWS, Azure, and GCP environments using CSPM platforms to identify misconfigurations, excessive permissions, exposed resources, compliance gaps, and other security risks.
Develop, maintain, and enforce cloud security baselines aligned with industry standards, regulatory requirements, and organizational security policies.
Perform periodic cloud security assessments and audits using CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and internal security standards.
Drive remediation of findings identified through CSPM monitoring, security assessments, audits, compliance reviews, and risk assessments.
Support internal and external audits by providing cloud security evidence, compliance reporting, and remediation status updates.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).