More jobs:
Principal AWS Cloud Security Engineer
Job in
Walnut Creek, Contra Costa County, California, 94598, USA
Listed on 2026-06-23
Listing for:
I.T. Solutions, Inc.
Full Time
position Listed on 2026-06-23
Job specializations:
-
Software Development
AWS, DevOps, Cloud Engineer - Software
Job Description & How to Apply Below
Title:
Principal Cloud Security Engineer (AWS)
Location:
Reno, NV OR Walnut Creek, CA (must be on site 4 days/week)
Reports to:
Enterprise Security Manager
Must be US Citizen
About the role
- Client is hiring a Principal Cloud Security Engineer to make security an engineering output rather than a review checkpoint. You'll build the Terraform modules, AWS account patterns, policy-as-code, and CI/CD controls that engineering teams use to ship safely so the security baseline rises through code, not through tickets.
- This is a software engineering role inside our security team. We want someone whose instinct, when handed a security problem, is to design and ship a durable technical control, not to write a policy document or stand up another tool. Engineers who came up through software, platform, or SRE work and then went deep on security are exactly who we're looking for.
- Design AWS multi-account, organization, and guardrail patterns that make the secure path the easy one.
- Build and own a library of Terraform modules and policy-as-code that engineering teams adopt across the company.
- Implement preventive controls, including SCPs, deployment-time policy validation, and drift detection, for high-risk cloud actions, in the code paths where work already happens.
- Build logging integrity and tamper resistance into Cloud Trail, telemetry pipelines, and core monitoring; define what good cloud telemetry looks like for downstream detection.
- Partner with Platform and Architecture on identity, networking, EKS, and serverless patterns. Work with Security Operations to turn cloud signals into useful detections.
- Make architecture decisions visible through design docs, pull requests, and reference implementations others can read and copy.
- 8+ years across software engineering, platform engineering, SRE, or cloud security, with substantial hands‑on AWS work in multi‑account environments.
- Production-quality code in at least one of Go, Python, Type Script, C#, or Java. You think about security problems as software problems.
- Deep Terraform: reusable modules, tested patterns, and an opinion about how IaC should be structured at scale.
- Hands‑on experience with policy-as-code, preventive guardrails, and securing EKS and serverless workloads.
- Experience building detective and preventive controls for cloud control planes and logging integrity.
- Comfort working through pull requests and design reviews with engineering teams, not only with security teams.
- SIEM/XDR integration experience; familiarity with Palo Alto or Prisma.
- CI/CD security patterns and developer‑enablement work.
- Securing AI/GenAI services, internal copilots, or agentic workflows in cloud environments.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×