Cloud Security Engineer
Workstreet Philippines
Computer and Network Security · 51-200 employees
About the role
The Cloud Security Engineer will design, implement, and maintain robust security controls across AWS, Azure, and GCP environments to ensure regulatory compliance. They will also perform architectural risk assessments, manage security tool suites, and automate security guardrails within CI/CD pipelines.
What they look for
Requirements
Candidates must have proven experience in multi-cloud security engineering, cloud architecture, and security automation using tools like Terraform. Strong communication skills and the ability to work a standard 8:00 AM–5:00 PM U.S. Eastern Time schedule are required.
Benefits
Full description
Get to know the Security Services Team
We are the team that turns complex security requirements and compliance frameworks into infrastructure and services that actually work. Moving fast and taking true end-to-end ownership, our team spans three core functions: Cloud Security Engineering, where we design hardened AWS, Azure, and GCP environments, write Terraform baselines, and fix failing controls to meet frameworks like SOC 2, ISO 27001, CMMC, and FedRAMP; Penetration Testing, where we run disciplined offensive assessments across networks, apps, cloud, and AI/LLM systems to catch vulnerabilities before adversaries do; and Vulnerability Management, where we continuously prioritize, patch, and validate risk reduction across the client footprint. We do not hide behind process or just point out gaps. We step in, build solutions, and deliver real security posture improvements with minimal disruption.
What makes this team special isn't just our technical depth; it is how we back each other up. Our strongest engineers and assessors are the ones building reusable modules, writing custom tools, jumping into channels to unblock teammates, and mentoring without being asked. From early-stage startups to regulated enterprises, you will work directly with clients, take on real ownership early, and be surrounded by people who want to see you get good. If you enjoy solving tough security problems and want to be part of a team that is scrappy enough to move fast but seasoned enough to get it right, you will be in good company here.
The Opportunity
We are seeking a Cloud Security Engineer to help clients design, implement, and maintain security controls that meet compliance and security requirements. This role is ideal for professionals with hands-on experience in cloud security engineering, compliance frameworks, and cloud-based security best practices. You’ll work closely with clients and internal teams to strengthen their cloud security posture and automate security operations across AWS, GCP, and Azure environments.
What you'll do
- Deploy and maintain robust cloud security controls across AWS, GCP, and Azure to eliminate system misconfigurations and preserve continuous regulatory alignment.
- Execute deep-dive architectural risk assessments to surface infrastructure vulnerabilities, evaluate asset exposures, and engineer targeted technical remediation blueprints.
- Configure and manage enterprise security tool suites, including SIEM platforms, log analytics engines, identity management layers, IDS/IPS tools, and vulnerability scanning infrastructure.
- Own the client relationship lifecycle as the primary trusted advisor for an assigned portfolio, establishing project milestones, managing communication pathways, and handling technical escalations with calm professionalism.
- Programmatically enforce security controls by engineering automated, repeatable Infrastructure as Code (IaC) deployment playbooks and configuration scripts.
- Embed continuous security guardrails into CI/CD pipelines and development workflows to intercept infrastructure vulnerabilities early in the lifecycle.
- Investigate and contain cloud-related security incidents, rapidly executing technical diagnostics and remediation loops to restore platform integrity.
- Support continuous audit readiness within GRC frameworks by systematically gathering, testing, and validating multi-cloud configuration evidence.
Who you are
- Proven multi-cloud security engineer - Command direct operational ownership securing infrastructure across AWS, GCP, and Azure environments by implementing strict security baselines and reducing structural risk.
- Cloud security architecture expert - Mastered advanced identity and access management (IAM) strategies, cloud network zoning, data encryption standards, and systemic risk mitigation workflows.
- Advanced security automation developer - Highly proficient utilizing Infrastructure as Code (IaC) tools and logic, specifically building automated guardrails through Terraform, AWS CloudFormation, Python, or Bash.
- GRC infrastructure strategist - Aligned technical, cloud-native configurations directly against global regulatory compliance and audit frameworks, including SOC 2, ISO 27001, GDPR, and HIPAA.
- Surgical technical problem-solver - Apply rigorous analytical diagnostics to independently isolate cloud infrastructure vulnerabilities, resolve failing controls, and execute zero-disruption remediation.
- High-impact client consultant - Confidently orchestrate multiple client portfolios concurrently, partnering directly with US-based technology founders, DevOps leads, and executive teams to scale cloud security maturity.
- Elite technical communicator - Deliver flawless written and verbal English communication that effortlessly translates dense cloud vulnerabilities and risk vectors into actionable business value.
What help you succeed
- Deep data and monitoring tooling execution - Advanced manipulation of enterprise logging platforms, vulnerability management engines, threat hunting feeds, and network traffic analyzers.
- Validated cloud security credentials - Hold active technical certifications such as AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, CISSP, CISM, or CISA.
- Container and DevSecOps engineering - Practical success auditing and isolating security boundaries within microservice architectures, Docker instances, and Kubernetes clusters.
- Zero Trust deployment models - Direct execution of identity-centric security policies, network micro-segmentation, and context-aware access structures.
- Commercial tenure in fast-growth environments - Documented history scaling infrastructure configurations within hyper-growth tech startups or elite managed security service providers (MSSP).
What we offer
- Career Development: Clear path with mentorship and training opportunities.
- Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- Growth Opportunity: Early-stage company with significant room for career advancement.
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What you'll need to thrive
- Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
- A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
- Commitment to working a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time (ET) to effectively collaborate with team members, stakeholders, and cross-functional partners while ensuring timely communication and support.
- Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process
- Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
- Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
- Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
- Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
Workstreet Is An Equal Opportunity Employer
As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.
Similar roles
-
Security Engineer I
URM Stores Inc Spokane, Washington, United States · $79K–$96K/yr
-
Cybersecurity Program Manager
Gunnison Consulting Group Alexandria, Virginia, United States · $180K–$210K/yr
-
Cybersecurity Operations Lead
Gunnison Consulting Group Alexandria, Virginia, United States · $160K–$170K/yr
-
Security Engineer
Sundt Tempe, Arizona, United States
-
Director, Cybersecurity Practice
Collective Insights Careers Atlanta, Georgia, United States
-
Senior Director, Cybersecurity & Enterprise Infrastructure
Rimkus Chapel Hill, North Carolina, United States