Security Engineer, Infrastructure
Applied Systems, Inc. · United States · $80K–$120K/yr
Software Development · 1,001-5,000 employees
About the role
Design and operate security controls across cloud platforms and edge infrastructure, including Cloudflare WAF and SASE solutions. Collaborate with infrastructure and incident response teams to implement zero-trust network access and cloud security posture management.
What they look for
Requirements
Requires at least 3 years of experience in cloud security engineering, DevSecOps, or site-reliability engineering. Candidates must possess advanced knowledge of major cloud platforms and proficiency in infrastructure-as-code and scripting languages.
Benefits
Full description
Job Description
Amazing Career Moments Happen Here Transforming the insurance industry is ambitious, we know. That’s why at Applied, we’re building a team that shows up every day ready to learn, willing to try new things, and driven to deliver innovative software and services that make us indispensable to our customers – all within a culture built on values that make us indispensable to each other too. With 40+ years of experience in the insurtech game, we’re not just redefining what’s achievable, we’re creating a place where amazing career moments are made possible.
Position Overview
We're seeking an experienced Infrastructure Security Engineer to design and operate security controls across our cloud platforms and edge infrastructure. You'll work at the intersection of cloud security and modern network access, implementing Cloudflare WAF and SASE solutions, zero-trust network access controls, and cloud security posture management across AWS, GCP, and Azure. This role is ideal for an engineer who enjoys the technical depth of cloud infrastructure security, wants to move beyond traditional perimeter security into edge and identity-based models, and is comfortable with infrastructure-as-code and automation. You'll own specific security initiatives, collaborate with infrastructure and incident response teams, and have the opportunity to mentor junior engineers as you grow.
What You’ll Do
- Design, implement, and maintain cloud security solutions across AWS, GCP, and Azure environments
- Lead the design and deployment of Cloudflare WAF and related edge security controls across production infrastructure
- Implement and optimize SASE (Secure Access Service Edge) architecture and controls to replace traditional perimeter security
- Develop and maintain cloud access policies and zero-trust network access controls
- Conduct security reviews and threat modeling of cloud infrastructure and data flows
- Implement cloud security posture management (CSPM) and identify/remediate misconfigurations
- Design, implement, and maintain infrastructure-as-code security configurations
- Contribute to the creation and maintenance of runbooks and playbooks for cloud security incident response
- Assist with proof-of-concept builds for new cloud security and SASE solutions
- Contribute to detection rule tuning and security monitoring in cloud environments
- Participate in the Security Engineering Team on-call rotation
We’re looking for someone who:
- Has the ability to work from an Applied Systems office or 100% remotely
- Your experience should include some or all of the following:
- Minimum of 3 years' experience in cloud security engineering, DevSecOps, or site-reliability engineering
- Advanced knowledge of at least two major cloud platforms (AWS, GCP, Azure)
- Hands-on experience implementing and optimizing WAF solutions, with Cloudflare strongly preferred
- Demonstrated experience designing or implementing SASE/zero-trust network access solutions
- Working knowledge of Privileged Access Management (PAM) solutions and principles (BeyondTrust or similar)
- Familiarity with secrets management and privileged credential storage (Keeper or similar)
- Advanced knowledge of Linux and/or Windows operating systems
- Experience with one or more scripting languages (PowerShell, Python, Bash, Go)
- Experience with infrastructure-as-code technologies (Terraform, Ansible, Pulumi)
- Working knowledge of traditional networking and software-defined networking (SDN) concepts
- Strong understanding of cloud networking models (VPC, security groups, network policies)
- Knowledge of encryption in transit and at rest, certificate management
- Experience with cloud logging, monitoring, and alerting (CloudWatch, Stackdriver, Azure Monitor, etc.)
- Demonstrated ability to work with systems at scale
- Excellent written and verbal communication skillsStrong problem-solving abilities and attention to detail
- We know that talent comes from all backgrounds and experience levels. We encourage military members and their spouses as well as candidates without a degree or a background in tech to apply!
Location
Candidate will need to reside in North America, working arrangement will be remote.
When You Join Team Applied, You Can Expect:
A culture that values who you are and recognizes that you aren’t just an employee; you are a teammate, and you matter. We thrive on the benefits of our different experiences and celebrate the uniqueness our teammates bring to work with them every day.
We flex our time together, collaborating remotely and in-person to empower our teams to work in the ways that work best for them.
A comprehensive benefits and compensation package that centers our teammates and helps them to bring their best to work every day:
Medical, Dental, and Vision Coverage
Holiday and Vacation Time
Health & Wellness Days
A Bonus Day for Your Birthday
Learn more about the people behind our products at https://www1.appliedsystems.com/en-us/about-us/jobs/
Our targeted starting base salary in the United States for this position ranges from $80,000 - $120,000. To determine a new team member’s starting pay, we consider a variety of factors, including someone’s depth, breadth, and variety of experience, skills, and responsibilities. Depending on the role, team members may also be eligible to participate in additional compensation plans such as bonus and commission.
Your Security Matters: Our candidates’ personal information and online safety are top of mind for us. At Applied, we proactively protect your personal information and only communicate with candidates via a secure @appliedsystems.com email or through our official careers portal. Recruiters will never request payments, ask for financial account information or sensitive information like social security numbers.
EEO Statement
Applied Systems is proud to be an Equal Employment Opportunity Employer. Diversity and Inclusion is a business imperative and is a part of building our brand and reputation. At Applied, we don’t discriminate, and we are committed to recruit, develop, retain, and promote regardless of race, religion, color, national origin, sexual orientation, gender identity, disability, age, veteran status, and other protected status as required by applicable law.
#LI-Remote