FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in designing and implementing secure cloud infrastructure, with a strong focus on AWS security, cloud-native architecture, and DevSecOps practices. Proficient in automating security controls and monitoring within CI/CD pipelines while ensuring compliance with industry standards such as HIPAA and HITRUST.
Highest-signal resume keywords
AWS SecurityCloud-Native ArchitectureDevSecOpsInfrastructure-As-CodeCISSP
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security EngineeringCloud Security Posture ManagementPythonTerraformKubernetesDockerCSPM ToolsSIEMDLP ImplementationsVulnerability Remediation
Soft Skills
Excellent Communication Skills
Tools & Technologies
Google WorkspaceSlackConfluenceJiraZoom
Certifications & Qualifications
CISSPCNAPP
Industry Keywords
Digital HealthcareHIPAA ComplianceHITRUST ComplianceSOC Compliance
Tech Stack
Tools & technologiesAWSCloudDockerKubernetesPythonTerraform
About the role
Key responsibilities & impact- Lead the design, build, and security of cloud infrastructure
- Establish cloud architecture security standards
- Implement infrastructure-as-code security controls across cloud environments
- Maintain cloud security posture and execute core cloud security functions
- Architect secure, scalable cloud systems
- Collaborate with engineering and security leadership to design, build, and maintain secure cloud architecture
- Monitor and analyze cloud-specific threat landscapes and mitigate public-cloud misconfiguration risks
- Monitor and triage CSPM and cloud-native security alerts and conduct forensic investigations
- Partner with DevOps to automate security monitoring and alerting in CI/CD pipelines using IaC
- Integrate automated vulnerability scanning and security testing into the development lifecycle
- Coordinate cross-functional vulnerability remediation
- Design and audit cloud-native security controls for HIPAA, HITRUST, and SOC compliance
- Monitor and evaluate system and application security configurations
- Participate in containment, eradication, and recovery throughout the security incident response lifecycle
- Consult with software engineering teams on secure cloud architecture and application features
Requirements
What you’ll need- 5 to 8+ years of dedicated Security Engineering experience focused on AWS security, cloud-native architecture, and DevSecOps
- Experience building and architecting security infrastructure from the ground up, serving as primary architect and functional owner of the security domain
- Experience implementing cloud-native security tooling, such as CSPM and CWPP, and embedding automated security controls into CI/CD deployment pipelines
- Proficiency in Python, Terraform, Kubernetes, and Docker/containerization strategies
- Strong understanding of SaaS risk management and hardening processes
- Experience with DLP implementations and management
- Previous experience in a startup environment
- CISSP, CNAPP, or related certifications
- Experience developing or implementing new tooling using the latest resources or technologies
- Experience implementing or using CSPM tools such as Wiz, Orca, or AWS security tools suite
- Experience implementing and tuning SIEM and event management tools
- Experience in the digital healthcare industry
- Excellent verbal and written communication skills
- Prior experience with Google Workspace, Slack, Confluence/Jira, and Zoom is a plus
Benefits
Comp & perks- 10% target annual bonus
- Paid benefits
- Employee perks
- Access to Cleerly offices in Denver, Colorado; New York, New York; Dallas, Texas; and Lisbon, Portugal
- Remote work for most teams
- Travel for some team meetings and cross-functional projects, typically once per month or once per quarter
