Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
One Identity

Principal Security Engineer – Cloud and Infrastructure Security

One Identity

. Own security architecture across Azure and AWS, including tenant, subscription and account design, network segmentation and traffic control, private connectivity, egress policy, and workload isolation .

Posted 10/6/2026full-timeRemote • IndiaLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in cloud security architecture across Azure and AWS, with a focus on securing AI workloads and implementing infrastructure-as-code practices. Proven ability to manage security policies, vulnerability assessments, and compliance controls in a distributed team environment.

Highest-signal resume keywords
Cloud Security ArchitectureInfrastructure As CodeContainer SecurityPolicy As CodeVulnerability Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security ArchitectureNetwork SegmentationEgress ControlAI Workload SecurityImage HardeningSecrets ManagementAudit ControlsCloud MigrationISO 27001 ComplianceSOC 2 Compliance
Soft Skills
JudgmentCommunication
Tools & Technologies
AzureAWSKubernetesOne IdentityAutomation Tools
Industry Keywords
FedRAMPIRAPCloud ArchitectureInfrastructure EngineeringSecurity Engineering

Tech Stack

Tools & technologies
AWSAzureCloudKubernetes

About the role

Key responsibilities & impact
  • Own security architecture across Azure and AWS, including tenant, subscription and account design, network segmentation and traffic control, private connectivity, egress policy, and workload isolation
  • Assess One Identity products against real security requirements and communicate findings to product teams
  • Bring engineering teams into architectural decisions early
  • Improve infrastructure-as-code security through hardened modules, secure-by-default landing zones and account baselines
  • Extend policy as code across the pipeline and platform to provide commit-time signals
  • Own the hardened virtual machine and container image pipeline, including building, patch cadence, provenance, signing, and automation
  • Secure the container orchestration layer and define reference architecture and secure defaults
  • Set security architecture for AI workloads, including endpoint exposure, data boundaries and residency, agent and service-principal identity, secrets handling, and development-lifecycle guardrails
  • Own infrastructure vulnerability and exposure management from discovery through prioritization, routing, remediation tracking, and verification
  • Establish unified cloud posture and workload protection across Azure and AWS
  • Define appropriate agentic security-engineering workflows, verification requirements, and automated pull-request remediation
  • Build query-based control evidence for ISO 27001, SOC 2, IRAP, ACN, and PCI self-assessment
  • Serve as the senior technical security voice for a lean, globally distributed team

Requirements

What you’ll need
  • Ten or more years in security engineering or infrastructure engineering, with substantial time in cloud architecture; equivalent depth counts
  • Deep cloud security architecture experience across Azure and AWS, with real depth in one and working command of the other
  • Hands-on work securing AI workloads or AI-enabled tooling within the last six months
  • Something built that engineering teams adopted and kept using
  • Seniority in infrastructure as code
  • Network security fundamentals applied to cloud, including segmentation, private connectivity, egress control, and east-west traffic
  • Container and Kubernetes security, image hardening, supply chain integrity, and secrets management
  • Policy-as-code frameworks and understanding of enforcement in the lifecycle
  • Controls personally designed and accountable for under an audit
  • Judgment about which risks to carry and which to escalate
  • Helpful: experience shipping software customers deploy themselves, FedRAMP or IRAP, and a carve-out or large-scale cloud migration

Benefits

Comp & perks
  • Health and wellness programs
  • Career development and learning opportunities
  • Equal employment opportunity and non-discrimination protections