FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Principal Security Engineer – Cloud and Infrastructure Security
One Identity. Own security architecture across Azure and AWS, including tenant, subscription and account design, network segmentation and traffic control, private connectivity, egress policy, and workload isolation .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in cloud security architecture across Azure and AWS, with a focus on securing AI workloads and implementing infrastructure-as-code practices. Proven ability to manage security policies, vulnerability assessments, and compliance controls in a distributed team environment.
Highest-signal resume keywords
Cloud Security ArchitectureInfrastructure As CodeContainer SecurityPolicy As CodeVulnerability Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security ArchitectureNetwork SegmentationEgress ControlAI Workload SecurityImage HardeningSecrets ManagementAudit ControlsCloud MigrationISO 27001 ComplianceSOC 2 Compliance
Soft Skills
JudgmentCommunication
Tools & Technologies
AzureAWSKubernetesOne IdentityAutomation Tools
Industry Keywords
FedRAMPIRAPCloud ArchitectureInfrastructure EngineeringSecurity Engineering
Tech Stack
Tools & technologiesAWSAzureCloudKubernetes
About the role
Key responsibilities & impact- Own security architecture across Azure and AWS, including tenant, subscription and account design, network segmentation and traffic control, private connectivity, egress policy, and workload isolation
- Assess One Identity products against real security requirements and communicate findings to product teams
- Bring engineering teams into architectural decisions early
- Improve infrastructure-as-code security through hardened modules, secure-by-default landing zones and account baselines
- Extend policy as code across the pipeline and platform to provide commit-time signals
- Own the hardened virtual machine and container image pipeline, including building, patch cadence, provenance, signing, and automation
- Secure the container orchestration layer and define reference architecture and secure defaults
- Set security architecture for AI workloads, including endpoint exposure, data boundaries and residency, agent and service-principal identity, secrets handling, and development-lifecycle guardrails
- Own infrastructure vulnerability and exposure management from discovery through prioritization, routing, remediation tracking, and verification
- Establish unified cloud posture and workload protection across Azure and AWS
- Define appropriate agentic security-engineering workflows, verification requirements, and automated pull-request remediation
- Build query-based control evidence for ISO 27001, SOC 2, IRAP, ACN, and PCI self-assessment
- Serve as the senior technical security voice for a lean, globally distributed team
Requirements
What you’ll need- Ten or more years in security engineering or infrastructure engineering, with substantial time in cloud architecture; equivalent depth counts
- Deep cloud security architecture experience across Azure and AWS, with real depth in one and working command of the other
- Hands-on work securing AI workloads or AI-enabled tooling within the last six months
- Something built that engineering teams adopted and kept using
- Seniority in infrastructure as code
- Network security fundamentals applied to cloud, including segmentation, private connectivity, egress control, and east-west traffic
- Container and Kubernetes security, image hardening, supply chain integrity, and secrets management
- Policy-as-code frameworks and understanding of enforcement in the lifecycle
- Controls personally designed and accountable for under an audit
- Judgment about which risks to carry and which to escalate
- Helpful: experience shipping software customers deploy themselves, FedRAMP or IRAP, and a carve-out or large-scale cloud migration
Benefits
Comp & perks- Health and wellness programs
- Career development and learning opportunities
- Equal employment opportunity and non-discrimination protections