Unknown Company

Senior Engineer, Cloud Security

miami, fl • Posted 1 weeks ago
Onsite Full Time General

Senior Engineer, Cloud SecurityThe Senior Engineer, Cloud Security is responsible for strengthening and operating PayCargo's security controls across a modernizing platform that spans legacy systems, a multi-account AWS environment, Microsoft Entra ID, GitHub/ZenHub workflows, GitHub Actions pipelines, and a growing set of secure AI platform requirements. This is a senior, hands-on engineering role — not an entry-level or SOC-analyst position — focused on implementing and operating security controls, not only monitoring them.This is a hands-on individual contributor role on PayCargo's DevSecOps team. The Senior Engineer - Cloud Security continuously monitors the perimeter, hardens cloud and endpoint controls, runs access reviews, supports audits, and leads incident response, turning security obligations into repeatable operational controls rather than one-time checklist items.

The role requires strong judgment, strong follow-through, and the ability to reduce reactive fire drills while raising overall control maturity.The Senior Engineer, Cloud Security partners closely with DevOps, Engineering, Architecture, Product, Compliance, Support, and executive stakeholders to keep PayCargo's global payments platform secure, available, and audit-ready.This position has no direct reports.

The role leads indirectly by setting and enforcing security standards, guiding engineers and DevOps toward secure patterns, and reducing single points of failure across the security function.As the Senior Engineer, Cloud Security, you will:Monitor the perimeter, cloud, and endpoint environments for threats, misconfigurations, and anomalous activity across AWS and Microsoft Entra IDOperate and tune security tooling, including CrowdStrike, Microsoft Defender, and CloudWatch and SNS logging and alertingTriage security alerts, drive incident response, and lead root cause analysis with clear, durable follow-upMaintain and improve on-call and escalation workflows (e.g., PagerDuty) so security events are handled consistentlyRun periodic access reviews and enforce least privilege across AWS IAM and IAM Identity Center, Microsoft Entra ID, and SaaS platformsStrengthen RBAC/ABAC, MFA, and SSO, SAML2, and OAuth2/OIDC patterns across internal and customer-facing systemsReduce standing access and broad repository or local admin privileges in favor of bounded, auditable accessOperate the federated access model, including SAML-based assumed access to AWS (via CommonFate Granted) and GitHub OIDC for pipelines, so people and CI receive least-privilege, time-bound access without static credentialsOperate the PKI, including AWS Private CA and ACM, certificate issuance and rotation, CRLs, and mTLS trust stores on load balancersAdminister Entra ID groups and the Tailscale ACLs that gate network accessGovern dependency and supply-chain risk using Dependabot and approved-package practices, and keep secrets in AWS Secrets Manager and SSM Parameter StoreSupport SOC 1 Type 2, SOC 2, and PCI DSS obligations by owning the implementation of controls and the evidence behind themCoordinate penetration testing, remediation tracking, and verification of fixesProduce clean, repeatable audit evidence and reduce last-minute audit scramblesTranslate compliance requirements into operational controls engineers can follow without constant guidanceHelp enforce containment for AI and model usage, including stateless model access, whitelisted egress, and approved destinationsSupport tokenization and PII-protection patterns so sensitive data is not exposed to model providersReview AI-assisted workflows and applications for security boundaries, logging, and blast-radius reductionPartner with DevOps and Engineering to embed security into the Terraform and GitHub Actions pipelines, environments, and deployment pathsWork with Compliance on audits and frameworks (SOC, PCI, ISO 27001) and on auditor-facing reportingAdvise Product and Architecture on secure-by-design patterns and practical trade-offsImplement and operate the security controls, boundaries, and egress rules defined in the platform architecture owned by the Director of Cloud & AI Platform ArchitectureProvide clear status, escalate risks early, and document controls, runbooks, and decisionsRequired Qualifications:5+ years of hands-on security engineering, cloud security, or security operations experience preferredStrong working knowledge of AWS security and identity services, plus an enterprise identity provider such as Microsoft Entra ID or OktaHands-on experience with endpoint and threat tooling such as CrowdStrike and Microsoft DefenderPractical experience with SOC and/or PCI DSS controls, audits, and evidenceStrong understanding of IAM, RBAC/ABAC, MFA, SSO, SAML2, OAuth2/OIDC, JWT, including common failure modes, and least-privilege designHands-on experience with PKI and certificates, including a certificate authority such as AWS Private CA, TLS and mTLS, and certificate issuance, rotation, and revocationExperience with incident response, logging and alerting, and root cause analysisAbility to convert security and compliance requirements into repeatable operational controlsStrong communication and documentation skills, and the ability to influence without direct authorityExperience and Education:Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent practical experience5+ years of hands-on security engineering, cloud security, or security operations experience preferredDemonstrated experience operating production security controls in cloud environmentsExperience supporting SOC, PCI, or comparable audits and frameworksPayments, fintech, SaaS, or logistics experience is a plusPreferred Qualifications:Security certifications such as CISSP, CISM, CCSP, or equivalentExperience coordinating penetration testing and managing remediationFamiliarity with secure AI/LLM patterns, data tokenization, and egress controlExperience securing CI/CD pipelines (GitHub Actions), GitHub/ZenHub, and Terraform-based infrastructure-as-codeExperience with zero-trust network access such as Tailscale or Zscaler, and SSO brokers such as CommonFate GrantedExperience in payments, fintech, SaaS, or other regulated, high-volume environmentsFamiliarity with ISO 27001 and SaaS security posture managementYou Will Likely Succeed If:Have a winning attitudeAre naturally curious with an always-learning mentalityTreat security as an enabler, not only a gatekeeperLove to solve difficult problemsAre assertive, confident, but also humbleSpeak with clarity and listen with intentionAre disciplined with your processes, documentation, and follow-upCan own a problem end to end without constant directionTake ownership of both the security outcome and the business resultWhat Success Looks Like:Security controls are operational, monitored, and repeatable rather than reactiveAccess is least-privilege, reviewed, and auditable across cloud and SaaSAudits and penetration tests are supported with clean evidence and timely remediationIncidents are handled with clear response, root cause analysis, and durable fixesAI and platform initiatives ship with security boundaries built in from the startThe Senior Engineer - Cloud Security becomes a trusted owner of one or more critical security domains within 90 to 180 daysWhat We Offer:Our compensation package includes a competitive salary and bonus plan.We care about your wellbeing and personal life. We offer vacation, sick, personal time off policies, a generous 401K match, and strong healthcare benefits.Your success at PayCargo is determined by the impact that you are making, and how well you collaborate with the various teams that you interact with. Everyone at PayCargo

Senior Engineer, Cloud Security in miami at Unknown Company

This position is listed as full time and onsite.

Back to Job Search