About this role
Lead design, implementation, and governance of secure multi-cloud cloud environments and IaC at RISCPoint. Own security architecture decisions and ensure regulatory alignment across FedRAMP, SOC 2, ISO 27001, and HIPAA while collaborating with compliance teams.
Key Responsibilities
- CI/CD pipeline ownership: design, implement, and maintain automated security gates. Automation-first engineering: replace manual processes with reliable automation. Secure IaC development: build and maintain Terraform modules encoding compliance requirements. Security-by-design: own security architecture decisions across cloud deployments (IAM, networking, secrets management, logging, encryption). Client collaboration: translate regulatory and security requirements into executable infrastructure for clients and communicate decisions clearly.
Technical Overview
Stacks include Terraform; cloud providers AWS, Azure, GCP; security tooling including CSPM (Prisma Cloud, Wiz, Lacework, AWS Security Hub), SAST/DAST tools; container security with Kubernetes; scripting in Python/Bash; Linux with DISA STIG; focus on IAM, encryption, secrets management, and logging/monitoring.
Ideal Candidate
The ideal candidate is a senior cloud security engineer with 3+ years in cloud infrastructure or DevSecOps, strong Terraform experience, and multi-cloud expertise (AWS/Azure/GCP). They excel at translating security requirements into secure cloud architectures and have hands-on experience with CSPM tools and regulatory frameworks.
Must-Have Skills
3+ years of professional experience in cloud infrastructure or DevSecOps1+ year of hands-on experience with TerraformStrong expertise in cloud security including IAMnetworkingsecrets managementencryptionand monitoringExperience with observability platforms (Datadogetc.)Solid understanding of compliance requirements (FedRAMPFISMACMMC Level 2SOC 2ISO 27001HIPAA)Experience with SAST/DAST tooling (SonarQubeSnykBurp SuiteTenable/Nessusetc.)Experience with containerizationKubernetesand secure hardeningFamiliarity with cloud governance frameworks and CSPM tools (Prisma CloudWizLaceworkAWS Security HubAWS Inspector)Scripting in Python or BashExperience configuring Linux operating systems (DISA STIG)Intermediate or higher cloud certifications; AWS Solutions Architect Associate required
Nice-to-Have Skills
AWS Solutions Architect ProfessionalAWS Security SpecialtyGCP and Azure equivalents (preferred)Advanced degree (MSc/PhD) in CS/AI/MLCSPM tool certifications (Prisma CloudWizLacework)
Tools & Platforms
TerraformGitHub ActionsGitLab CIJenkinsDatadogKubernetesAWS Security HubAWS InspectorPrisma CloudWizLaceworkSonarQubeSnykBurp SuiteTenableNessus
Required Skills
TerraformAmazon Web ServicesAWSGoogle Cloud PlatformGCPMicrosoft AzureAzureKubernetesDatadogSonarQubeSnykBurp SuiteTenableNessusFedRAMPSOC 2ISO 27001HIPAAIAMIdentity and Access ManagementDISA STIGInfrastructure as CodeCI/CDGitHub ActionsGitLab CIJenkinsPythonBash
Hard Skills
TerraformAmazon Web ServicesAWSGoogle Cloud PlatformGCPMicrosoft AzureAzureIAMIdentity and Access ManagementNetworkingSecrets managementEncryptionLoggingMonitoringDatadogSonarQubeSnykBurp SuiteTenableNessusFedRAMPSOC 2ISO 27001HIPAADISA STIGKubernetesDockerPrisma CloudWizLaceworkAWS Security HubAWS InspectorPythonBashLinuxInfrastructure as CodePolicy-as-code
Soft Skills
Excellent communication skillsAbility to translate security requirements into actionable engineering tasksCollaborative and client-facingProblem-solvingTechnical leadership
Certifications
Required
AWS Solutions Architect Associate
Preferred
AWS Certified Solutions Architect – ProfessionalAWS Certified Security – SpecialtyGoogle Cloud Certified – Professional Cloud ArchitectMicrosoft Certified: Azure Solutions Architect Expert
Keywords for Your Resume
cloud security engineerTerraformAmazon Web ServicesAWSGoogle Cloud PlatformGCPMicrosoft AzureAzureKubernetesDatadogSonarQubeSnykBurp SuiteTenableNessusFedRAMPSOC 2ISO 27001HIPAAIAMIdentity and Access ManagementDISA STIGInfrastructure as CodeTerraform modulesPolicy-as-codeSAST
Deal Breakers
Lack of Terraform experience, Less than 3 years cloud/DevSecOps experience, No AWS Solutions Architect Associate, Lack of Kubernetes or container security experience
Get matched to jobs like this
Luna finds roles that fit your skills and career goals — no endless scrolling required.
Create a Free Profile