Senior Security Engineer - Cloud Security
PagerDuty · Atlanta
About this role
**PagerDuty — Senior Security Engineer (Cloud Security | Platform, Identity & Cryptography)** PagerDuty is seeking a **Senior Security Engineer** to join the **Cloud Security** team within **Security Engineering (CTO org)**. This is a preventive, platform-focused role owning security posture across a **multi-account AWS environment** and the **Kubernetes platforms** running on it—especially **identity & access management** and **cryptography (PKI and encryption)**. You’ll partner with **30+ engineering teams**, shipping **controls as code** without disrupting engineering (including across the **FedRAMP** footprint). *Note: This role requires **2 days/week in the Atlanta office**.* --- ## What you’ll do - Harden PagerDuty’s **AWS and Kubernetes** environments against **CIS Benchmarks**, **DISA STIGs**, and **FedRAMP Moderate** baselines across a multi-account, multi-org footprint—using evidence, config-remediation tooling, and KPIs for posture, identity, and encryption/PKI health. - Harden **EKS clusters** and the **Istio service mesh** against the **CIS Kubernetes Benchmark**, **DISA Kubernetes STIG**, and **NSA/CISA** hardening guidance. - Design and enforce **Kubernetes RBAC**, **least-privilege workload identity**, and **container supply-chain controls** (image provenance, admission control, runtime policy). - Own **PKI and encryption standards**: certificate lifecycle/management, **KMS-backed key management and rotation**, **TLS/mTLS** (including within Istio), and **encryption at rest/in transit**. - Design and roll out **Service Control Policy (SCP)** guardrails and **least-privilege IAM/PAM** across dozens of accounts and multiple orgs. - Use **AI/agentic tooling** to improve efficiency—posture triage, threat modeling, risk assessment, incident enrichment/investigation, compliance-evidence generation, and detection tuning. - Shape detection strategy for your domains (Kubernetes/Istio, identity, cryptography): author/tune detections in the SIEM, define “good” coverage, and perform threat hunting (container escape, lateral movement, anomalous mesh traffic, identity/credential abuse). - Participate in **on-call**: triage cloud and Kubernetes threat alerts and act as **Incident Lead** during incidents (containment, blast-radius/exposure analysis, post-incident review). - Automate security controls as code using **Terraform** and **Python** (including Kubernetes policy-as-code and tool integrations). - Partner with **AppSec** and **GRC** to align platform controls with secure-development needs and translate hardening work into audit/compliance evidence. --- ## Additional responsibilities - Mentor teammates on platform, identity, and cryptography security practices; contribute to roadmap and annual planning. At the senior end, help draft external/auditor-facing communications and represent the team in cross-team planning. --- ## Basic qualifications - **5+ years** as a Security Engineer in an **AWS-native, microservice SaaS** environment, focused on cloud infrastructure, container, and identity security. - Deep, hands-on expertise securing **Kubernetes/containerized environments** (EKS, RBAC, admission control, network policy, workload identity). - Container runtime and image security experience; **Istio** familiarity strongly preferred. - Strong, hands-on expertise in **PKI and cryptography** (certificate lifecycle/management, TLS/mTLS, key management/rotation via **AWS KMS or similar HSM/KMS**, encryption at rest/in transit).
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.