CronJobs

security jobs

Senior Cybersecurity Engineer

Buspatrol · TX - Austin

hybridsenior$130,000–$150,000Posted Sep 30, 2026AWSIAMTerraformAWS CDKKMSSecrets ManagerGitHub ActionsOPA

Apply on the employer site

About this role

## Senior Cybersecurity Engineer ### Job Overview BusPatrol is transforming student transportation safety through AI-enabled, cloud-connected platforms and real-time operational systems. We’re seeking a **Senior Cybersecurity Engineer** to make our platform **secure by default**, **resilient**, and **easier for engineering teams to operate safely**. This is a **hands-on platform and cloud security engineering** role focused on securing the platform layer (not application security or general SRE). You’ll partner with DevOps, application engineering, architecture, MLOps, IT, and Cyber Security to turn security requirements into reusable controls and paved-road patterns. **Location:** Austin, TX --- ### Key Responsibilities - Design, implement, and continuously improve security controls across BusPatrol’s **AWS multi-account environments**. - Establish **least-privilege identity patterns** using **AWS IAM**, IAM Identity Center, **Entra ID**, permission sets, groups, cross-account roles, service roles, and time-bound elevated access. - Build and maintain secure, reusable **Terraform modules** and **AWS CDK constructs** for platform services, security controls, logging, encryption, networking, and account/environment guardrails. - Evolve **AWS Organizations**, **Control Tower**, **service control policies (SCPs)**, account boundaries, and shared-services patterns to reduce blast radius and improve governance. - Secure cloud networking with practical controls for **VPCs**, routing, security groups, network ACLs, **WAF**, private connectivity, site-to-site VPNs, **Direct Connect**, and segmentation strategies. - Implement secrets-management and encryption patterns using **AWS KMS**, Secrets Manager, Parameter Store, **TLS**, and automated credential rotation. - Integrate security checks into **GitHub Actions** and delivery workflows (infrastructure validation, dependency/vulnerability scanning, container/image security, **SBOMs**, signing, and policy enforcement). - Develop **policy-as-code** and preventive guardrails using tools such as AWS Config, SCPs, CloudFormation Guard, OPA, Conftest, Checkov, tfsec, or equivalents. - Partner with engineering teams to define **secure golden paths**, platform templates, and documented patterns that make safe implementation the easiest implementation. - Operate and improve cloud security telemetry and findings across **GuardDuty**, **Security Hub**, **CloudTrail**, AWS Config, CloudWatch, and Datadog. - Triage, prioritize, and remediate platform security findings from **CNAPP/CSPM**, vulnerability management, penetration testing, and internal assessment tools (e.g., Wiz). - Support incident response, containment, root-cause analysis, and post-incident improvements for cloud, infrastructure, identity, and platform security events. - Produce concise architecture decisions, threat-informed control designs, runbooks, evidence, and operational documentation. - Collaborate with Cyber Security and GRC on **SOC 2**, **ISO 27001**, **CIS**, **NIST**, customer assurance, and audit readiness—without turning compliance into a manual exercise. - Mentor engineers through design reviews, infrastructure PRs, office hours, and practical security enablement. - Contribute to secure AI-enabled engineering and platform workflows by protecting sensitive data, non-human identities, secrets, tool permissions, logging, and production change controls. --- ### Qualifications - **8–10+ years** of professional experience in c

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord