Senior Cloud Security Engineer
Beyondfinance · Remote
About this role
## Senior Cloud Security Engineer ### About Beyond Finance At Beyond Finance, we help everyday Americans escape the cycle of crippling debt and step into a brighter financial future through compassionate, individualized care, a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions. We’ve helped over 1 million clients. ### The Role As a **Senior Security Engineer**, you’ll harden the security posture of our **AWS environment** and our **software development pipeline**. **Cloud Security and vulnerability management in Wiz** are primary focus areas. You’ll partner with **DevOps**, **Engineering**, and our **Application Security Engineer** to build preventative controls across **infrastructure, identity, and CI/CD**. The work is hands-on: configuring tooling, reviewing architecture, hardening pipelines, and supporting application security work where needed. ### Key Responsibilities - Own cloud security posture across our AWS environment using **Wiz** and **AWS-native services**, reducing risk across **IAM**, **network segmentation**, **container security**, **secrets**, and **data exposure**. - Establish secure defaults in **Infrastructure as Code** using reusable modules, guardrails, and **policy as code**. - Harden **CI/CD pipelines** in partnership with DevOps. - Run **vulnerability management** across cloud and application findings: intake, prioritization, **SLA tracking**, and remediation with engineering. - Build automation that scales the program: ingestion, deduplication, prioritization, and developer-facing workflows. - Instrument **telemetry**, **alerting**, and **runbooks** for systems you own. - Operate and tune our **WAF**: managed and custom rules, rate limiting, and bot mitigation. ### Requirements - **5+ years** of hands-on security engineering across **cloud security** and **vulnerability management**. - Strong AWS security background: **IAM**, networking, container orchestration, and logging/audit. - Hands-on experience securing **CI/CD pipelines** and **Infrastructure as Code**; **Terraform required**. - Experience running or substantially contributing to a **vulnerability management** program. - Working knowledge of **OWASP Top 10** and **threat modeling**. - Operates independently and drives projects without day-to-day oversight. ### Nice to Have - Experience with our stack: **Wiz**, **Cloudflare (WAF, Gateway, Zero Trust)**, **GitHub Advanced Security**, **Spacelift**, and AWS-native services. - Hands-on **WAF** experience in production: writing/tuning rules, managing false positives, responding when something gets through. - AI/ML security exposure: prompt injection, data poisoning, model abuse, and mitigations. - Secrets management platforms (AWS Secrets Manager, Keeper, Infisical). - Identity security across human and non-human identities. - PCI-regulated or financial services environment. - Familiarity with **Ruby on Rails**, **Python**, or **Go**. ### The Ideal Candidate You measure success by **reduced risk**, not tickets closed. You pursue secure design and simplicity, think like an attacker, and bring a developer mindset—connecting the dots across **cloud, identity, and pipeline**. When something is blocked, you bring a proposed path forward. ### Base Salary Range - **$140,000 – $165,000 USD** (eligible for additional incentives, including an annual bonus) ### Why Join Us? For eligible full-time employees, we offer: - Employer contributions for
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.