About this Cyber Cloud Security Engineer role at Pierce Technology Corp
Multi-Cloud Security Leadership: Built and managed comprehensive cloud security programs across AWS, Azure, and GCP, establishing baseline security standards, policies, and governance procedures.
Secure Architecture & Zero Trust: Designed, implemented, and validated secure cloud architectures applying Zero Trust principles across network, infrastructure, and identity access models.
Vulnerability & Posture Management: Leveraged CSPM tools (Wiz, AWS Security Hub) and automated remediation workflows to continuously detect, prioritize, and resolve cloud misconfigurations and vulnerabilities.
Detection Engineering & Monitoring: Developed automated continuous monitoring and alerting systems while partnering with the SOC to strengthen cloud detection engineering capabilities.
Shift-Left Security & Cross-Team Collaboration: Embedded security into the SDLC by partnering directly with Platform, DevOps, and Engineering teams to promote secure development practices and deliver shared security initiatives.
Requirements
AWS & Cloud Security Architecture: 6–10 years of hands-on experience designing and securing AWS environments, backed by strong knowledge of native security tools (IAM, KMS, Config, GuardDuty, CloudTrail) and industry certifications (AWS Security/Architect, CISSP, CCSP).
Identity & Access Management (IAM): Proven expertise architecting cloud identity solutions, including SSO/federation (Okta), RBAC, ABAC, and robust service-to-service authentication models.
Infrastructure as Code (IaC) & Automation: Skilled in provisioning secure infrastructure via Terraform, AWS CDK, or CloudFormation, using Python and Bash to build custom security tooling and automated workflows.
Container Security & DevOps: Hands-on experience securing containerized workloads (Docker, Kubernetes, AWS EKS) integrated directly with modern CI/CD pipelines (GitLab CI, Jira).
Governance, Compliance & Influence: In-depth knowledge of translating frameworks (NIST CSF, CIS Benchmarks, ISO 27001, SOC 2) into cloud controls, with strong communication skills to influence stakeholders and drive security initiatives.