Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Cloud Security Engineer

Security Risk Advisors
CompanySecurity Risk Advisors
CategoryEngineering
LocationPhiladelphia
RemoteOn-site (inferred)
EmploymentFull-time
LevelNot stated
SalaryNot stated by the employer
Posted10 Jul 2026
Last verified30 Jul 2026
SourceEmployer career page (workable)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Security Risk Advisors Intl., LLC (SRA) is offering a Cloud Security Engineer position. This role is responsible for designing, implementing, and maintaining security controls across SRA's multi-cloud environment, spanning Microsoft Azure/Entra ID, Google Cloud Platform (GCP), and Amazon Web Services (AWS). The Cloud Security Engineer will work closely with internal IT, security operations, and engineering teams to ensure cloud infrastructure is deployed and maintained in a secure, compliant, and resilient manner.  Essential Functions  Design, implement, and maintain cloud security architectures across Azure/Entra ID, GCP, and AWS environments.  Administer and continuously improve cloud identity and access management (IAM) policies, roles, and privilege models across all three platforms.  Monitor cloud environments for misconfigurations, threats, and vulnerabilities using cloud-native and third-party security tooling (e.g., Defender for Cloud, Security Command Center, AWS Security Hub).  Operationalize cloud vulnerability and patch management processes, ensuring timely remediation of identified risks.  Implement and maintain Cloud Security Posture Management (CSPM) solutions to enforce security baselines and compliance standards.  Develop and enforce cloud security policies, standards, and guardrails (e.g., Azure Policy, GCP Organization Policies, AWS SCPs).  Collaborate with engineering and DevOps teams to embed security into CI/CD pipelines and infrastructure-as-code (IaC) workflows.  Conduct cloud security assessments and architecture reviews for new and existing environments.  Support incident response activities related to cloud infrastructure, including investigation, containment, and remediation.  Create and maintain technical documentation for cloud security architectures, configurations, and operational procedures.  Research and evaluate emerging cloud security technologies and provide recommendations for adoption.  Develop detection content and security analytics in SRA's internal SOC applicable to cloud environments.  Requirements Competencies  In-depth understanding of:  Microsoft Azure and Entra ID, including conditional access, PIM, and Defender for Cloud  Google Cloud Platform (GCP) security services, including Security Command Center, IAM, and VPC Service Controls  Amazon Web Services (AWS) security services, including IAM, GuardDuty, Security Hub, and AWS Config  Cloud identity and access management principles and zero trust architecture  Working knowledge of:  Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP)  Infrastructure-as-Code (IaC) tools such as Terraform, Bicep, or CloudFormation  Networking concepts as applied to cloud environments (VPCs, peering, private endpoints, firewalls)  SIEM and EDR technologies in cloud-integrated environments  Experience with:  CI/CD pipeline security and DevSecOps practices  Organizing or supporting penetration testing, purple team exercises, or cloud-focused security assessments  Compliance frameworks relevant to cloud environments (e.g., CIS Benchmarks, NIST CSF, SOC 2)  Moderate experience with:  Scripting and automation using Python, PowerShell, or Bash  Automation via tools such as Power Automate, Logic Apps, or cloud-native orchestration services  Supervisory Responsibility   None    Work Environment      This job operates on-site in a professional office environment or remotely as needed/required. This role routinely uses standard office equipment.      Physical Demands   The physical demands de
HOUSE AD986,449 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →