xelys jobs xelys jobs

Cloud Security Engineer

Polymarket

midpermanentsecuritybackend New York, United States 9 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

AWSIAMSCPsAWS ConfigCloudTrailGuardDutySecurity HubKMSInfrastructure as CodePulumi

About the role

Role overview

Polymarket is hiring a Cloud Security Engineer to own the security posture of its AWS environment. You will work hands-on with engineering and security teams to design and enforce security controls in infrastructure code, build scalable guardrails, and reduce risk without slowing delivery.

Responsibilities

  • Own and continuously improve Polymarket’s AWS security posture across accounts, regions, and services, including:
    • IAM policies and SCPs
    • VPC segmentation and account-level security baselines
  • Review and enhance Infrastructure as Code (IaC) modules that encode security defaults
  • Integrate automated security checks into the deployment pipeline, including:
    • Policy-as-code validation
    • Misconfiguration scanning
  • Own and improve cloud security telemetry and detection signals using:
    • CloudTrail, GuardDuty, Security Hub, AWS Config rules
    • VPC Flow Logs and S3 access logging
  • Develop and tune detection logic for cloud threats; partner with the SOC team on:
    • alert fidelity
    • incident response runbooks
    • AWS-level investigations
  • Govern secrets management using AWS Secrets Manager and SSM Parameter Store; manage KMS key policies/rotation and envelope encryption patterns
  • Drive remediation for findings from AWS Inspector, Security Hub, and third-party CSPM tooling; maintain benchmarks aligned to CIS AWS Foundations
  • Support audit and compliance activities (SOC 2, PCI-DSS, or similar) and perform regular access reviews to prevent privilege creep

Requirements

  • 4+ years of experience in cloud security, cloud engineering, or a security-focused infrastructure role
  • Deep hands-on expertise with AWS security services, including:
    • IAM, SCP, GuardDuty, Security Hub, CloudTrail, AWS Config, KMS, WAF, Inspector, VPC
  • Hands-on IaC experience (e.g., Pulumi, Terraform, CDK) with a security-first mindset
  • Strong understanding of AWS networking and how misconfigurations become attack surface
  • Proficiency in at least one scripting/programming language for automation (e.g., Python, TypeScript, Go)
  • Ability to evaluate security risk in architectural decisions and communicate clearly with engineering peers

Nice to have

  • Familiarity with Pulumi, especially TypeScript-based stacks
  • Experience in Web3/blockchain/crypto threat models
  • Experience securing containerized workloads on ECS or EKS (image scanning, runtime security)
  • AWS certifications (Security Specialty, Solutions Architect — Professional, or equivalent)
  • Exposure to SOC 2 Type II or PCI-DSS cloud control requirements

About Polymarket

Polymarket is the world’s largest prediction market platform, enabling people to trade outcomes across real-world events such as politics, economics, sports, culture, and current affairs. The platform is built as a peer-to-peer marketplace with no centralized “house,” producing transparent, market-based probabilities. It operates at internet scale and is expanding rapidly in both volume and adoption.

Scraped 7/21/2026