xelys jobs xelys jobs

Sr. Infrastructure Security Engineer

Jobgether

seniorpermanentsecuritydevops United States Yesterday via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Cloud SecurityGCPAzureTerraformCI/CDSecurity-as-CodeCNAPPWizVulnerability ManagementSIEM

About the role

Role Overview

Sr. Infrastructure Security Engineer (United States). Own and improve cloud infrastructure security across GCP and Azure, combining hands-on engineering with security strategy, automation, and cross-functional collaboration to reduce risk at scale.

Responsibilities

  • Lead cloud security initiatives across Google Cloud Platform (GCP) and Microsoft Azure (design through implementation and operationalization)
  • Improve cloud security posture using CNAPP capabilities (prioritize meaningful risks, reduce security noise, drive remediation)
  • Embed security controls into infrastructure workflows with Terraform, CI/CD, and security-as-code practices
  • Own vulnerability management: identify vulnerabilities, prioritize risk, coordinate remediation, and track improvements
  • Enhance data and endpoint protection (e.g., DLP, endpoint detection, identity management, device security)
  • Develop and improve threat detection using SIEM (detection logic and support for incident response)
  • Identify and remediate security weaknesses across IAM, networking/firewall, encryption, and access controls
  • Create security standards, documentation, and operational runbooks for engineering teams
  • Act as a senior escalation point during security incidents (investigation, response, resolution)
  • Use AI-powered tools responsibly to improve security analysis, automation, code review, and operational efficiency
  • Mentor engineers and promote security awareness

Requirements

  • 8+ years relevant experience with a Bachelor’s degree (or 6+ years with a Master’s)
  • Strong hands-on experience securing cloud environments, particularly GCP and/or Azure
  • Deep knowledge of cloud security fundamentals: IAM, networking, logging/monitoring, encryption, and identity management
  • Experience with CNAPP tools such as Wiz to identify, prioritize, and remediate real risks
  • Proficiency with Terraform and integrating security controls into CI/CD
  • Experience running vulnerability management and partnering with engineering for remediation
  • Familiarity with data security practices (e.g., DLP, sensitive data discovery, endpoint protection, identity platforms such as Okta or Google Workspace)

Nice-to-haves

  • Strong SIEM experience for threat detection and incident response support
  • Experience creating detection logic and operationalizing security controls at scale

Scraped 7/30/2026