Job Overview
We are seeking an innovative and experienced Senior Cloud Security Engineer to secure Posit’s cloud infrastructure. The ideal candidate will be a systems thinker with deep cloud security expertise and a proven track record in building secure, scalable solutions for cloud-hosted and on-premise software. You’ll play a crucial role in shaping our security architecture, implementing robust controls, and ensuring the security of our multi-tenant environments and software supply chain.
Our department’s mission is to ensure the security of Posit’s employees, assets, and customer data. We achieve this through secure architecture design, threat detection and response, supply chain security, secure development practices, and security operations, enabling innovation with right-sized security controls.
Since its inception, Posit has operated as a 100% distributed company with a SaaS-based infrastructure. This presents unique challenges and requires pragmatism and creativity to be successful. This position requires the ability to be design and systems focused in support of your team and colleagues.
Key Responsibilities
Own
- Architect and implement security controls for AWS-hosted applications and multi-tenant environments (GCP, Azure)
- Design and maintain secure infrastructure patterns using Infrastructure as Code
- Lead cloud security incident investigations and response efforts
- Implement comprehensive supply chain security controls
- Improve automated threat detection and response capabilities
- Create and maintain cloud security incident response playbooks
- Design security architecture standards for new application components
Assist
- Contribute directly to Posit product reference architecture, lending security expertise to design decisions
- Support compliance initiatives for cloud infrastructure by creating processes and providing evidence of security controls
- Drive security monitoring strategy across cloud infrastructure
Teach
- Guide teams in performing secure DevOps practices
- Collaborate on technical documentation and standards
Learn
- Using AI to improve Cloud Security and ways to protect software development and Posit customers from AI threats
- Data science workflows to report on security telemetry systems
About You
- Deep expertise in AWS security architecture and services
- Understanding of Google Cloud and Microsoft Azure security architecture and services
- Strong background in securing multi-tenant environments
- Extensive experience with security controls with an emphasis on vulnerability management and detection of misconfigurations
- Proficiency in Python for security automation and the creation of reusable workflows using GitHub Actions
- Experience with cloud security platforms
- Knowledge of software supply chain security
- Expertise with security telemetry systems and SIEM platforms
- Strong background in Infrastructure as Code (Pulumi preferred)
- Excellent written communication for use by other engineers and operators
- Experience with container security and container orchestration platforms (Kubernetes)
- Knowledge of compliance frameworks (SOC 2, ISO 27001)
APPLY