386,639open jobs
10,098companies
50,285added this week
Browse all
Salary
$114k – $212k per year
Location
In office (San Jose)
Employment
Full-Time
Overview
Company
Impact
Profile match
Cadence Design Systems is an American software company founded in 1988 that supplies the electronic design automation tools engineers use to design and verify integrated circuits. Its products cover digital synthesis and place-and-route, custom and analogue design, circuit simulation with the Spectre and Virtuoso families, functional verification, and increasingly system-level analysis for packaging, thermal behaviour and computational fluid dynamics. Headquartered in San Jose and listed on Nasdaq, it also licenses design intellectual property such as processor and interface blocks, and competes primarily with Synopsys and Siemens EDA.

At Cadence, we hire and develop leaders and innovators who want to make an impact on the world of technology.

Job Title: Cloud Security Operations Engineer

Location: San Jose, California

Reports to: Senior Cloud Security Architect

Job Overview:

We are seeking a skilled and passionate Cloud Security Operations Engineer to join our dynamic Information Security team. In this role, you will be responsible for designing, implementing, and maintaining robust security controls across our public cloud environments, including AWS, Azure, GCP, and IBM Cloud. As a hands-on technical expert, you will play a crucial role in enhancing our cloud security posture, with a primary focus on data protection and incident management. This position offers the opportunity to work in a collaborative environment, where you will contribute to the security and resilience of our cloud infrastructure.

Job Responsibilities:

1. Secure Architecture and Engineering

  • Design and deploy secure reference architectures across multi-cloud environments.

  • Integrate security into Infrastructure-as-Code (IaC) using tools like Terraform, CloudFormation, and ARM Templates.

  • Implement cloud-native security controls: VPCs, WAFs, DDoS, and endpoint protections.

  • Ensure data protection via encryption, KMS/HSM, and DLP policies.

2. Identity and Access Management (IAM)

  • Design, implement, and audit IAM policies, roles, service accounts, and federation models using least-privilege principles.

  • Configure MFA, SSO, and PAM solutions for secure cloud access.

3. Monitoring, Detection, and Response

  • Configure and maintain cloud-native security tools (e.g., AWS Security Hub, Microsoft Defender for Cloud, Google Security Command Center).

  • Integrate cloud logs with SIEM systems for threat detection.

  • Lead incident response efforts for cloud-related security events.

  • Continuously monitor cloud environments using CSPM, CNAPP, and cloud-native security tools to identify, prioritize, and remediate security misconfigurations and policy violations.

  • Track and manage cloud security findings through remediation workflows.

  • Partner with Cloud Platform, Infrastructure, and Application teams to coordinate remediation of identified security risks and vulnerabilities.

  • Conduct root cause analysis of recurring cloud security issues and recommend preventive controls and automation improvements.

4. Cloud Data Loss Prevention (DLP) Management

  • DLP Alert Triage and Investigation: Monitor, triage, and investigate all DLP alerts and events. Differentiate between policy violations, potential insider threats, and false positives, escalating confirmed incidents to the Incident Response team.

  • Tool Optimization and Tuning: Serve as the subject matter expert (SME) for Cloud DLP tools (e.g., Microsoft Purview, Google DLP, dedicated CASB solutions). Continuously tune policies and rulesets to minimize alert fatigue while maintaining high fidelity.

  • Reporting and Compliance: Generate regular reports on DLP effectiveness, policy violations, and risk trends for leadership and compliance/audit teams (e.g., SOC 2, HIPAA, GDPR).

  • Data Classification Integration: Collaborate with Governance, Risk, and Compliance (GRC) teams to ensure DLP policies align with the corporate data classification framework.

5. Automation and DevSecOps

  • Develop automation scripts (Python, PowerShell, Bash) and serverless functions (AWS Lambda, Azure Functions, Google Cloud Run).

6. Cloud Security Posture Management & Compliance

  • Continuously assess AWS, Azure, and GCP environments using CSPM platforms to identify misconfigurations, excessive permissions, exposed resources, compliance gaps, and other security risks.

  • Develop, maintain, and enforce cloud security baselines aligned with industry standards, regulatory requirements, and organizational security policies.

  • Perform periodic cloud security assessments and audits using CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and internal security standards.

  • Drive remediation of findings identified through CSPM monitoring, security assessments, audits, compliance reviews, and risk assessments.

  • Support internal and external audits by providing cloud security evidence, compliance reporting, and remediation status updates.

7. Secure Access and Network Security Controls

  • Enforce secure access patterns by eliminating unnecessary public exposure and implementing private endpoints, bastion hosts, AWS Systems Manager Session Manager, and least-privilege network segmentation.

  • Enforce private connectivity architectures by leveraging:

    • AWS PrivateLink

    • Azure Private Endpoints

    • Google Private Service Connect

  • Eliminate unnecessary public exposure of cloud workloads, services, and management interfaces.

  • Design and maintain least-privilege network segmentation and cloud-native firewall controls across multi-cloud environments.

8. Cloud Workload Security and Hardening

  • Establish and maintain secure cloud operating system baselines using CIS Benchmarks and vendor-recommended hardening standards.

  • Perform periodic reviews and validation of operating system, virtual machine, and container security configurations.

  • Collaborate with Infrastructure and Platform teams to implement hardened images and golden image standards.

  • Monitor and remediate deviations from approved OS hardening baselines.

Job Qualifications:

Technical Expertise

  • Deep knowledge of at least one cloud platform (AWS, Azure, or GCP).

  • Proficiency in scripting: Python (preferred), PowerShell, Unix shell scripting.

  • Strong understanding of networking and cloud-native network security.

  • Experience with CSPM/CNAPP platforms such as CloudGuard Dome9, Wiz, Prisma Cloud, Microsoft Defender for Cloud, or similar solutions.

  • Strong knowledge of CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and industry cloud security best practices.

  • Familiarity with securing OS and containerized environments (Docker, Kubernetes).

  • Experience implementing secure cloud network architectures, private endpoints, bastion access patterns, and zero-trust security principles.

  • Experience supporting cloud compliance, audit readiness, and regulatory assessments.

Education & Certification

  • Bachelor’s degree in computer science, Information Security, or related field (or equivalent experience).

  • Preferred Certifications:

    • AWS Certified Solutions Architect - Associate

    • AWS Certified Security - Specialty

    • Microsoft Certified: Azure Administrator Associate

    • Microsoft Certified: Azure Security Engineer Associate

    • Google Cloud: Associate Cloud Engineer

    • Google Cloud: Professional Cloud Security Engineer

    • (ISC)² Certified Cloud Security Professional (CCSP)

    • (ISC)² Certified Information Systems Security Professional (CISSP)

Soft Skills

  • Strong analytical and problem-solving abilities.

  • Excellent communication and collaboration skills, especially with DevOps and engineering teams.

Cadence is committed to equal employment opportunity and employment equity throughout all levels of the organization. We strive to attract a qualified and diverse candidate pool and encourage diversity and inclusion in the workplace.

Travel: N/A

The hourly range for California is $57.21 to $106.25 per hour. You may also be eligible to receive incentive compensation: bonus, equity, and benefits. Please note that the hourly range is a guideline and compensation may vary based on factors such as qualifications, skill level, competencies and work location. Our benefits programs include: paid vacation and paid holidays, 401(k) plan with employer match, employee stock purchase plan, a variety of medical, dental and vision plan options, and more.

We’re doing work that matters. Help us solve what others can’t.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
386,639 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Jose
$29k – $72k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Bengaluru
DevOps
AWS
Azure
CI/CD
GCP
SLI/SLO/SLA
Cybersecurity
CVSS
EPSS
KEV
Apply
$136k – $222k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Toronto
Python
AI/ML
AI Agents
Embeddings
JAX
LLM
PyTorch
RAG
Semantic Search
TensorFlow
Anthropic
OpenAI
Semantic Search
DevOps
AWS
Azure
Docker
GCP
Kubernetes
Terraform
Vector
Apply
$40k – $114k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Mexico City
Python
Databases
Apache Kafka
AI/ML
AI Agents
LLM
OCR
DevOps
AWS
AWS Step Functions
CI/CD
KEDA
Kubernetes
Apply
In office • Full-Time • 4+ years exp • PhD • Cairo
C#
JavaScript
PowerShell
TypeScript
C#
.NET
DevOps
Azure
Azure DevOps
Bicep
CI/CD
Git
GitHub
GitHub Actions
Terraform
Management
Power Apps
Power Automate
Apply
$86k – $115k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Westminster
Java
Python
TypeScript
JavaScript
Java
Spring Boot
Python
FastAPI
Databases
PostgreSQL
AI/ML
AI Agents
Frontend
Angular
React.js
Vue.js
DevOps
AWS
CI/CD
CloudFormation
Docker
GCP
Kubernetes
Rest API
Terraform
Apply
$27k – $71k per year (Estimated) • In office • Full-Time • 7+ years exp • Pune
C#
C++
Java
Python
DevOps
Azure
CI/CD
Git
QA
Pytest
Apply
In office • Full-Time • Seoul
C++
SystemVerilog
Verilog
Apply
$28k – $74k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Noida
C++
Python
Chips/EDA
Cadence Pegasus
Apply
In office • Full-Time • Master's Degree • Beijing
C++
Chips/EDA
Cadence AMS Designer
Cadence Spectre
Cadence Xcelium
Apply
In office • Full-Time • Master's Degree • Hsinchu
C++
Apply
$87k – $196k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • San Jose • Minneapolis • Folsom
JavaScript
Python
AI/ML
AI Agents
Anomaly Detection
Claude
Claude Code
Cursor
Gemini
LLM
RAG
Scikit-learn
DevOps
AWS
Azure
GCP
Analytics
Matplotlib
Plotly
Apply
$147k – $299k per year (Estimated) • Remote/Hybrid • Full-Time • 12+ years exp • San Jose
C++
Cybersecurity
Zero Trust
Zscaler
Apply
$174k – $327k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • San Jose
Go
Python
Rust
DevOps
AWS
Azure
GCP
Cybersecurity
Zero Trust
Zscaler
Apply
$140k – $200k per year • In office • San Jose
Java
Kotlin
Mobile
Kotlin Multiplatform
DevOps
GCP
Marketing
LinkedIn
Apply
$140k – $200k per year • In office • PhD • San Jose
AI/ML
Text-to-Speech
DevOps
AWS
Azure
Docker
GCP
Kubernetes
Vercel
Management
Google Docs
Stripe
Marketing
LinkedIn
Apply
See all jobs
This is one of many
386,639 more open roles from verified company boards, updated every day.