Confirmed on the employer's own hiring board on Oct 11, 2026. First seen by Alion on Oct 11, 2026.
Join Scribd as a Staff Cloud Security Engineer, where you'll play a crucial role in protecting our applications and cloud infrastructure. You'll shape the technical direction of Cloud Security, drive complex architectural investments across our AWS and GCP environments, and work closely with engineering teams to address security risks and build effective security controls. This hands-on technical leadership role offers a competitive benefits package, including healthcare coverage, paid parental leave, and a 401k matching plan.
Missions
- Set the Cloud Security architecture and strengthen security architecture and guardrails across AWS and GCP environments.
- Drive security architecture and guardrails for cloud workloads, including Kubernetes, secure base images, workload identity, runtime protection.
- Shape and drive the Cloud Security technical roadmap, lead complex technical initiatives, and influence their adoption across engineering teams.
Profil recherché
- Experience designing and implementing cloud security guardrails at scale, including account or project security baselines, policy-as-code (e.g., AWS SCPs or OPA), secure infrastructure provisioning, and landing zone automation- Experience with cloud security visibility and response, including cloud-native security tooling (e.g., GuardDuty, Security Command Center, CloudTrail, or Cloud Audit Logs), detection capabilities, SIEM integration, and applying incident learnings to improve preventive and detective controls
- 10+ years of experience with significant depth in cloud or infrastructure security engineering, or an equivalent blend of software and security engineering, with hands-on experience securing production cloud environments at scale. Deep expertise in at least one of AWS or GCP, with sufficient fluency in the other to reason about security risks
- Experience shaping security architecture and leading initiatives across team boundaries, including influencing engineering teams to adopt security standards and controls without formal authority
- Experience with cloud security posture management and workload protection, including CSPM/CNAPP platforms, evaluating security findings, identifying attack paths, and translating them into prioritized improvements
- Experience securing cloud workloads, including Kubernetes, container security, runtime protection, and workload isolation
- Strong Infrastructure-as-Code and automation skills, including Terraform or equivalent tooling and proficiency in a programming language such as Python or Go
- A track record of delivering measurable security improvements, balancing technical depth, architectural judgment, and hands-on execution
- Deep hands-on identity and access management expertise, including least-privilege access, cross-account access patterns, short-lived workload credentials (e.g., IRSA, OIDC federation), and service-to-service identity and authorization (e.g., mTLS, SPIFFE/SPIRE, or service mesh identity models), with experience reducing standing access and long-lived credentials

