703,105open jobs
41,483companies
102,003added this week
Browse all
Salary
$106k – $241k per year (Estimated)
Location
Remote (United States)
Employment
Full-Time
Overview
Company
Impact
Profile match
SOC 2, CMMC, pentesting & security questionnaires handled by ex-Big Four security leaders and AI that works behind the scenes. You focus on product and customers. We handle the rest.

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

Get to Know the Security Services Team

We are the team that turns complex security requirements and compliance frameworks into infrastructure and services that actually work. Moving fast and taking true end-to-end ownership, our team spans three core functions: Cloud Security Engineering, where we design hardened AWS, Azure, and GCP environments, write Terraform baselines, and fix failing controls to meet frameworks like SOC 2, ISO 27001, CMMC, and FedRAMP; Penetration Testing, where we run disciplined offensive assessments across networks, apps, cloud, and AI/LLM systems to catch vulnerabilities before adversaries do; and Vulnerability Management, where we continuously prioritize, patch, and validate risk reduction across the client footprint. We do not hide behind process or just point out gaps. We step in, build solutions, and deliver real security posture improvements with minimal disruption.

What makes this team special isn't just our technical depth; it is how we back each other up. Our strongest engineers and assessors are the ones building reusable modules, writing custom tools, jumping into channels to unblock teammates, and mentoring without being asked. From early-stage startups to regulated enterprises, you will work directly with clients, take on real ownership early, and be surrounded by people who want to see you get good. If you enjoy solving tough security problems and want to be part of a team that is scrappy enough to move fast but seasoned enough to get it right, you will be in good company here.

The Opportunity

We are seeking a Cloud Security Engineer with Oracle Cloud Infrastructure (OCI), including compute, networking, storage, and IAM experience, to help clients design, implement, and maintain security controls that meet compliance and security requirements. This role is ideal for professionals with hands-on experience in cloud security engineering, compliance frameworks, and cloud-based security best practices. You’ll work closely with clients and internal teams to strengthen their cloud security posture and automate security operations across AWS, GCP, and Azure environments.

What You'll Do

  • Deploy and maintain robust cloud security controls across AWS, GCP, Azure, and OCI to eliminate misconfigurations and preserve strict regulatory compliance alignment.
  • Execute deep-dive architectural risk assessments to surface cloud system vulnerabilities, evaluate asset exposures, and engineer targeted technical remediation blueprints.
  • Configure and manage enterprise security tool suites, including SIEM solutions, log analytics platforms, identity management layers, IDS/IPS tools, and vulnerability management engines.
  • Own the client relationship lifecycle as the primary trusted advisor for an assigned portfolio, establishing project milestones, managing communication pathways, and handling technical escalations with calm professionalism.
  • Programmatically enforce security controls by engineering automated, repeatable IaC deployment playbooks and security testing infrastructure.
  • Embed continuous security guardrails into CI/CD pipelines and containerized environments to intercept system vulnerabilities early in the software development lifecycle.
  • Investigate and contain cloud-related security incidents, rapidly executing forensic logic and remediation steps to restore system integrity and minimize blast radii.
  • Support continuous audit readiness within GRC platforms like Vanta by systematically gathering, testing, and validating cloud configuration evidence.

Who You Are

  • Proven multi-cloud security engineer - Command direct operational ownership of distributed cloud infrastructure security, with hands-on validation across AWS, GCP, Azure, and Oracle Cloud Infrastructure (OCI).
  • Cloud security architecture expert - Mastered advanced identity and access management (IAM) strategies, cloud network zoning, payload encryption standards, and systemic risk mitigation workflows.
  • Advanced security automation developer - Highly proficient in in Infrastructure as Code (IaC), building and deploying automated guardrails with Terraform, AWS CloudFormation, Python, and Bash.
  • GRC infrastructure strategist - Aligned technical, cloud-native configurations directly against global regulatory compliance and audit frameworks, including SOC 2, ISO 27001, GDPR, and HIPAA.
  • Surgical technical problem-solver - Apply rigorous analytical diagnostics to isolate cloud infrastructure vulnerabilities, resolve failing controls, and execute zero-disruption remediation.
  • High-impact client consultant - Confidently orchestrate multiple client portfolios concurrently, partnering directly with US-based technology founders, DevOps leads, and executive teams to scale cloud security maturity.
  • Elite technical communicator - Deliver flawless written and verbal English communication that effortlessly translates dense cloud vulnerabilities and risk vectors into actionable business value.

What will help you succeed

  • Deep data and monitoring tooling execution - Advanced manipulation of enterprise logging platforms, vulnerability management engines, threat hunting feeds, and network traffic analysers.
  • Validated cloud security credentials - Hold active technical certifications such as AWS Certified Security - Specialty, GCP Professional Cloud Security Engineer, CISSP, CISM, or CISA.
  • Container and DevSecOps engineering - Practical success auditing and isolating security boundaries within microservice architectures, Docker instances, and Kubernetes clusters.
  • Zero Trust deployment models - Direct execution of identity-centric security policies, network micro-segmentation, and context-aware access structures.
  • Commercial tenure in fast-growth environments - Documented history scaling infrastructure configurations within hyper-growth tech startups or elite managed security service providers (MSSP).

What We Offer

  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.

What You'll Need to Thrive

  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM-5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.

Hiring and Selection Process

  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.

Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.

All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact [email protected]

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
703,105 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$77k – $143k per year (Estimated) • Equity • In office • Full-Time • Paris
Python
Python
FastAPI
Asyncio
Databases
Redis
AI/ML
Cursor
LangChain
Claude Code
Model Context Protocol
AI Agents
Gemini
LLM
OpenAI Codex
LiveKit
Edge AI
Mobile
Clean Architecture
DevOps
GCP
WebSockets
Azure
CI/CD
AWS
Docker
Kubernetes
Linux
Apply
$64k – $130k per year (Estimated) • In office • Full-Time • 5+ years exp • Toronto
Python
PowerShell
AI/ML
NIST AI RMF
DevOps
Azure
DNS
Cybersecurity
Qualys Cloud Platform
Microsoft Sentinel
Zscaler
Microsoft Defender
Zero Trust
Least Privilege
Microsoft Entra ID
Management
ServiceNow
Apply
$140k – $150k per year • Equity • Remote • Full-Time • 8+ years exp • Washington • New York
DevOps
Azure
AWS
Cybersecurity
SOC 2
HIPAA
Apply
$60k – $62k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Lewisville
DevOps
Azure
Windows
VPN
Cybersecurity
Active Directory
Management
Service Desk
Microsoft Office
Apply
$99k – $212k per year (Estimated) • In office • Full-Time • 3+ years exp • Toronto
Python
PowerShell
AI/ML
NIST AI RMF
Cybersecurity
MITRE ATT&CK
Cyber Kill Chain
Diamond Model
STIX
TAXII
SIEM
Apply
Remote • Full-Time
DevOps
GCP
Azure
AWS
SLI/SLO/SLA
Cybersecurity
ISO 27001
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Management
ServiceNow
Apply
$13k – $30k per year (Estimated) • Remote • Full-Time
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Apply
$20k – $50k per year (Estimated) • Remote • Full-Time
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Apply
GRC Engineer (NIST) 1 month ago
$66k – $128k per year (Estimated) • Remote • Full-Time • 2+ years exp • Master's Degree
DevOps
Azure
AWS
Cybersecurity
ISO 27001
SOC 2
GDPR
NIST 800-53
NIST 800-171
FedRAMP
Apply
GRC Engineer (CMMC) 1 month ago
$74k – $184k per year (Estimated) • Remote • Full-Time
DevOps
Azure
AWS
Cybersecurity
ISO 27001
SOC 2
GDPR
NIST 800-53
NIST 800-171
FedRAMP
Apply
See all jobs
This is one of many
703,105 more open roles from verified company boards, updated every day.