Back to search
LHH Linkedin · Posted 12d ago

Senior Cloud Security Engineer

San Francisco, CA, United States

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Location: Hybrid in San Francisco (1+ days a week)

Job Type: Fulltime, direct hire

Please note: This is not a C2C or C2H role. Our client is unable to sponsor or take over sponsorship of an employment visa at this time.


We are seeking a Senior Cloud Security Engineer to help drive secure platform operations and software delivery practices for a growing AI SaaS startup. This role sits at the intersection of platform engineering and security, with responsibility for building security into the development lifecycle through automation, infrastructure standards, and operational controls. The position is hands-on and includes both technical execution and collaboration across engineering teams.


Responsibilities:

  • Build and operate secure CI/CD pipelines, embedding SAST, DAST, dependency, and container scanning as automated quality gates.
  • Own Kubernetes platform security on AKS, including hardened baselines, network policy, admission control (OPA/Gatekeeper), and runtime protection.
  • Harden the software supply chain through signed container images, SBOM generation, provenance attestations, hardened base images, and policy-enforced container registries (ACR).
  • Manage infrastructure as code (Terraform) and GitOps delivery (Argo CD and/or Flux), with security and policy-as-code controls (Azure Policy) enforced across the cloud landing zone.
  • Operate and optimize cloud security tooling, including Microsoft Defender for Cloud, Sentinel, Key Vault, Entra ID, and Privileged Identity Management (PIM), while tuning detections and alerting workflows.
  • Partner closely with engineering teams to remediate vulnerabilities, manage secrets, and improve the signal-to-noise ratio of scanning, detection, and WAF workflows.
  • Contribute to evidence collection, automation, and control implementation efforts supporting ISO 27001, ISO 42001, and SOC 2 compliance programs.


Requirements:

  • 8+ years in DevOps/SRE/security engineering, with deep hands-on Azure experience (AKS, ACR, networking, IAM/RBAC).
  • Strong IaC and GitOps skills (Terraform plus Argo CD or Flux) and fluent scripting (Python, Bash, or Go).
  • Practical security depth: container and Kubernetes hardening, supply-chain security, secrets management, and threat modeling.
  • Experience with policy-as-code and a compliance framework (ISO 27001, SOC 2, or NIST).
  • A bias for automation and clear judgment on where to enforce vs. enable.


Nice to have:

  • AI/ML platform security exposure (Azure AI Foundry, OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF).
  • Azure security certifications (AZ-500, SC-100) or CKS.


Benefits:

  • Competitive market salary
  • Health insurance coverage
  • PTO
  • 401k with match
  • Hybrid Work Schedule
  • Opportunity to join at the ground floor of a growing, financially backed startup


Equal Opportunity Employer/Veterans/Disabled:

To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to https://www.lhh.com/us/en/candidate-privacy

The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:

• The California Fair Chance Act

• Los Angeles City Fair Chance Ordinance

• Los Angeles County Fair Chance Ordinance for Employers

• San Francisco Fair Chance Ordinance

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search