Cloud Security Engineer
About Workstreet
At Workstreet , we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the Security Services Team
We are the team that turns complex security requirements and compliance frameworks into infrastructure and services that actually work. Moving fast and taking true end-to-end ownership, our team spans three core functions: Cloud Security Engineering , where we design hardened AWS, Azure, and GCP environments, write Terraform baselines, and fix failing controls to meet frameworks like SOC 2, ISO 27001, CMMC, and FedRAMP; Penetration Testing , where we run disciplined offensive assessments across networks, apps, cloud, and AI/LLM systems to catch vulnerabilities before adversaries do; and Vulnerability Management , where we continuously prioritize, patch, and validate risk reduction across the client footprint. We do not hide behind process or just point out gaps. We step in, build solutions, and deliver real security posture improvements with minimal disruption.
What makes this team special isn't just our technical depth; it is how we back each other up. Our strongest engineers and assessors are the ones building reusable modules, writing custom tools, jumping into channels to unblock teammates, and mentoring without being asked. From early-stage startups to regulated enterprises, you will work directly with clients, take on real ownership early, and be surrounded by people who want to see you get good. If you enjoy solving tough security problems and want to be part of a team that is scrappy enough to move fast but seasoned enough to get it right, you will be in good company here.
The Opportunity
We are seeking a Cloud Security Engineer to help clients design, implement, and maintain security controls that meet compliance and security requirements. This role is ideal for professionals with hands-on experience in cloud security engineering, compliance frameworks, and cloud-based security best practices. You’ll work closely with clients and internal teams to strengthen their cloud security posture and automate security operations across AWS, GCP, and Azure environments.
What you'll do
-
Deploy and maintain robust cloud security controls across AWS, GCP, and Azure to eliminate system misconfigurations and preserve continuous regulatory alignment.
-
Execute deep-dive architectural risk assessments to surface infrastructure vulnerabilities, evaluate asset exposures, and engineer targeted technical remediation blueprints.
-
Configure and manage enterprise security tool suites , including SIEM platforms, log analytics engines, identity management layers, IDS/IPS tools, and vulnerability scanning infrastructure.
-
Own the client relationship lifecycle as the primary trusted advisor for an assigned portfolio, establishing project milestones, managing communication pathways, and handling technical escalations with calm professionalism.
-
Programmatically enforce security controls by engineering automated, repeatable Infrastructure as Code (IaC) deployment playbooks and configuration scripts.
-
Embed continuous security guardrails into CI/CD pipelines and development workflows to intercept infrastructure vulnerabilities early in the lifecycle.
-
Investigate and contain cloud-related security incidents , rapidly executing technical diagnostics and remediation loops to restore platform integrity.
-
Support continuous audit readiness within GRC frameworks by systematically gathering, testing, and validating multi-cloud configuration evidence.
Who you are
-
Proven multi-cloud sec