Senior Cloud Security Engineer

🏢 Med-Metrix · all Med-Metrix jobs
📍 United States
📅 Posted 2026-08-06 · via Himalayas
🏷 Cloud-Security-Engineering,Cloud-Security-Engineer,DevSecOps,AI-ML-Security,Cloud-Architecture,Senior-Cloud-Infrastructure-Security-Engineer,Senior-Cloud-Security-Software-Engineer,Senior-Cloud-Security-Architect,Senior-Cloud-Security-Analyst,Lead-Cloud-Security-Architect,Security-Engineer
Apply on original site ↗

Job Purpose The Senior Cloud Security Engineer will design, implement, and maintain security controls across our multi-cloud environment, with a particular emphasis on securing AI/ML workloads and leveraging AI-driven security tooling. The Senior Cloud Security Engineer will serve as a technical leader, partnering with engineering, application development, and DevOps teams to embed security into every stage of the cloud and AI development lifecycle.
Duties & Responsibilities

- Design and implement secure cloud architecture across AWS and Azure, including identity, network security, encryption, and key management

- Implement cloud-native logging, monitoring, and threat detection to improve visibility and incident response

- Build Infrastructure-as-Code (Terraform, CloudFormation, Bicep), Policy-as-Code, and automated compliance controls

- Implement and enhance Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWPP), and CNAPP capabilities

- Conduct threat modeling, security architecture reviews, and risk assessments for cloud services and applications

- Design and secure AI/ML environments, including MLOps pipelines, model security, inference endpoints, and AI governance

- Assess and mitigate AI-specific threats, including prompt injection, model poisoning, adversarial attacks, and data leakage

- Partner with engineering and data science teams to implement secure-by-design and privacy-preserving controls for regulated data

- Develop automated detections, SOAR playbooks, and AI-driven threat hunting capabilities

- Lead technical response to cloud and AI security incidents, including forensic analysis and remediation

- Design and implement security controls supporting HIPAA, HITRUST, PCI DSS, SOC 2, NIST CSF, and NIST AI RMF requirements

- Support technical readiness, evidence collection, and remediation activities for security audits and compliance assessments

- Develop and maintain cloud security standards, technical guidance, and AI governance documentation

- Support enterprise risk management and vendor security assessments

- Integrate security throughout the DevSecOps lifecycle, including application, container, and secrets management

- Develop security metrics, communicate technical risks to stakeholders, and recommend continuous security improvements

- Mentor junior engineers and champion security best practices across engineering teams

- Other duties as assigned

- Use, protect and disclose patients’ protected health information (PHI) only in accordance with Health Insurance Portability and Accountability Act (HIPAA) standards

- Understand and comply with Information Security and HIPAA policies and procedures at all times

- Limit viewing of PHI to the absolute minimum as necessary to perform assigned duties

Qualifications

- High school diploma or equivalent required

- 6+ years of experience in information security, with at least 4 years focused on cloud security engineering

- Deep hands-on expertise in both AWS and Microsoft Azure, including native security services (e.g., AWS GuardDuty, Security Hub, IAM Identity Center; Microsoft Defender for Cloud, Sentinel, Entra ID)

- Strong knowledge of IAM, zero trust architecture, network security, encryption, and secrets management in cloud environments

- Practical experience securing AI/ML systems or LLM-based applications, or demonstrable working knowledge of AI security frameworks (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF)

- Proficiency in at least one scripting/programming language (Python preferred) and infrastructure-as-code tooling

- Experience with container and orchestration security (Docker, Kubernetes, EKS/AKS)

- Solid understanding of DevSecOps practices and CI/CD security integration

- Hands-on experience supporting compliance programs such as HIPAA, HITRUST CSF, PCI DSS, and SOC 2 in cloud environments, including audit evidence and control implementation

- Proficiency in Microsoft Office Suite

- Strong interpers

← All remote jobs