Position: Cloud Security Engineer
Location: Boston, MA (On-Site)
Duration: Long Term Contract
Note: W2/1099 only accepted
Job description:
• Have 12+ years of experience in security or infrastructure engineering roles, with demonstrated ownership of enterprise security domains such as SaaS security, IAM, Zero Trust, endpoint security, or cloud-delivered security services
• Approach every project AI-first: you design with AI, refine with AI, and take full responsibility for validating and owning what you deploy — you are not a passive consumer of AI output
• Hands-on by default — you are equally comfortable writing policy-as-code, reviewing architecture, and debugging a production issue
• Proficient with Terraform for building and maintaining infrastructure-as-code across enterprise security systems
• Experienced operating in AWS environments, with strong familiarity with cloud security services, IAM policies, and secure architecture patterns
• Experience with enterprise IdP solutions such as Okta, AWS Cognito
• Experienced with enterprise security tooling such as Cloudflare (WAF, gateway), Wiz (CNAPP/cloud security), and CrowdStrike (EDR/endpoint)
• Knowledgeable in secrets management, JITA, and modern identity patterns including SSO, SCIM, and privileged access workflows including SAML 2.0, SCIM, OAuth and OIDC — note this is not a dedicated IAM role; fluency in these areas supports broader enterprise security ownership, not identity program management
• Experienced mentoring engineers and working through influence: you raise the bar for the people around you and hold team-wide technical standards
• Nice to have: experience with Google Cloud Platform or Azure environments, Spacelift for IaC orchestration, AI agent development, or securing AI coding platforms (e.g., Lovable, Vercel, Cursor)
• Able to work alone or as part of a team working collaboratively with business and technical stakeholders and customers.
• Must have strong communications skills (oral and written).