Cloud Security Specialist - Platform Engineering

Burlingame, CA, US • Posted 2 hours ago • Updated 2 hours ago
Full Time
On-site
USD $153,000.00 - 178,000.00 per year
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Real-time
  • Satellite
  • Global Positioning System
  • FOCUS
  • Hardening
  • Identity Management
  • Authentication
  • Authorization
  • Computer Networking
  • Regulatory Compliance
  • NIST SP 800 Series
  • Threat Modeling
  • Incident Management
  • Root Cause Analysis
  • DevOps
  • Security Operations
  • Google Cloud Platform
  • Google Cloud
  • Microsoft Azure
  • Amazon Web Services
  • CISSP
  • Kubernetes
  • Security Controls
  • RBAC
  • Network
  • Scripting
  • Python
  • Continuous Integration
  • Continuous Delivery
  • Bill Of Materials
  • Event Management
  • SIEM
  • Cloud Security
  • Management
  • Cloud Computing
  • Security Clearance
  • PASS
  • Security Analysis
  • ITAR

Summary

Xona is the navigational intelligence company bringing real-time, centimeter-level certainty to any device, anywhere on Earth.

With Pulsar - the world's most advanced PNT satellite infrastructure in Low Earth Orbit - Xona will offer a future-proof, backwards-compatible global positioning system optimized for absolute precision, superior power, and robust protection.

Overview

We are looking for a Cloud Security Engineer to embed security into the core of our Platform Engineering team. In this role, you will design, implement, and automate security guardrails across our AWS infrastructure and deployment pipelines. Rather than acting as a traditional compliance gatekeeper, you will focus on building secure defaults, automated policy enforcement, and self-service security tools that empower engineering teams to move fast without compromising safety.

Working closely with architecture, DevOps, and enterprise security, you will deliver secure foundational services, automate compliance, and help maintain high security standards across the entire engineering organization.

Key Responsibilities
  • Cloud Security Architecture & Hardening: Design and enforce secure cloud patterns, zero-trust network segmentation, and hardening standards across our AWS multi-account architecture and container platforms (e.g., Kubernetes).
  • Identity and Access Management (IAM): Architect secure authentication, authorization, secrets management, and zero-trust networking principles across all platform services.
  • Automation & Guardrails: Build automated security guardrails that empower developers to move fast safely, minimizing friction while maintaining strict compliance standards (e.g., CMMC, NIST 800-171).
  • Threat Management & Incident Response: Conduct regular security assessments and threat modeling. Partner with SRE and operations teams to monitor security telemetry, triage cloud threats, and participate in incident response and root-cause analysis.

Qualifications & Requirements
  • Experience: 4+ years of experience in cloud security, DevOps, or platform engineering, with a strong emphasis on security operations and architecture.
  • Cloud Expertise: Deep hands-on experience securing cloud environments (AWS, Google Cloud Platform, or Azure). Certifications such as AWS Certified Security, CISSP, or CCSK are a plus.
  • Container & Kubernetes Security: Strong understanding of containerization security best practices, and Kubernetes security controls (RBAC, network policies, runtime security).
  • Scripting & Automation: Proficiency in languages such as Python, Go, etc. and experience with automation tools.
  • Security Tooling: Familiarity with CI/CD security integrations, Software Bill of Materials (SBOM), Security Information and Event Management (SIEM), and cloud security posture management (CSPM) tools.

Preferred Qualifications
  • Experience implementing Zero Trust architectures within a modern enterprise.
  • Familiarity with Policy-as-Code frameworks (e.g., Open Policy Agent).
  • Demonstrated passion for developer enablement and building "security as a product" rather than a roadblock.
  • Hands-on experience running offensive security scenarios or red-team exercises for distributed, highly available cloud environments.



For U.K. Roles: To comply with U.K. regulations, this role requires Baseline Personnel Security Standard (BPSS) checks, and successful candidates must be eligible to obtain UK Security Clearance (SC).

For Canada Roles: Successful candidates must obtain and hold a security clearance at the reliability status level, and pass security assessment for the Canadian Controlled Goods Program (CGP) and ITAR.

We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 80183772
  • Position Id: 4c0338b98fd629f7a0ceb2c751afd034
  • Posted 2 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

San Francisco, California

3d ago

Full-time

USD 166,600.00 - 208,300.00 per year

San Mateo, California

Today

Full-time

Sunnyvale, California

Today

Full-time

USD 169,000.00 - 224,000.00 per year

San Mateo, California

24d ago

Full-time

USD 180,000.00 - 220,000.00 per year

Search all similar jobs