Cloud Security Engineer
Department:
Job Summary
HappyRobot is the infrastructure for enterprises to build and orchestrate AI workforces. Our AI workers dont just communicate through voice and email - they make decisions take action and run operations autonomously across entire enterprise systems. Born in Y Combinator (S23) and backed by a16z Base10 Prysm Capital and Eurazeo with over $150M raised we power critical operations for global enterprises worldwide.
Our platform is battle-tested in the most demanding environments where AI has real consequences. We started in logistics built our own voice stack models and orchestration layer from the ground up and are now bringing that infrastructure to every enterprise that runs the real economy. Learn more about our vision in our manifesto.
We are looking for a Cloud Security Engineer to join our team. You will be the single accountable owner for cloud security posture across AWS Azure and GCP bringing the technical depth and operational discipline to keep our infrastructure hardened our findings remediated on SLA and our security baseline consistent across every environment we run.
This is not a governance or advisory role. Your deepest strength is the ability to own outcomes end-to-end: triaging Wiz findings by real-world exploitability shipping policy-as-code gates that catch misconfigurations before they hit production and getting remediation done by engineering teams you dont manage. That said you operate with a platform mindset building guardrails that scale rather than manually reviewing every change.
What Youll Do
Cloud Posture Management Own the CNAPP end-to-end. Triage Wiz findings by exploitability and business impact drive remediation across engineering teams to SLA and keep the backlog from accumulating. Be the person who actually gets findings closed not just reported.
IaC Security Design and ship policy-as-code gates in the Terraform pipeline that block misconfigurations at PR and plan time before they reach production. Use OPA/Rego Checkov tfsec or equivalent and calibrate gates to stop bad patterns without creating friction that causes teams to route around them.
Multi-Cloud Baseline Define document and enforce a consistent security baseline across AWS Azure and GCP covering IAM networking KMS/encryption and logging. Own the documentation that supports enterprise customer security reviews and audit evidence requests.
Kubernetes & Container Security Harden clusters images and admission paths across EKS AKS and GKE. Set and enforce RBAC policies admission controls and image scanning standards.
Remediation Leadership Drive fixes through engineering teams you dont have direct authority over. Track SLAs communicate risk clearly to technical and non-technical stakeholders and escalate when needed without creating noise.
Shift-Left Guardrails Grow the share of cloud infrastructure managed via Terraform with active security checks quarter over quarter. Trend new critical misconfigurations reaching production to zero.
Must Have
46 years in cloud security or platform/infrastructure security.
Expert depth in at least one major cloud provider (AWS Azure or GCP): IAM networking KMS/encryption and logging.
Hands-on experience with a CNAPP/CSPM Wiz strongly preferred including triage prioritization and driving remediation with engineering teams.
Terraform in production plus policy-as-code experience (OPA/Rego Checkov tfsec or similar) integrated in CI/CD.
Kubernetes security fundamentals: RBAC admission control and image scanning.
Scripting proficiency in Python or Go.
English B2 (professional working proficiency).
Nice to Have
Working experience across 2 cloud providers we deploy on AWS Azure and GCP.
Cross-cloud and Kubernetes certifications: CCSK CKA CKS AWS Security Specialty or equivalent.
EKS/AKS/GKE hardening and container runtime security experience.
TypeScript or Go beyond scripting.
SIEM/detection exposure we run RunReveal.
SOC 2 / ISO 27001 cloud control evidence experience.
Join a world-class team of engineers and builders.
Backed by top investors including a16z Y Combinator Base10 Prysm Capital and Eurazeo.
Have ownership and autonomy of projects and are encouraged to ship.
Comprehensive Benefits including healthcare dental vision coverage.
Competitive salary equity in a high-growth startup.
Extreme Ownership
We take full responsibility for our work and outcomes. No excuses no blame-shifting. If something needs fixing we own it.
Craftsmanship
We sweat the details because details compound. We never settle for just fine whether its a scoping document a prototype demo or a customer conversation.
We are Majos
Be a good human. Friendly genuine kind. Were building something ambitious and its better when we enjoy it together.
Urgency with Focus
Move fast but in the right direction. Prioritize ruthlessly. Act decisively. Aim for the highest leverage action.
Talent Density and Meritocracy
Every hire raises the bar. Ability over seniority. Ownership goes to those who earn it.
First-Principles Thinking
Strip problems to their fundamentals ignore industry dogma and rebuild from scratch when needed. Its how we build what others think is impossible.
The personal data provided in your application and during the selection process will be processed by Happyrobot Inc. acting as Data Controller.
By sending us your CV you consent to the processing of your personal data for the purpose of evaluating and selecting you as a candidate for the position. Your personal data will be treated confidentially and will only be used for the recruitment process of the selected job offer.
In relation to the period of conservation of your personal data these will be eliminated after three months of inactivity in compliance with the GDPR and legislation on the protection of personal data.
If you wish to exercise your rights of access rectification deletion portability or opposition in relation to your personal data you can do so through subject to the GDPR.
For more information visit submitting your request you confirm that you have read and understood this clause and that you agree to the processing of your personal data as described.
Required Experience:
IC