Cloud Security Operations Engineer
San Jose, CA - USA
Job Summary
Job Title: Cloud Security Operations Engineer
Location: San Jose California
Reports to: Senior Cloud Security Architect
Job Overview:
We are seeking a skilled and passionate Cloud Security Operations Engineer to join our dynamic Information Security this role you will be responsible for designing implementing and maintaining robust security controls across our public cloud environments including AWS Azure GCP and IBM Cloud. As a hands-on technical expert you will play a crucial role in enhancing our cloud security posture with a primary focus on data protection and incident management. This position offers the opportunity to work in a collaborative environment where you will contribute to the security and resilience of our cloud infrastructure.
Job Responsibilities:
1. Secure Architecture and Engineering
Design and deploy secure reference architectures across multi-cloud environments.
Integrate security into Infrastructure-as-Code (IaC) using tools like Terraform CloudFormation and ARM Templates.
Implement cloud-native security controls: VPCs WAFs DDoS and endpoint protections.
Ensure data protection via encryption KMS/HSM and DLP policies.
2. Identity and Access Management (IAM)
Design implement and audit IAM policies roles service accounts and federation models using least-privilege principles.
Configure MFA SSO and PAM solutions for secure cloud access.
3. Monitoring Detection and Response
Configure and maintain cloud-native security tools (e.g. AWS Security Hub Microsoft Defender for Cloud Google Security Command Center).
Integrate cloud logs with SIEM systems for threat detection.
Lead incident response efforts for cloud-related security events.
Continuously monitor cloud environments using CSPM CNAPP and cloud-native security tools to identify prioritize and remediate security misconfigurations and policy violations.
Track and manage cloud security findings through remediation workflows.
Partner with Cloud Platform Infrastructure and Application teams to coordinate remediation of identified security risks and vulnerabilities.
Conduct root cause analysis of recurring cloud security issues and recommend preventive controls and automation improvements.
4. Cloud Data Loss Prevention (DLP) Management
DLP Alert Triage and Investigation: Monitor triage and investigate all DLP alerts and events. Differentiate between policy violations potential insider threats and false positives escalating confirmed incidents to the Incident Response team.
Tool Optimization and Tuning: Serve as the subject matter expert (SME) for Cloud DLP tools (e.g. Microsoft Purview Google DLP dedicated CASB solutions). Continuously tune policies and rulesets to minimize alert fatigue while maintaining high fidelity.
Reporting and Compliance: Generate regular reports on DLP effectiveness policy violations and risk trends for leadership and compliance/audit teams (e.g. SOC 2 HIPAA GDPR).
Data Classification Integration: Collaborate with Governance Risk and Compliance (GRC) teams to ensure DLP policies align with the corporate data classification framework.
5. Automation and DevSecOps
Develop automation scripts (Python PowerShell Bash) and serverless functions (AWS Lambda Azure Functions Google Cloud Run).
6. Cloud Security Posture Management & Compliance
Continuously assess AWS Azure and GCP environments using CSPM platforms to identify misconfigurations excessive permissions exposed resources compliance gaps and other security risks.
Develop maintain and enforce cloud security baselines aligned with industry standards regulatory requirements and organizational security policies.
Perform periodic cloud security assessments and audits using CIS Benchmarks CSA Cloud Controls Matrix (CCM) NIST and internal security standards.
Drive remediation of findings identified through CSPM monitoring security assessments audits compliance reviews and risk assessments.
Support internal and external audits by providing cloud security evidence compliance reporting and remediation status updates.
7. Secure Access and Network Security Controls
Enforce secure access patterns by eliminating unnecessary public exposure and implementing private endpoints bastion hosts AWS Systems Manager Session Manager and least-privilege network segmentation.
Enforce private connectivity architectures by leveraging:
AWS PrivateLink
Azure Private Endpoints
Google Private Service Connect
Eliminate unnecessary public exposure of cloud workloads services and management interfaces.
Design and maintain least-privilege network segmentation and cloud-native firewall controls across multi-cloud environments.
8. Cloud Workload Security and Hardening
Establish and maintain secure cloud operating system baselines using CIS Benchmarks and vendor-recommended hardening standards.
Perform periodic reviews and validation of operating system virtual machine and container security configurations.
Collaborate with Infrastructure and Platform teams to implement hardened images and golden image standards.
Monitor and remediate deviations from approved OS hardening baselines.
Job Qualifications:
Technical Expertise
Deep knowledge of at least one cloud platform (AWS Azure or GCP).
Proficiency in scripting: Python (preferred) PowerShell Unix shell scripting.
Strong understanding of networking and cloud-native network security.
Experience with CSPM/CNAPP platforms such as CloudGuard Dome9 Wiz Prisma Cloud Microsoft Defender for Cloud or similar solutions.
Strong knowledge of CIS Benchmarks CSA Cloud Controls Matrix (CCM) NIST and industry cloud security best practices.
Familiarity with securing OS and containerized environments (Docker Kubernetes).
Experience implementing secure cloud network architectures private endpoints bastion access patterns and zero-trust security principles.
Experience supporting cloud compliance audit readiness and regulatory assessments.
Education & Certification
Bachelors degree in computer science Information Security or related field (or equivalent experience).
Preferred Certifications:
AWS Certified Solutions Architect Associate
AWS Certified Security Specialty
Microsoft Certified: Azure Administrator Associate
Microsoft Certified: Azure Security Engineer Associate
Google Cloud: Associate Cloud Engineer
Google Cloud: Professional Cloud Security Engineer
(ISC)² Certified Cloud Security Professional (CCSP)
(ISC)² Certified Information Systems Security Professional (CISSP)
Soft Skills
Strong analytical and problem-solving abilities.
Excellent communication and collaboration skills especially with DevOps and engineering teams.
Cadence is committed to equal employment opportunity and employment equity throughout all levels of the organization. We strive to attract a qualified and diverse candidate pool and encourage diversity and inclusion in the workplace.
Travel: N/A
The hourly range for California is $57.21 to $106.25 per hour. You may also be eligible to receive incentive compensation: bonus equity and benefits. Please note that the hourly range is a guideline and compensation may vary based on factors such as qualifications skill level competencies and work location. Our benefits programs include: paid vacation and paid holidays 401(k) plan with employer match employee stock purchase plan a variety of medical dental and vision plan options and more.
Required Experience:
IC
About Company
Do you want to shape the future of technology? Cadence is leading the charge to solve some of technology’s toughest challenges. We work with the world’s most innovative companies, across a growing range of industries. Major trends that you hear about everyday – like artificial intell ... View more