Security Engineer, Cloud
New York City • FullTime
Posted 16h ago
Remote Work Policy
On-site
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Rogo is seeking a Security Engineer to lead the design and implementation of cloud security architecture across AWS and GCP. This is a hands-on role for an engineer experienced in building and operating secure cloud platforms at scale, utilizing code, systems design, and automation to solve security challenges. The successful candidate will own the technical direction of cloud security, designing secure primitives, authoring Terraform, shaping identity and network architecture, and embedding security into the core platform. This senior technical leadership position requires tactical execution, including writing production code, reviewing infrastructure changes, and providing pragmatic security solutions.
Responsibilities
- Architect and implement cloud security foundations across AWS and GCP, including account structure, IAM, network segmentation, and secure service-to-service communication.
- Author Terraform-based security architecture, including reusable modules for IAM, networking, logging, and encryption.
- Implement policy enforcement and guardrails to prevent insecure infrastructure deployment.
- Design and operate cloud identity systems at scale, covering workload identity, service accounts, role assumption, and cross-cloud access.
- Lead the security design of cloud networking, including VPC architecture, private connectivity, egress control, and firewalling.
- Build and maintain security automation across CI/CD and cloud environments.
- Own Kubernetes and container security for production workloads (GKE/EKS), including cluster hardening, RBAC, workload identity, image security, and runtime controls.
- Define and implement logging, monitoring, and detection pipelines for cloud security posture and incidents.
- Perform threat modeling and architectural reviews for new infrastructure and platform changes.
- Review critical infrastructure changes, mentor engineers, and improve organizational security standards.
Requirements
- Experience building cloud security platforms or foundational infrastructure in AWS and GCP.
- Deep fluency in Terraform, including large-scale state management, module design, and safe rollout strategies.
- Experience thinking in terms of secure systems and primitives.
- Strong opinions on cloud IAM and networking design, informed by real-world failures and incident response.
- Comfort operating in ambiguous environments and defining long-term technical direction.
- Preference for automation, code, and guardrails over documentation and manual review.
- Ability to influence architecture through technical depth.
- Experience designing multi-account AWS organizations or large GCP project hierarchies (bonus).
- Familiarity with policy-as-code systems (OPA, custom policy engines) (bonus).
- Experience with cloud-native detection and posture tools (bonus).
- Background in high-growth startups or infrastructure-heavy platforms (bonus).