What are the responsibilities and job description for the Cloud Security Engineer position at American Unit, Inc?
Cloud Security Engineer
Englewood, Colorado
6 Months Contract
Job Description
Principal Public Cloud Security Engineer (Onsite 4 days per week: Candidates must be local to one of the following for a hybrid schedule: Englewood, CO; Charlotte, NC; St. Louis, MO; or Austin, TX.)
In this role, you will lead cloud security engineering efforts and drive secure DevOps practices across large-scale enterprise workloads within a newly established public cloud infrastructure division (GCP environment). This is a high-impact opportunity to define cloud security standards from the ground up, influence architectural direction, and mentor cross-functional teams while helping build the foundation of a secure, scalable public cloud organization.
Ideal candidates will have either deep AWS OR GCP security engineering experience, proven automation skills, and a history of mentoring others. Candidates must be willing to learn the Google Cloud Platform (GCP) if they don’t have any experience.
What You’ll Do
- Lead the design and implementation of secure, scalable GCP environments (IAM, encryption, network security).
- Develop automated guardrails and CI/CD security checks across pipelines and workloads.
- Deploy and tune cloud-native threat detection tools (GuardDuty, Security Hub, WAF, CloudTrail).
- Collaborate with DevOps, Infrastructure, and Compliance teams to align controls with PCI/SOC2/ISO frameworks.
- Drive secure-by-design architecture and mentor engineers on cloud security best practices.
- Contribute to cloud governance strategy and help shape enterprise standards.
- Learn and assist in secure GCP engineering as the team expands its multi-cloud footprint.
What You Bring
- 10–12 years of total engineering experience, including 7–8 in public cloud environments in either GCP OR AWS.
- 4 years of AWS OR GCP security engineering experience (IAM, KMS, VPC).
- 3 years in automation (Terraform/CloudFormation) and CI/CD integration.
- 2 years of Python or similar scripting.
- Familiarity with SIEM/SOAR, container security, and compliance frameworks (PCI, SOC2, ISO).
- Strong communicator who can align engineering and compliance teams toward shared goals.
- AWS Security Specialty or GCP experience is a plus.