What are the responsibilities and job description for the Cloud Security Engineer position at MOHR Talent?
Compensation: $130,000 Bonus
Position Overview
We are seeking a Cloud Security Engineer with hands-on technical experience securing cloud platforms and modern application environments. This role will focus on implementing and improving cloud security controls, monitoring and responding to security findings, supporting compliance initiatives, and partnering with engineering and project teams to integrate security into cloud and application workflows.
The environment is primarily based within Google Cloud Platform (GCP), with a smaller Azure footprint supporting a subset of applications.
The ideal candidate is a hands-on engineer who can solve technical security challenges across cloud infrastructure, Identity and Access Management (IAM), data and workload protection, and DevOps/CI/CD processes.
Success in this role requires strong collaboration and communication skills, as this individual will work closely with infrastructure, platform, application, and security teams to improve security while enabling business objectives.
Key ResponsibilitiesCloud Security Implementation- Implement and maintain cloud security controls across GCP and Azure environments, including projects, subscriptions, and organizational structures.
- Assist with the design, deployment, and continuous improvement of cloud security guardrails, baseline configurations, and policy enforcement mechanisms.
- Support Identity and Access Management initiatives, including:
- Least-privilege access
- Privileged account and identity management
- Service account governance
- Identity federation
- Zero-trust principles
- Secure cloud services, workloads, and data platforms through configuration reviews, hardening activities, and security best practices.
- Work with technologies including:
- VPC Service Controls
- Network Security Groups
- Cloud Storage
- GKE
- BigQuery
- Cloud SQL
- Pub/Sub
- Cloud Functions
- Cloud Run
- Support container and workload security initiatives, including hardened container images, CVE scanning, and secure deployment practices.
- Support encryption, key management, and data protection controls across cloud environments.
- Contribute to security automation using Infrastructure as Code, scripting, and cloud-native tooling.
- Integrate and maintain cloud-native and third-party security tools to improve visibility, posture management, and threat detection.
- Support the implementation of security controls within CI/CD pipelines, including:
- Vulnerability scanning
- Secrets detection
- Policy validation
- DevSecOps controls
- Assist development teams with secure cloud architecture patterns and application deployment practices.
- Monitor and tune cloud security alerts, vulnerabilities, and findings from cloud-native and third-party CSPM and CNAPP tools.
- Investigate suspicious activity, misconfigurations, exposed secrets, and potential security incidents.
- Support incident response involving cloud resources, identities, workloads, applications, and data.
- Perform root cause analysis and recommend remediation actions following security events.
- Validate remediation efforts and improve monitoring coverage based on lessons learned from incidents and investigations.
- Support cloud security assessments and control reviews against established frameworks and organizational standards, including:
- CIS Benchmarks
- NIST 800-53
- PCI-DSS
- Assist with vulnerability management activities, including identification, prioritization, remediation tracking, and validation.
- Participate in cloud security posture reviews and continuous improvement initiatives using CNAPP and CSPM technologies.
- Support audit requests, evidence collection, and documentation related to cloud security controls.
- Execute security assessments of:
- Cloud workloads
- Data storage
- Network segmentation
- CI/CD processes
- Partner with infrastructure, platform, application development, and security teams to promote secure cloud adoption and DevSecOps best practices.
- Provide guidance on secure cloud architecture, infrastructure-as-code, identity management, and cloud-native services.
- Assist development teams with identifying and remediating cloud and application security issues throughout the Software Development Life Cycle.
- Contribute to the development of cloud security standards, procedures, technical documentation, and operational runbooks.
- 3 years of experience in cloud security, cybersecurity, cloud engineering, DevSecOps, or a related technical field.
- Hands-on experience with Google Cloud Platform security services and concepts.
- Experience securing cloud workloads, identities, applications, and data services.
- Familiarity with cloud security monitoring, vulnerability management, and incident response.
- Strong understanding of:
- IAM
- Encryption
- Logging
- Threat detection
- Vulnerability management
- Secure application deployment
- Familiarity with application security concepts such as:
- Secrets management
- Dependency scanning
- Vulnerability remediation
- Secure coding principles
- Strong analytical, troubleshooting, and communication skills.
- Ability to work effectively with both technical and non-technical stakeholders.
- Relevant cloud or security certifications such as:
- Google Professional Cloud Security Engineer
- Azure Security Engineer Associate (AZ-500)
- Security
- Equivalent certifications
- Familiarity with CNAPP and CSPM tools.
- Experience with container security, Kubernetes security, and secure software supply chain practices.
- Exposure to application security tools and processes such as:
- SAST
- DAST
- Dependency scanning
- Secrets detection
- Software Composition Analysis
- Secure code review
- Familiarity with security frameworks such as CIS Benchmarks, NIST 800-53, PCI-DSS, or ISO 27001.
- Experience with scripting and automation using Python, PowerShell, Bash, or similar languages.
- Strong troubleshooting and analytical mindset with excellent attention to detail.
- Comfortable working in fast-moving cloud environments with minimal supervision.
- Strong communication skills across technical and non-technical teams.
- Proactive and accountable, with the ability to identify risks before failures occur
MOHR Talent is an equal-opportunity employer and complies with all applicable federal, state, and local nondiscrimination laws. We provide equal employment opportunities regardless of race, color, religion, sex, national origin, age, disability, marital status, sexual orientation, gender identity, genetic information, military/veteran status, or any other protected status. If you believe you have been discriminated against or have concerns about our compliance, please contact our Human Resources department at hr@themohrgrp.com