Career Opportunities

Senior Engineer, Cloud Security

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.


Get to Know the Security Services Team


We are the team that turns complex security requirements and compliance frameworks into infrastructure and services that actually work. Moving fast and taking true end-to-end ownership, our team spans three core functions: Cloud Security Engineering, where we design hardened AWS, Azure, and GCP environments, write Terraform baselines, and fix failing controls to meet frameworks like SOC 2, ISO 27001, CMMC, and FedRAMP; Penetration Testing, where we run disciplined offensive assessments across networks, apps, cloud, and AI/LLM systems to catch vulnerabilities before adversaries do; and Vulnerability Management, where we continuously prioritize, patch, and validate risk reduction across the client footprint. We do not hide behind process or just point out gaps. We step in, build solutions, and deliver real security posture improvements with minimal disruption.


What makes this team special isn't just our technical depth; it is how we back each other up. Our strongest engineers and assessors are the ones building reusable modules, writing custom tools, jumping into channels to unblock teammates, and mentoring without being asked. From early-stage startups to regulated enterprises, you will work directly with clients, take on real ownership early, and be surrounded by people who want to see you get good. If you enjoy solving tough security problems and want to be part of a team that is scrappy enough to move fast but seasoned enough to get it right, you will be in good company here. 

The Opportunity 

Workstreet is seeking a Senior Engineer, Cloud Security who is a builder at heart with deep technical expertise in cloud infrastructure engineering, with a strong emphasis on Azure and multi-cloud architectures. This is a hands-on, high-impact engineering role focused on designing and deploying security infrastructure, building hardened landing zones, automating identity lifecycles, and authoring reusable Terraform modules rather than performing audit assessments.

The successful candidate will integrate rapidly into client environments, taking direct ownership of cloud security engineering tasks, vulnerability remediation, and client engagements within their first 15 days. Working directly with client engineering leads during U.S. Eastern Time business hours, you will lead technical discussions, execute automated security operations, and ensure every environment achieves drift-resistant, code-defined security excellence.

What You'll Do

  • Engineer security via Infrastructure as Code - design and maintain reusable Terraform and CloudFormation modules for IAM, networking, and logging to build drift-resistant cloud environments.
  • Build enterprise cloud architectures - deploy and manage AWS multi-account structures including Organizations and SCPs, alongside Azure Hub-Spoke and Landing Zone architectures.
  • Architect identity and access management - implement least-privilege IAM using RBAC, ABAC, permission boundaries, JIT or PIM automation, and federated identity via Okta or Entra ID.
  • Execute direct vulnerability remediation - remediate cloud misconfigurations through active engineering changes, automated patching, and configuration drift correction.
  • Automate security operations and pipelines - build automated remediation workflows using Lambda, Azure Functions, and Python, integrating SAST, DAST, and secret scanning into GitHub Actions or Azure DevOps pipelines.
  • Configure native cloud security stacks - deploy and tune AWS GuardDuty, Security Hub, AWS Config, Azure Sentinel, and Defender for Cloud to build native logging pipelines for SIEM ingestion.
  • Manage network and encryption engineering - design VPCs, security groups, network segmentation, WAFs, and full-lifecycle encryption using AWS KMS and Azure Key Vault.
  • Implement technical NIST 800-53 controls - translate NIST 800-53, FedRAMP, and CMMC compliance criteria into hands-on technical controls across cloud environments.
  • Drive client-facing technical ownership - interface directly with client engineering teams, lead architectural workshops, and manage multiple client engagements simultaneously.

Who You Are

  • Hands-on security builder - proven track record of deploying security infrastructure, writing OPA policies, and managing secrets in Vault or AWS Secrets Manager.
  • Cloud-native technical specialist - deep expertise in Azure and AWS nuances, capable of distinguishing compliance maps from functional technical controls.
  • Infrastructure as Code expert - proficient in Terraform, with demonstrated expertise in module versioning, state management, and provider security controls.
  • Identity and access authority - deep technical understanding of SAML, OIDC, cross-account IAM roles, and enforcing least privilege without disrupting developer workflows.
  • Articulate technical communicator with a strong verbal presence, able to lead technical workshops and clearly explain complex architecture to engineering teams.
  • Multi-account portfolio operator - thrives in fast-paced startup environments, balancing multiple client priorities and executing rapid remediation without perfect documentation.

What will help you succeed

  • Active cloud security credentials - hold technical certifications such as AWS Certified Security Specialty, Azure Security Engineer Associate, or GCP Professional Security Engineer.
  • FIPS 140 encryption implementation: practical experience configuring and enforcing FIPS 140 standards across cloud services.
  • Federal enclave build experience - hands-on history building CMMC-compliant enclaves or FedRAMP security architectures.
  • Container runtime security mastery - experience implementing runtime security controls and vulnerability scanning across containerized environments.

What We Offer 

  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.

What You'll Need to Thrive 

  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.

Hiring and Selection Process 

  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.

Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.


All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact accommodationsus@workstreet.com 


Delivery

Remote (United States)

Partilhar em:

Termos de serviço.PrivacidadeCookiesDesenvolvido pela Rippling