Xcel Energy is hiring a Security Engineer – Cloud Security (AWS) for a hybrid role in Denver, CO. You will build and run the AWS cloud security program with a focus on reducing risk through visibility, guardrails, and automation. This position emphasizes clear ownership, cross-team collaboration, and actionable risk communication, while operational logging and monitoring ownership is handled by SOC/IR teams.
What you’ll do
- Build and mature the AWS cloud security program with defined ownership, processes, and workflows.
- Identify, prioritize, and communicate cloud security risk across commercial, GovCloud, dev, and test AWS accounts.
- Implement preventative controls and guardrails to reduce risk before deployment.
- Use automation and integrations to reduce manual effort and improve consistency across security workflows.
- Drive remediation by routing findings to the appropriate owners and tracking outcomes.
- Serve as the primary cloud security engineer for AWS environments, including support for enterprise visibility into IAM, network configuration, logging, monitoring, and workload security posture.
- Identify security issues such as overly permissive access, unused accounts, misconfigurations, and exposure risks.
- Develop and implement guardrails, policies, and controls to prevent insecure configurations and reduce attack surface.
- Promote hardened images, containers, and standardized builds to reduce deployment-time risk.
- Integrate cloud security findings into existing workflows and coordinate remediation with responsible teams.
- Collaborate with Cloud Platform, SAP, Enterprise Architecture, and other groups to deliver security improvements.
- Partner with Application Security to support DevSecOps practices, including CI/CD pipeline integration, gates, and automation.
- Support SAP cloud security needs and maintain awareness of SAP-specific risks within AWS environments.
- Use APIs, scripting, and automation to streamline data collection, analysis, and workflow execution.
- Leverage AWS native security capabilities such as Inspector and Security Hub (and related services) to identify and analyze risk.
- Support setup and integration of logging and monitoring capabilities while deferring operational ownership to SOC/IR teams.
What you bring
- Minimum 5 years of experience in information security.
- Strong hands-on experience with AWS cloud environments and cloud security concepts.
- Strong understanding of AWS IAM, networking, logging, monitoring, and workload security.
- Experience using AWS native security tools such as Inspector, Security Hub, or equivalent.
- Strong understanding of DevSecOps principles, CI/CD pipelines, and application security fundamentals.
- Basic understanding of SAP environments in cloud-hosted architectures.
- Experience identifying and communicating risk related to cloud configurations and architecture.
- Strong analytical and complex technical problem-solving skills.
- Ability to communicate technical risk clearly to non-technical stakeholders.
- Experience with APIs, scripting, or automation for data integration and workflow execution.
- Ability to operate independently and build a program with limited oversight.
Preferred qualifications
- Experience across multiple cloud environments, including AWS multi-account and GovCloud architectures.
- Experience supporting Azure cloud environments.
- Experience implementing preventative security controls such as guardrails, policy enforcement, or pipeline gating.
- Experience improving data quality and visibility across multiple cloud and security data sources.
- Experience working with enterprise cloud platform, networking, or architecture teams.
Tools & technologies
AWS, Inspector, Security Hub, IAM, CI/CD pipelines, DevSecOps, APIs, scripting, automation, containers, SAP, Azure, GovCloud
Certifications
- AWS Certified Security – Specialty (required)
- AWS Certified Solutions Architect – Professional or AWS Certified DevOps Engineer – Professional (preferred)
Compensation & location
Salary: USD 97,600 - 138,600 per year.
Location: Hybrid role requiring three days per week in the office. Must be located within Xcel Energy territory and reasonably close to an Xcel Energy facility. Denver, Colorado and Minnesota areas preferred.
Benefits
- Annual Incentive Program
- Medical/Pharmacy Plan
- Dental
- Vision
- Life Insurance
- Dependent Care Reimbursement Account
- Health Care Reimbursement Account
- Health Savings Account (HSA) (if enrolled in eligible health plan)
- Limited-Purpose FSA (if enrolled in eligible health plan and HSA)
- Transportation Reimbursement Account
- Short-term disability (STD)
- Long-term disability (LTD)
- Employee Assistance Program (EAP)
- Fitness Center Reimbursement (if enrolled in eligible health plan)
- Tuition reimbursement
- Transit programs
- Employee recognition program
- Pension
- 401(k) plan
- Paid time off (PTO)
- Holidays
- Volunteer Paid Time Off (VPTO)
- Parental Leave