Cloud Security Engineer
Application Security
Cloud Security
Cloud Security Posture Management
Cyber Security
Engineer
Identity and Access Management
Incident Response
Information Security
InfoSec
Security
Security Automation
Security Compliance
Security Information And Event Management
Security Monitoring
Security Operations
Security Standards
Security Testing
Software Security
Job Description
Tulip Interfaces is a security-focused team building cloud protections that directly shape product and culture. This hybrid role in Boston, MA offers company equity and a benefits package designed to support your health, family, and long-term growth, including health, dental, and vision coverage, flexible spending, parental leave, a 401(K), flexible work scheduling, and an unlimited vacation policy. You will help strengthen security engineering across cloud security, detection and alerting, vulnerability management, and compliance support, with hands-on work primarily in AWS.
What you’ll do
- Design, build, and maintain security controls as code across cloud environments, including posture hardening and account-level guardrails.
- Own vulnerability management end-to-end: triage findings across environments, prioritize to reduce noise, and drive remediation through to closure.
- Run the recurring alert-review workflow, tuning detections, reducing false positives, and improving coverage over time.
- Build and maintain log ingestion and SIEM pipelines, and participate in incident response work.
- Partner with engineering and product teams on architecture, authentication, and application security reviews, including code review and automated testing.
- Support FedRAMP and other compliance efforts through documentation upkeep, alert monitoring, evidence collection, training exercises, and customer security questionnaires.
What you bring
- 5+ years of security engineering experience with hands-on ownership of cloud security work.
- Deep, hands-on experience securing AWS and/or Azure environments, including containerized and Kubernetes workloads (EKS/AKS).
- Ability to build and manage security controls as code using Terraform and Python (or similar).
- Experience authoring and tuning detections and SIEM rules, and running vulnerability and container-image scanning in CI.
- Working knowledge of compliance frameworks such as FedRAMP, ISO 27001, or SOC 2, including evidence practices.
- Nice to have: incident response or forensics experience, threat modeling of new services, or running internal security exercises.
- Education: Bachelor's degree in a technical field, or equivalent working experience.
Tools you’ll work with
AWS, Azure, EKS, AKS, Terraform, Lambda, Python, Kubernetes, SIEM, FedRAMP, ISO 27001, SOC 2
Collaboration
- Infrastructure and Product Engineering
- IT, Legal & Compliance, and Product Management
- Engineering and Security leadership
Benefits
- Company equity
- Health, Dental, Vision
- Short-term Disability
- Long-term Disability
- Life Insurance, AD&D Insurance
- Flexible Spending Account (FSA)
- Commuter Benefits
- Parental Leave
- 401(K)
- Flexible work schedule
- Unlimited vacation policy
- Learning & Development program
- Virtual company events and happy hours
- Fitness subsidies
- Inclusive, dog-friendly office
- Direct impact on product and culture