Principal Cloud Security Engineer
Aws Security
Azure Security
Cloud
Cloud Infrastructure
Cloud Platform
Cloud Platforms
Cloud Technology
Cybersecurity Tools
DevOps
DevSecOps
Engineer
Google Cloud Security
Identity and Access Management
Information Security
InfoSec
Infrastructure As Code
Risk Management
Security Automation
Security Compliance
Security Standards
Solution Architecture
Job Description
The Principal Cloud Security Engineer will help secure Rocket Lab’s cloud footprint across vendor services, code pipelines, and automation. This onsite role in Long Beach, CA focuses on building and maintaining security controls, performing risk-focused assessments, and supporting IAM, compliance, incident response, and DevSecOps/MLOps practices.
Role Focus
Own the design, development, and ongoing maintenance of security controls for hybrid cloud environments, spanning IaaS, PaaS, SaaS, and FaaS. Partner with teams across development and operations to reduce risk in public cloud deployments, CI/CD pipelines, and agentic systems while strengthening overall security posture.
Responsibilities
- Design, implement, and maintain security controls for hybrid cloud-based environments, including IaaS, PaaS, SaaS, and FaaS solutions.
- Design and develop custom automation aligned with the cyber team objectives.
- Provide security support for internal and external design reviews related to security.
- Conduct security assessments and risk analyses to identify vulnerabilities and develop mitigation strategies for automated infrastructure such as public cloud, CI/CD pipelines, and agentic systems.
- Collaborate with Infrastructure Operations to implement and manage identity and access management (IAM) solutions for controlling access to cloud resources and applications.
- Develop documentation, plans, and proofs of concept for cybersecurity-related platform improvements.
- Configure and monitor cloud security tools and services.
- Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC), DevOps, and MLOps processes.
- Maintain systems to stay current on emerging threats, vulnerabilities, and DevSecOps/MLOps industry best practices, and recommend proactive measures to enhance security posture.
- Provide guidance and support to internal teams on security-related matters, including incident response, compliance, and security awareness training.
- Participate in regular security audits, assessments, and compliance reviews to ensure adherence to regulatory requirements and industry standards.
Requirements
- 12+ years of experience in scripting languages (for example: Bash, PowerShell, Python) and configuration management and infrastructure as code tools (for example: Puppet, Ansible, Terraform).
- Bachelor’s degree or equivalent years of work experience (16+ years of total work experience).
- Proven experience in cloud security architecture, design, and implementation across major cloud platforms (AWS, Azure, Google Cloud).
- Hands-on experience with cloud security tools and services, such as AWS Security Hub, Azure Security Center, and Google Cloud Security Command Center.
- Experience operating within US Government compliance regimes, including CMMC, NIST, and DISA STIG, along with ITIL/Change Review systems.
- Proficiency in vulnerability management systems (for example: Tenable, Bringa) and CLI scanning tools (for example: Trivy, OpenSCAP).
- Extensive experience with git-driven version control systems (for example: GitHub, GitLab, Bitbucket).
- Strong understanding of networking concepts, encryption techniques, and secure communication protocols.
- Experience with databases (for example: PostgreSQL, SQLite) and data formats (for example: Parquet, Arrow).
- Proficiency in analytics systems (for example: PowerBI, Jupyter) and vendor-agnostic assessment engines (for example: Cloud Custodian, Panther).
- U.S. citizenship is required due to program requirements.
Nice to Have
- Advanced degree in computer science, information technology, cybersecurity, or equivalent career experience.
- Involvement with community cybersecurity organizations.
- Experience with AWS GovCloud / Azure GCC High.
- Experience with CI/CD pipeline security.
- Experience with Tier 2 cloud vendors.
- Experience with hybrid cloud engineering.
- Experience with SAST and DAST testing.
- Experience with secrets management tools such as vaults and HSMs.
- Experience with cloud incident response and forensics.
- Experience with log aggregators such as Graylog, ELK, or Splunk.
Technologies
- Bash, PowerShell, Python, Puppet, Ansible, Terraform
- AWS, Azure, Google Cloud
- AWS Security Hub, Azure Security Center, Google Cloud Security Command Center
- CMMC, NIST, DISA STIG, ITIL
- Tenable, Bringa, Trivy, OpenSCAP
- GitHub, GitLab, Bitbucket
- PostgreSQL, SQLite, Parquet, Arrow
- PowerBI, Jupyter, Cloud Custodian, Panther
- IaaS, PaaS, SaaS, FaaS, CI/CD, SDLC, DevOps, MLOps, DevSecOps, IAM
Compensation and Location
- Location: Long Beach, CA (onsite)
- Salary: USD 152,300 - 165,000 per year
Additional Information
- For US offices: Rocket Lab employees must be a U.S. citizen, lawful U.S. permanent resident (current Green Card holder), lawfully admitted into the U.S. as a refugee or granted asylum, or eligible to obtain required authorizations from the U.S. Department of State and/or the U.S. Department of Commerce, as applicable.
- Reasonable accommodation requests for the application/interview process in the United States should be directed to Giulia Johnson at [email protected].
- A response to your request may take up to two business days.
- For New Zealand offices: background checks will be undertaken prior to employment offers, including nationality checks, due to eligibility requirements tied to equipment and data regulated by the United States' International Traffic in Arms Regulations.
- Under those regulations, eligibility may be limited based on citizenship or ineligible dual citizenship or nationality.
Similar Jobs
S