Security Engineer - Cloud Security Controls
Job Description
The Security Engineer will join PNC’s Cloud Security team to build and deploy security controls across Azure and AWS public cloud workloads. The role focuses on cloud posture assessment, security testing in CI/CD, and collaboration with cloud, SOC, and Infrastructure as Code teams.
Location
Birmingham, AL (onsite)
Compensation
USD 91,000 - 185,900 per year
Role Overview
This position is responsible for engineering and operating security controls for Azure resources and AWS services. Work includes using Cloud Provider and CSPM tools for posture assessment, leveraging Security as Code (SAC) pipelines and CI/CD to test and deploy controls, and performing workload analysis to support production readiness. The role partners with cloud architects, SOC, Cloud Product, and Infrastructure as Code teams to refine priorities and operationalize controls.
Responsibilities
- Build and test security controls for Azure resources and AWS services
- Validate security control effectiveness and promote controls to production workloads
- Participate in agile team planning sessions
- Engineer and configure CSPM tools to analyze and assess cloud workloads for compliance within a CI/CD environment
- Assess, implement, automate, and document security solutions and processes for Microsoft Azure and AWS
- Provide analysis of workloads to align with operational security requirements before production deployment
- Collaborate with the Cloud Security Product Owner to refine backlog tickets, including priority and sizing
- Automate and orchestrate cloud deployment through CI/CD to integrate enterprise security standards, policies, configurations, and architectures
- Assist DevOps team members with development and operationalization of security
- Support and maintain the security posture of applications seeking deployment into Production
- Provide subject matter expertise for security concepts; maintain technology solutions and deliverables aligned to project timelines
- Work with architecture to determine implementation details (for example, sizing and integration details), onboarding, and operationalization
- Evaluate patches, updates, and ongoing maintenance; determine impacts when new standards are implemented using change control and governance processes
- Develop detailed implementation, configuration, design, and engineering documentation; build and implement solutions
- Coordinate with operational partners to enable day-to-day supportability and transition
- Provide engineering support to production technologies and collaborate with other groups as needed; identify opportunities to expand knowledge beyond core expertise
Required Qualifications
- Deep experience with AWS and/or Azure cloud services in an Enterprise environment
- Thorough understanding of cloud security best practices
- Experience performing security gap analysis on cloud services or cloud infrastructure
- Experience implementing security controls for public cloud workloads in Azure and AWS
- Experience creating security solutions that balance security requirements with other corporate priorities
- Proficiency in one or more scripting languages such as Python, PowerShell, Bash, etc.
- Expertise with Git, including branching workflows
- Experience testing security controls to ensure effectiveness
- Strong written and verbal communication skills
- Process- and detail-oriented approach
- Demonstrated project leadership, guiding direction for large team initiatives
- Ability to consider options for scaling security controls across multiple cloud service providers
- Expertise in SQL or SQL-type query languages
- University/college degree with 5+ years of industry-relevant experience (or an equivalent combination of education, job-specific certification(s), and experience)
- Bachelors
Preferred Certifications
- Azure Fundamentals - AZ-900
- Azure Security Engineer Associate - AZ-500
- AWS Cloud Security Engineer
Preferred Skills
- Access Control (AC)
- AWS Devops
- Building Architecture
- Cloud Security
- Customer Solutions
- Disaster Recovery Planning
- Information Security
- Microsoft Azure Security
- Network Security
- Physical Security
- Risk Assessments
- Security Technologies
Technologies
- Azure
- AWS
- Cloud Security Posture Management (CSPM) tools
- Security as Code (SAC) pipeline
- CI/CD
- Infrastructure as Code (IAC) teams
- Python
- PowerShell
- Bash
- Git
- SQL
- SQL-type query languages
- Azure Fundamentals - AZ-900
- Azure Security Engineer Associate - AZ-500
- AWS Cloud Security Engineer
Competencies
- Analytical Thinking
- Effective Communications
- Information Security Management
- Information Security Technologies
- IT Environment
- IT Standards, Procedures & Policies
- IT Systems Management
- Network and Internet Security
- Problem Solving
- Technical Troubleshooting
Benefits
- Medical/prescription drug coverage with a Health Savings Account feature
- Dental and vision options
- Employee and spouse/child life insurance
- Short and long-term disability protection
- 401(k) with PNC match
- Pension
- Stock purchase plans
- Dependent care reimbursement account
- Back-up child/elder care
- Adoption, surrogacy, and doula reimbursement
- Educational assistance, including select programs fully paid
- Robust wellness program with financial incentives
- Maternity and/or parental leave
- Up to 11 paid holidays each year
- 9 occasional absence days each year, unless otherwise required by law
- 15 to 25 vacation days each year, depending on career level
- Disability Accommodations Statement: reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform essential functions of their positions
Application Window
Generally expected to be posted for two business days from 05/11/2026, though it may be longer with business discretion.