Sr Cloud Security Engineer
Job Description
This is a hands-on Cloud Security Engineer role focused on securing and operating BJ’s cloud environments across AWS, Azure, and GCP, evaluating cloud and application designs, operating security tooling, and driving remediation in partnership with engineering and platform teams.
Responsibilities
- Lead triage, validation, prioritization, and remediation tracking for vulnerability findings across cloud, on-prem, and application environments.
- Perform risk-based analysis of vulnerabilities, including false positive validation, asset context assessment, and remediation verification.
- Collaborate with platform, cloud, infrastructure, and application teams to achieve effective and sustainable remediation outcomes.
- Support and continually improve enterprise vulnerability management and patching workflows, including SLAs, exception processes, and escalation paths.
- Assist with infrastructure hardening and patch compliance across cloud and on‑premises environments.
- Contribute to vulnerability discovery and remediation through CSPM, vulnerability scanners, application security tooling, and penetration testing results.
- Implement, operate, and tune security tooling for vulnerability visibility, monitoring, detection, and response across AWS, Azure, and GCP.
- Perform security architecture and design reviews for cloud services, applications, and technologies, providing actionable guidance to reduce exposure to vulnerabilities.
- Evaluate security controls such as identity and access management, encryption, logging, monitoring, and network protections to prevent recurring vulnerabilities.
- Help define and continually improve security standards, reference architectures, configuration baselines, and hardening guidelines.
- Review application designs and implementation patterns to ensure alignment with Secure SDLC and secure coding practices.
- Support application security activities including static, dynamic, and dependency scanning, and assist development teams in understanding and remediating findings.
- Identify opportunities to automate vulnerability validation, remediation tracking, and control validation to increase efficiency and consistency.
- Provide operational support for web application security technologies such as WAFs and edge controls, including Akamai where applicable.
- Assist with certificate lifecycle management, including inventory accuracy, renewal tracking, deployment coordination, and reduction of certificate-related risk.
- Develop and maintain security documentation, runbooks, and standard operating procedures related to vulnerability and risk management.
- Contribute to metrics and reporting that reveal trends in vulnerability exposure, remediation effectiveness, and overall risk reduction.
- Participate in security initiatives and continuous improvement efforts through hands-on execution and technical insight.
Requirements
- Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.
- 4 to 6 years of hands-on experience in security engineering, systems engineering, cloud engineering, or vulnerability management roles.
- Experience operating or supporting an enterprise vulnerability management program.
- Strong understanding of vulnerability discovery, CVE/CVSS concepts, risk-based prioritization, and remediation workflows.
- Experience securing workloads in AWS, Azure, and/or GCP.
- Working knowledge of cloud security controls including IAM, logging, monitoring, encryption, and threat detection as they relate to reducing vulnerabilities.
- Experience operating security controls in highly available production environments.
- Hands-on scripting or automation experience (Python, Bash, PowerShell).
- Working knowledge of infrastructure as code or configuration management tools such as Terraform, CloudFormation, ARM, Puppet, or Ansible.
- Understanding of Secure SDLC concepts and application vulnerability management practices.
- Familiarity with security frameworks or compliance requirements such as NIST, PCI DSS, CIS, or ISO 27001, particularly in vulnerability and patch management contexts.
- Strong communication skills and ability to collaborate with engineering and operations teams.
Technologies
- AWS
- Azure
- GCP
- CSPM
- Vulnerability scanners
- Penetration testing
- Python
- Bash
- PowerShell
- Terraform
- CloudFormation
- ARM
- Puppet
- Ansible
- SAST
- SCA
- DAST
- Akamai
- Akamai Control Center
- Akamai WAF
- Docker
- Kubernetes
- DigiCert
- AppViewX
- IAM
Benefits
- Weekly Pay
- Free BJ’s Memberships
- Generous Paid Time Off
- Flexible and Affordable Health Benefits
- 401(k) Retirement Savings Plan
- Employee Stock Purchase Plan
Location
Location: Marlborough, MA with a hybrid work arrangement
Compensation
Salary: USD 100,000 - 131,500 per year