← Back to list
Job · Principal

Staff Cloud Security Engineer

Security Engineer • Principal • Remote • Full-time European Union EU/EMEA

Staff-level security engineering role hardening AWS cloud security posture and the software delivery pipeline at a debt-relief fintech, with Wiz-based cloud security and vulnerability management as the primary focus.

Responsibilities

  • Own cloud security posture across the AWS environment using Wiz and AWS-native services, reducing risk in IAM, network segmentation, container security, secrets, and data exposure
  • Establish secure defaults in Infrastructure as Code through reusable modules, guardrails, and policy as code
  • Harden CI/CD pipelines in partnership with DevOps
  • Run vulnerability management across cloud and application findings: intake, prioritization, SLA tracking, and remediation with engineering
  • Build automation that scales the program: ingestion, deduplication, prioritization, and developer-facing workflows
  • Instrument telemetry, alerting, and runbooks for owned systems
  • Operate and tune the WAF: managed and custom rules, rate limiting, and bot mitigation

Requirements

  • 8+ years of hands-on security engineering across cloud security and vulnerability management
  • Strong AWS security background: IAM, networking, container orchestration, logging and audit
  • Hands-on experience securing CI/CD pipelines and Infrastructure as Code; Terraform required
  • Experience running or substantially contributing to a vulnerability management program
  • Working knowledge of OWASP Top 10 and threat modeling
  • Ability to operate independently and drive projects without day-to-day oversight

Nice to have

  • Experience with the team's stack: Wiz, Cloudflare (WAF, Gateway, Zero Trust), GitHub Advanced Security, Spacelift, and AWS-native services
  • Hands-on WAF experience in production: writing and tuning rules, managing false positives
  • AI/ML security exposure: prompt injection, data poisoning, model abuse, and related mitigating controls
  • Experience with secrets management platforms (AWS Secrets Manager, Keeper, Infisical)
  • Identity security across human and non-human identities
  • Experience in a PCI-regulated or financial services environment
  • Familiarity with Ruby on Rails, Python, or Go

Soft skills

Measures success by reduced risk rather than tickets closedThinks like an attacker while bringing a developer mindset to partnering with engineeringConnects cloud, identity, and pipeline security rather than treating them separatelyEarns engineers' trust through technical judgment

About the company

Beyond Finance's mission is to help everyday Americans escape the cycle of crippling debt through compassionate, individualized care, a culture focused on compliance and ethics, and customized financial solutions; the company has helped over 1 million clients.

Similar jobs