Skip to content
← Back to job listings

Staff Cloud Security Engineer

SentinelOne · United States

External listingfull-time11 days ago

About The Role

Join our team as a Staff Cloud Security Engineer, where you will be the trusted advisor for customers facing critical security scenarios. You will work directly with our agentic code scanning pipeline, validate cloud exposures, and present findings to customers. You will lead cloud-domain workstreams, conduct deep reviews across major cloud providers, and maintain awareness of cloud-native attack techniques. This role requires excellent communication skills and a strong background in cloud security.

  • Assurer la validation des expositions cloud en utilisant un jugement humain, en reconstruisant les chemins d'attaque cloud-natifs à partir des journaux et des méthodologies de déploiement.
  • Diriger les flux de travail cloud-domain des services d'IA Wayfinder Frontier, de l'engagement client aux examens proactifs, aux évaluations de compromis et au renforcement post-incident.
  • Effectuer des examens approfondis de la gestion des identités et des accès, du réseau et de l'identité sur AWS, Azure et GCP.
  • We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts
  • Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes
  • Comfortable triaging output from AI-assisted cloud-posture and attack-path tools, able to separate risk from noise
  • Kubernetes security at depth (RBAC, admission control, OPA/Gatekeeper, PSS) and IaC review across Terraform, Helm, CloudFormation, and Bicep
  • Deep AWS expertise; IAM, STS, Organizations, SCP, GuardDuty, CloudTrail, EKS, IRSA, and demonstrated ability to map cross-account attack paths
  • Working knowledge in GCP, IAM, Org Policy, Audit Logs, GKE Workload Identity
  • 7+ years in cloud security or cloud-focused application/infrastructure security, with a hands-on engineering background
  • Azure expertise; Entra ID, Conditional Access, RBAC, Activity Logs, Defender for Cloud, AKS, Workload Identity, including cross-tenant and hybrid-identity attack patterns
  • Working knowledge of cloud-native runtime security, eBPF telemetry, container runtime behavior, and how to spot a workload doing something it shouldn't
  • Proven track record translating complex findings into technical and executive-level debriefs. Excellent written and verbal communication is essential
  • Cloud incident response and log forensics experience across at least two major cloud providers

This is an external listing. JobSpring does not represent or verify the employer. Report this listing