<p>Cleo is seeking a Lead Cloud Security Engineer to design, implement, and continuously improve security controls across our cloud infrastructure and SaaS environments.<span data-ccp-props="{"335559738":240,"335559739":240}"> </span></p><p><span data-contrast="auto">This role is responsible for strengthening Cleo’s AWS security posture, embedding secure-by-default cloud guardrails, and partnering closely with Platform and Engineering teams to reduce infrastructure risk without slowing innovation.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></p><p><span data-contrast="auto">The ideal candidate is hands-on, technically deep in AWS, and experienced in building scalable cloud security capabilities in a high-growth SaaS environment.</span><span data-ccp-props="{"335559738":240,"335559739":240}"> </span></p><p><strong> </strong></p><h3><strong>What You Will Be Doing</strong></h3><p><strong>Cloud Security Architecture</strong><span data-ccp-props="{"134245418":false,"134245529":false,"335559738":280,"335559739":80}"> </span></p><ul><li><span data-contrast="auto"> Design and implement secure cloud architecture patterns</span></li><li><span data-contrast="auto"> Establish guardrails for AWS accounts and services</span></li><li><span data-contrast="auto"> Strengthen multi-account strategy and segmentation</span></li><li><span data-contrast="auto"> Improve IAM design, permission boundaries, and least-privilege models</span></li><li><span data-contrast="auto"> Review major infrastructure changes for security impact</span></li></ul><p><span data-contrast="none"><span data-ccp-parastyle="heading 3"><strong>Cloud Detection and Visibility</strong></span></span><span data-ccp-props="{"134245418":false,"134245529":false,"335559738":280,"335559739":80}"> </span></p><ul><li><span data-contrast="auto"> Implement and tune cloud-native detection capabilities</span></li><li><span data-contrast="auto"> Integrate AWS security services into centralized monitoring</span></li><li><span data-contrast="auto"> Identify misconfigurations and excessive permissions</span><span data-ccp-props="{}"> </span></li><li><span data-contrast="auto"> Improve signal-to-noise ratio in cloud alerts</span></li></ul><p><span data-contrast="none"><span data-ccp-parastyle="heading 3"><strong>Infrastructure as Code Security</strong></span></span><span data-ccp-props="{"134245418":false,"134245529":false,"335559738":280,"335559739":80}"> </span></p><ul><li><span data-contrast="auto"> Embed security controls into Terraform or other IaC workflows</span><span data-ccp-props="{"335559738":240}"> </span></li><li><span data-contrast="auto"> Enforce policy-as-code guardrails</span></li><li><span data-contrast="auto"> Ensure IaC scanning is integrated into CI/CD pipelines</span><span data-ccp-props="{}"> </span></li><li><span data-contrast="auto"> Reduce configuration drift across environments</span></li></ul><p><span data-contrast="none"><span data-ccp-parastyle="heading 3"><strong>Vulnerability and Configuration Management</strong></span></span><span data-ccp-props="{"134245418":false,"134245529":false,"335559738":280,"335559739":80}"> </span></p><ul><li><span data-contrast="auto"> Oversee cloud misconfiguration detection and remediation</span></li><li><span data-contrast="auto"> Track infrastructure vulnerability exposure</span></li><li><span data-contrast="auto"> Reduce critical vulnerability exposure window</span></li><li><span data-contrast="auto"> Partner with Platform teams to automate remediation</span></li></ul><p><span data-contrast="none"><span data-ccp-parastyle="heading 3"><strong>Data Protection and Encryption</strong></span></span><span data-ccp-props="{"134245418":false,"134245529":false,"335559738":280,"335559739":80}"> </span></p><ul><li><span data-contrast="auto"> Ensure proper encryption standards across storage and databases</span></li><li><span data-contrast="auto"> Manage KMS usage and key lifecycle best practices</span></li><li><span data-contrast="auto"> Strengthen logging and monitoring coverage</span></li></ul><p><span data-contrast="none"><span data-ccp-parastyle="heading 3"><strong>Incident Response Support</strong></span></span><span data-ccp-props="{"134245418":false,"134245529":false,"335559738":280,"335559739":80}"> </span></p><ul><li><span data-contrast="auto"> Lead cloud-focused investigations during security incidents</span></li><li><span data-contrast="auto"> Improve forensic readiness in AWS</span></li><li><span data-contrast="auto"> Harden logging and evidence retention practices</span></li></ul><p><span data-contrast="none"><span data-ccp-parastyle="heading 3"><strong>Automation and Continuous Improvement</strong></span></span><span data-ccp-props="{"134245418":false,"134245529":false,"335559738":280,"335559739":80}"> </span></p><ul><li><span data-contrast="auto"> Automate guardrails and enforcement mechanisms</span></li><li><span data-contrast="auto"> Improve developer experience with secure cloud defaults</span></li><li><span data-contrast="auto"> Reduce manual cloud security reviews</span></li><li><span data-contrast="auto"> Optimizing tooling cost and effectiveness</span><span data-ccp-props="{"335559739":240}"> </span></li></ul><p><span data-contrast="none"><span data-ccp-parastyle="heading 3"><strong>Metrics and Reporting</strong></span></span><span data-ccp-props="{"134245418":false,"134245529":false,"335559738":280,"335559739":80}"> </span></p><ul><li><span data-contrast="auto"> Define KPIs for cloud security posture</span></li><li><span data-contrast="auto"> Report on misconfiguration trends and exposure windows</span></li><li><span data-contrast="auto"> Provide executive-level reporting on infrastructure risk</span></li><li><span data-contrast="auto"> Support audit and compliance evidence collection</span></li></ul><p> </p><h3><strong>Your Qualifications</strong></h3><p> <strong>Required</strong><span data-ccp-props="{"134245418":false,"134245529":false,"335559738":280,"335559739":80}"> </span></p><ul><li><span data-contrast="auto"> 7+ years of experience in cloud security, cloud engineering, or infrastructure security</span></li><li><span data-contrast="auto"> Deep expertise in AWS architecture and services</span><span data-ccp-props="{}"> </span></li><li><span data-contrast="auto"> Strong understanding of IAM design and least-privilege principles</span></li><li><span data-contrast="auto"> Experience with Infrastructure as Code and CI/CD integration</span></li><li><span data-contrast="auto"> Experience implementing cloud-native detection and monitoring</span></li><li><span data-contrast="auto"> Ability to translate infrastructure risk into business impact</span></li></ul><p><span data-contrast="none"><span data-ccp-parastyle="heading 3"><strong>Preferred</strong></span></span><span data-ccp-props="{"134245418":false,"134245529":false,"335559738":280,"335559739":80}"> </span></p><ul><li><span data-contrast="auto"> Experience in mid-market or high-growth SaaS environments</span></li><li><span data-contrast="auto"> Experience supporting SOC 2 or similar audits</span></li><li><span data-contrast="auto"> Familiarity with policy-as-code frameworks</span></li><li><span data-contrast="auto"> Experience building multi-account AWS environments</span></li><li><span data-contrast="auto"> Relevant certifications such as AWS Security Specialty, CISSP, or equivalent</span></li></ul><h3> </h3><h3><strong>A few things we have to offer: </strong></h3><ul><li>$130,000 to $150,000 base salary + bonus opportunity</li><li>Great Healthcare + Dental + Vision</li><li>Flexible PTO</li><li>Culture of support, encouraging Life-Work balance</li><li>401k match</li><li>FSA and HSA options</li><li>Employee Assistance Program</li><li>Paid Parental Leave</li><li>Representing a company with 4,000+ clients and a 99% retention rate</li><li>Accelerated title and salary growth potential </li><li>A fun and energetic work environment that makes you excited to go to work every day</li></ul><div class="content-conclusion"><p><em>We use artificial intelligence (AI) tools to assist in certain stages of our recruitment process, such as resume screening and candidate matching. These tools are designed to support fair and consistent evaluations. If you have questions about this process or would like to request an alternative assessment method, please contact us at hr@cleo.com.</em><br></p><p><em>Cleo Communications US, LLC is an equal opportunity/affirmative action employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability status, protected veteran status, or any other characteristic protected by law.</em></p></div>