Senior Cloud Controls Engineer
Back to search resultsOn-Site role
Job Description:
- The Cloud Security Engineering team enables the firm to securely adopt and scale cloud-native technologies across the enterprise.
- You will work alongside highly skilled professionals in an environment that values intellectual rigor, technical depth, and collaboration.
- This role offers the opportunity to contribute to enterprise-scale cloud security while supporting standards, engineering practices and risk governance.
- We design, implement and operationalize security controls that govern the use of cloud services at scale across Microsoft Azure, AWS, and GCP.
- We are seeking a Senior Cloud Controls Engineer to contribute to cloud security research and control engineering in a fast-paced, highly technical environment.
- This role partners with engineering, architecture, risk and business stakeholders to ensure secure, scalable, and compliant cloud adoption.
What You’ll Do in the Role:
- Design and implement deploy-time security controls for cloud services across Azure, AWS, and GCP, using OPA (Rego) and Regula.
- Translate firm-wide configuration baseline requirements into enforceable policy-as-code controls integrated directly into Terraform workflows and CI/CD pipelines.
- Contribute across the control implementation lifecycle: requirement interpretation, policy authoring, testing, optimization, and deployment within engineering pipelines.
- Establish and maintain reusable policy libraries and modules to ensure consistency and scalability of controls across services and environments.
- Provide deep technical expertise in Terraform, infrastructure-as-code patterns, and pipeline orchestration, ensuring secure and efficient deployments.
- Define and implement testing strategies for policy validation, including unit and integration testing.
- Identify gaps where requirements cannot be enforced at deploy-time and propose compensating controls or alternative enforcement points.
- Contribute to the evolution of a unified control framework, enabling consistent control logic across deploy-time and runtime evaluation points.
- Contribute to cloud security strategy and standards.
Technical Expertise & Collaboration:
- Serve as a senior technical contributor for deploy-time control implementation, helping shape technical approaches and support high-quality delivery.
- Provide hands-on technical guidance and peer support in OPA/Rego, Regula, Terraform, and secure pipeline design.
- Participate in code reviews, design discussions, and knowledge sharing to strengthen engineering quality and consistency across the team.
- Partner with platform engineering, security architecture, and application teams to improve implementation clarity and reduce delivery friction.
- Communicate complex technical concepts clearly to engineering teams, stakeholders, and senior leadership.
- Contribute to engineering best practices for infrastructure-as-code, policy development, testing, and review processes.
What You’ll Bring to the Role:
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- 7+ years of hands-on experience in cloud security engineering, with a strong focus on infrastructure-as-code and deployment pipelines.
- Proven experience designing and implementing policy-as-code controls using OPA/Rego and/or Regula in production environments.
- Deep hands-on expertise with Terraform, including module design, state management, and secure configuration patterns.
- Strong experience integrating security controls into CI/CD pipelines, including gating and enforcement mechanisms.
- Demonstrated ability to translate security requirements into automated, testable, and enforceable deploy-time controls.
- Solid understanding of cloud security architectures across AWS, Azure, and/or GCP, including IAM, networking, and data protection controls.
- Experience implementing control validation and testing strategies, including policy unit testing, pipeline validation, and drift detection.
- Familiarity with CSPM platforms and the ability to align deploy-time controls with runtime detection and compliance models.
- Strong understanding of modern threat models, attack paths, and misconfiguration risks in cloud environments, and how to mitigate them through preventive controls.
- Experience building and maintaining reusable policy libraries and shared control frameworks at enterprise scale.
- Experience working as a senior engineer on complex technical initiatives, including task prioritization, delivery planning, and contribution to technical direction.
- Demonstrated ability to mentor peers and share expertise, particularly in policy-as-code, Terraform, and secure pipeline practices.
About us:
At our organization, we take our mission and values to heart! We are on a mission to offer more and better jobs all over the world! Our goal is to care for you while you care for our clients and get you paid the highest pay possible. All our associates working with us are expected to embrace our RACE values: R - Results Matter, A- Approachable, C - Care, and E - Emergency i.e. work with a sense of urgency.
For more relevant job opportunities please visit our website: Denken Solutions Careers