Summary
Applied Systems is transforming the insurance industry by building a team that is dedicated to delivering innovative software and services. They are seeking an experienced Infrastructure Security Engineer to design and operate security controls across cloud platforms and edge infrastructure, while mentoring junior engineers and collaborating with various teams.
Responsibilities
- Design, implement, and maintain cloud security solutions across AWS, GCP, and Azure environments
- Lead the design and deployment of Cloudflare WAF and related edge security controls across production infrastructure
- Implement and optimize SASE (Secure Access Service Edge) architecture and controls to replace traditional perimeter security
- Develop and maintain cloud access policies and zero-trust network access controls
- Conduct security reviews and threat modeling of cloud infrastructure and data flows
- Implement cloud security posture management (CSPM) and identify/remediate misconfigurations
- Design, implement, and maintain infrastructure-as-code security configurations
- Contribute to the creation and maintenance of runbooks and playbooks for cloud security incident response
- Assist with proof-of-concept builds for new cloud security and SASE solutions
- Contribute to detection rule tuning and security monitoring in cloud environments
- Participate in the Security Engineering Team on-call rotation
Skills
- Minimum of 3 years' experience in cloud security engineering, DevSecOps, or site-reliability engineering
- Advanced knowledge of at least two major cloud platforms (AWS, GCP, Azure)
- Hands-on experience implementing and optimizing WAF solutions, with Cloudflare strongly preferred
- Demonstrated experience designing or implementing SASE/zero-trust network access solutions
- Working knowledge of Privileged Access Management (PAM) solutions and principles (BeyondTrust or similar)
- Familiarity with secrets management and privileged credential storage (Keeper or similar)
- Advanced knowledge of Linux and/or Windows operating systems
- Experience with one or more scripting languages (PowerShell, Python, Bash, Go)
- Experience with infrastructure-as-code technologies (Terraform, Ansible, Pulumi)
- Working knowledge of traditional networking and software-defined networking (SDN) concepts
- Strong understanding of cloud networking models (VPC, security groups, network policies)
- Knowledge of encryption in transit and at rest, certificate management
- Experience with cloud logging, monitoring, and alerting (CloudWatch, Stackdriver, Azure Monitor, etc.)
- Demonstrated ability to work with systems at scale
- Excellent written and verbal communication skills
- Strong problem-solving abilities and attention to detail
Qualifications
Must Haves
- Minimum of 3 years' experience in cloud security engineering, DevSecOps, or site-reliability engineering
- Advanced knowledge of at least two major cloud platforms (AWS, GCP, Azure)
- Hands-on experience implementing and optimizing WAF solutions, with Cloudflare strongly preferred
- Demonstrated experience designing or implementing SASE/zero-trust network access solutions
- Working knowledge of Privileged Access Management (PAM) solutions and principles (BeyondTrust or similar)
- Familiarity with secrets management and privileged credential storage (Keeper or similar)
- Advanced knowledge of Linux and/or Windows operating systems
- Experience with one or more scripting languages (PowerShell, Python, Bash, Go)
- Experience with infrastructure-as-code technologies (Terraform, Ansible, Pulumi)
- Working knowledge of traditional networking and software-defined networking (SDN) concepts
- Strong understanding of cloud networking models (VPC, security groups, network policies)
- Knowledge of encryption in transit and at rest, certificate management
- Experience with cloud logging, monitoring, and alerting (CloudWatch, Stackdriver, Azure Monitor, etc.)
- Demonstrated ability to work with systems at scale
- Excellent written and verbal communication skills
- Strong problem-solving abilities and attention to detail
Benefits
- Medical, Dental, and Vision Coverage
- Holiday and Vacation Time
- Health & Wellness Days
- A Bonus Day for Your Birthday
- We flex our time together, collaborating remotely and in-person to empower our teams to work in the ways that work best for them.
- Your experience should include some or all of the following: Minimum of 3 years' experience in cloud security engineering, DevSecOps, or site-reliability engineering
- The ability to work from an Applied Systems office or 100% remotely
- Depending on the role, team members may also be eligible to participate in additional compensation plans such as bonus and commission.