Summary
Pegasystems is part of the Cloud Cybersecurity operations, focusing on security controls and automation for their cloud environments. The Cloud Security Engineer will manage identity operations, vulnerability scanning, and compliance patching while contributing to automation and security tooling.
Responsibilities
- Own Okta administration for PCFG and Commercial environments: MFA resets, account provisioning, Okta Verify troubleshooting, policy enforcement
- Manage IAM roles, permission boundaries, deployment entitlements, and access reviews across PCFG accounts (CloudOps, Jenkins, deployment pipelines)
- Build and maintain entitlement automation workflows for joiner/mover/leaver processes
- Support SailPoint quarterly certifications and access request workflows; contribute to AI-assisted certification automation
- Operate Nessus/Tenable and Netsparker scanning across PCFG RnD and PCFG Prod
- Respond to audit scan requests (UKCE, SOC, FedRAMP assessors) with findings and evidence
- Track and ensure zero high-severity findings outstanding beyond 30 days
- Execute FedRAMP Control Plane patching cycle every sprint — mandatory compliance obligation, non-negotiable
- Execute PCFG RnD OS automated patching and validate Commercial environment patches (SailPoint, PingCastle)
- Maintain patch compliance metrics; escalate blockers before sprint close
- Contribute to SSM Patch Manager automation to reduce manual patching overhead over time
- Build infrastructure automation: Control Tower account provisioning, PCFG account lifecycle, CloudFormation role deployment
- Develop SSM Patch Manager alerting and role infrastructure
- Respond to ad-hoc infrastructure requests: IAM policy changes, Global Accelerator, Lambda roles, Bedrock model enablement
- Contribute to team-wide AI-driven remediation features — SOAR response actions, AWS Config automation, and AI intake tooling
Skills
- Due to the nature of the role's work with FedRamp, US Citizenship is required
- 3+ years in cloud security engineering or a closely adjacent role; hands-on with AWS (IAM, CloudFormation, SSM, Inspector, Config, GuardDuty)
- Experience operating in a FedRAMP or similarly regulated environment, you understand what compliance-driven delivery looks like
- Proficient with identity platforms: Okta administration, SailPoint or equivalent IGA tooling
- Comfortable writing automation: Python, shell, CloudFormation/Terraform, you don't wait for someone else to build the script
- Familiar with vulnerability scanning tools (Nessus/Tenable, Netsparker, or AWS Inspector)
- You operate well in a team that splits time between BAU obligations and feature delivery, context-switching is part of the job
- Exposure to SOAR platforms (Chronicle SecOps, Siemplify, or similar) is a plus
- Experience with GitHub-based CI/CD pipelines, you're comfortable with PR-gated workflows, GitHub Actions, and treating infrastructure and security content as code that gets reviewed before it ships
- You use AI tools (Copilot, ChatGPT, or similar) as part of how you build, scaffolding automation, generating test cases, accelerating repetitive engineering work and you know how to validate what comes out
Qualifications
Must Haves
- Due to the nature of the role's work with FedRamp, US Citizenship is required
- 3+ years in cloud security engineering or a closely adjacent role; hands-on with AWS (IAM, CloudFormation, SSM, Inspector, Config, GuardDuty)
- Experience operating in a FedRAMP or similarly regulated environment, you understand what compliance-driven delivery looks like
- Proficient with identity platforms: Okta administration, SailPoint or equivalent IGA tooling
- Comfortable writing automation: Python, shell, CloudFormation/Terraform, you don't wait for someone else to build the script
- Familiar with vulnerability scanning tools (Nessus/Tenable, Netsparker, or AWS Inspector)
- You operate well in a team that splits time between BAU obligations and feature delivery, context-switching is part of the job
Nice to Haves
- Exposure to SOAR platforms (Chronicle SecOps, Siemplify, or similar) is a plus
- Experience with GitHub-based CI/CD pipelines, you're comfortable with PR-gated workflows, GitHub Actions, and treating infrastructure and security content as code that gets reviewed before it ships
- You use AI tools (Copilot, ChatGPT, or similar) as part of how you build, scaffolding automation, generating test cases, accelerating repetitive engineering work and you know how to validate what comes out
Benefits
- Competitive global benefits program inclusive of pay + bonus incentive, employee equity in the company (#LI-KH2)
- Continuous learning and development opportunities
- An innovative, inclusive, agile, flexible, and fun work environment
- Gartner Analyst acclaimed technology leadership across our categories of products