Logo for PowerPlan, Inc.

Senior Cloud Security Engineer

Role overview

Qualifications

  • 8+ years of experience in cloud security, infrastructure security, or security engineering, with deep hands-on experience across both AWS and Azure.
  • Demonstrated experience implementing security frameworks such as CIS, NIST, or SOC 2 at scale, including running assessments and driving remediation to closure.
  • Strong IAM design and implementation background, including federation (SAML, OIDC), RBAC, ABAC, and privileged access management.
  • Proficiency in Python and PowerShell for security automation, and hands-on experience writing Terraform modules that enforce controls as code.

Responsibilities

  • Complete an assessment of current security framework compliance across AWS and Azure and deliver a prioritized remediation roadmap.
  • Map the current state of IAM across AWS, Azure, and integrated tooling, and present a phased IAM maturity roadmap to leadership.
  • Turn security framework requirements and IAM controls into enforced, production-grade code, Terraform modules and automation.
  • Lead incident response for cloud security events end-to-end and drive the post-incident review process.

Key facts

  • Remote from: Georgia (USA)
  • Full time
  • Senior (5-10 years)
  • Cloud Security Engineer
  • English

Hard skills

Other skills

  • Communication
  • Leadership
  • Teamwork
  • Problem Solving

About the company

PowerPlan, Inc. logo

PowerPlan, Inc.

Computer Software / SaaS

PowerPlan’s award-winning integrated platform gives key stakeholders in accounting, tax, finance, operations, IT and regulatory the clarity they need to make decisions that improve corporate performance. PowerPlan layers complex regulatory requirements with granular financial and operational data from every corner of your organization into a single source of defensible and auditable information. That’s why PowerPlan developed their integrated platform to give key stakeholders in accounting, tax, finance, operations, IT and regulatory the insight they need to make better financial decisions. More than a financial solution, PowerPlan is a powerful insight machine that enables energy companies to: •Combine granular financial and operational asset details from every corner of your organization into a unique view for each stakeholder that enables you to create optimal department strategies. •Mitigate compliance risk by applying complex tax and industry specific regulatory requirements to your consolidated, auditable set of financial books. •Develop defensible, strategic financial asset scenarios that enable optimal planning for today, tomorrow and the next 20+ years and more. For more information how PowerPlan’s solutions can help your organization gain a clearer financial picture, email clarity@powerplan.com or visit www.powerplan.com.

Company details

Company typeSME
IndustryComputer Software / SaaS
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Overview:

This role offers a rare chance to build cloud security and IAM maturity programs from the ground up rather than caretake an existing one, with the Senior Cloud Security Engineer owning compliance, identity strategy, and security automation across both AWS and Azure as a senior individual contributor. Success here means shaping the roadmap leadership acts on, not just executing someone else's plan, with visible influence across Cloud Engineering, Information Security, and executive stakeholders within the first 90 days.

OUR COMPANY

Our company operates cloud infrastructure across AWS and Azure at a scale where security and identity management directly affect how fast the business can move. We invest in strong technical foundations, infrastructure as code, automated compliance, and mature access governance, because we would rather build guardrails once than firefight forever. This role sits at the center of that investment, partnering closely with Cloud Operations and Engineering to keep security built in rather than bolted on.

Responsibilities:

KEY PERFORMANCE OBJECTIVES (FIRST 12 MONTHS)

1: Cloud Security Framework Compliance (First 90 Days, Ongoing Through Year One)

Outcome: Complete an assessment of current security framework compliance across AWS and Azure in the first 30 days, deliver a prioritized remediation roadmap by day 90, and keep compliance scores improving through the first 6 months and beyond.

Impact: Closes framework gaps before they surface as audit or compliance findings, and gives leadership a clear, prioritized view of security posture instead of an ad hoc issue list.

How: By running structured assessments against framework benchmarks, maintaining security baselines and hardening guides, and translating framework requirements into Terraform modules and IaC guardrails that get enforced automatically.

IAM Maturity Roadmap (First 90 Days, Phase 1 By 6 Months)

Outcome: Map the current state of IAM across AWS, Azure, and integrated tooling in the first 30 days, present a phased IAM maturity roadmap to leadership by day 90, and deliver Phase 1 (least-privilege enforcement, access reviews in place) within the first 6 months.

Impact: Moves the organization from fragmented, ad hoc access to one governed by least-privilege and centralized oversight, closing off a major source of unmanaged access risk before it becomes an incident.

How: By assessing current IAM architecture end-to-end, then building out role-based and attribute-based access, federation, and access review processes essentially from the ground up.

Security-as-Code and Automation (Ongoing, Established Within First 6 Months)

Outcome: Turn security framework requirements and IAM controls into enforced, production-grade code, Terraform modules and Python/PowerShell automation, so compliance and access control are checked and enforced automatically rather than tracked in manual checklists.

Impact: Eliminates the gap between documented policy and actual environment state, and frees the security function from re-doing the same manual checks every cycle.

How: By writing Terraform modules that enforce controls as code integrated into CI/CD pipelines, and by building Python and PowerShell automation for assessments, remediation workflows, and compliance reporting.

4: Security Governance and Cross-Functional Partnership (Ongoing)

Outcome: Serve as the security subject matter expert in cloud architecture reviews and change advisory processes, and mentor Cloud Operations and Engineering teams on security best practices, so security judgment shapes decisions before they ship rather than gatekeeping after the fact.

Impact: Embeds security into how the organization designs and changes its cloud environment, and builds security capability across other teams rather than making the security function a bottleneck.

How: By reviewing architecture and change proposals as the security voice in the room, coaching Cloud Operations and Engineering on secure defaults and practices, and presenting security strategy in terms both technical and executive audiences can act on.

5: Cloud Security Incident Response Leadership (Ongoing)

Note: this objective is derived primarily from the job description rather than the hiring manager's intake answers.

Outcome: Lead incident response for cloud security events end-to-end, from detection through resolution, and drive the post-incident review process to convert findings into concrete follow-up actions.

Impact: Shortens the time from detection to containment during real security events, and turns each incident into a source of durable improvement rather than a one-off fire drill.

How: By acting as incident commander or lead responder for cloud security events, coordinating with Cloud Operations and Engineering during response, and documenting and tracking corrective actions after each incident closes.

Qualifications:
  • 8+ years of experience in cloud security, infrastructure security, or security engineering, with deep hands-on experience across both AWS and Azure.
  • Demonstrated experience implementing security frameworks such as CIS, NIST, or SOC 2 at scale, including running assessments and driving remediation to closure.
  • Strong IAM design and implementation background, including federation (SAML, OIDC), RBAC, ABAC, and privileged access management.
  • Proficiency in Python and PowerShell for security automation, and hands-on experience writing Terraform modules that enforce controls as code.
  • A track record of translating security requirements into infrastructure-as-code guardrails integrated into CI/CD pipelines.
  • Experience building or maturing a risk-based or IAM program from an early or fragmented state.
  • Excellent written and verbal communication skills, comfortable presenting security strategy to both engineers and executive leadership.
  • Experience leading incident response for security events and driving post-incident corrective action.

PowerPlan is an EOE

Applicant Privacy Notice

Please note that this is a hybrid role that involves a combination of onsite work from our corporate office as well as work from home. While we strive to accommodate flexible working arrangements when sensible, there will be times when onsite work is required. This could include scheduled office days, team meetings, client meetings, or special events.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cloud Security Engineer Related jobs

Other jobs at PowerPlan, Inc.

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.