Base Career helps you apply smarter for this job.
Key skills for this role
We are seeking a Cloud Security Engineer to design, implement, and maintain security controls across the organization's cloud infrastructure and cloud-native technology environments. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards.
This role partners with Infrastructure, Platform Engineering, DevOps, Software Engineering, IAM, and Security teams to establish secure cloud architectures, identify cloud risks, implement preventative controls, and continuously improve the organization's cloud security posture.
The Cloud Security Engineer serves as the primary technical security resource for cloud infrastructure and helps ensure security controls are scalable, automated, and integrated into the way cloud environments are designed and operated.
At Gifthealth, we're revolutionizing the way people experience healthcare by simplifying the process of managing prescriptions and health services. Our mission is to provide a seamless, personalized, and efficient healthcare experience for all our customers. We're a dynamic, innovative, and customer-centric company dedicated to making a positive impact on people's lives.
We are seeking a Cloud Security Engineer to design, implement, and maintain security controls across the organization's cloud infrastructure and cloud-native technology environments. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards.
This role partners with Infrastructure, Platform Engineering, DevOps, Software Engineering, IAM, and Security teams to establish secure cloud architectures, identify cloud risks, implement preventative controls, and continuously improve the organization's cloud security posture.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Columbus, USA
, USA
, USA
, USA
, USA
, USA
, USA
Columbus, USA
, USA
The Cloud Security Engineer serves as the primary technical security resource for cloud infrastructure and helps ensure security controls are scalable, automated, and integrated into the way cloud environments are designed and operated.
Develop and maintain security standards and reference architectures for cloud environments.
Participate in architecture reviews for new cloud services, platforms, and major infrastructure changes.
Evaluate proposed architectures for security risks and recommend appropriate controls.
Establish secure patterns for cloud networking, identity, encryption, logging, storage, compute, and managed services.
Evaluate the security boundary between AWS-managed infrastructure and externally managed platforms (e.g., Heroku, Snowflake) to ensure consistent controls across both.
Identify insecure cloud configurations and excessive permissions.
Continuously assess cloud environments against established security standards and benchmarks.
Prioritize cloud security findings based on technical severity and business risk.
Partner with system owners to remediate cloud security findings.
Identify systemic issues that can be addressed through platform-level controls.
Work with IAM teams to establish least-privilege access models for cloud resources.
Review cloud roles, permissions, service accounts, and privileged access.
Identify excessive, unused, or risky cloud privileges.
Establish controls for administrative and privileged cloud access.
Support secure workload identity and service-to-service authentication patterns.
Compute workloads
Storage
Databases
Networking
Serverless services
VPN and remote access infrastructure (Site-to-Site and client VPN)
Data warehouse platforms (e.g., Snowflake, BigQuery)
APIs
Secrets and key management
Establish secure configuration baselines.
Work with engineering teams to implement cloud security guardrails.
Ensure appropriate cloud logging and security telemetry is available for security monitoring.
Develop or assist with detections for suspicious cloud activity.
Partner with Security Operations to investigate cloud security events.
Improve visibility into administrative activity, authentication, workload behavior, and configuration changes.
Embed cloud security requirements into Infrastructure-as-Code.
Develop automated checks and preventative security controls.
Build reusable secure cloud modules and templates with engineering teams.
Use APIs, scripts, and cloud-native services to automate security processes.
Support vulnerability management across cloud infrastructure and workloads.
Identify vulnerable cloud resources, operating systems, containers, and services.
Coordinate remediation with infrastructure and engineering teams.
Help distinguish vulnerabilities requiring immediate remediation from findings better addressed through compensating controls or risk acceptance.
Develop and maintain cloud security standards and technical requirements.
Map cloud controls to applicable security and compliance requirements.
Provide technical evidence for audits and assessments when needed.
Evaluate new AI-enabled cloud services (e.g., Amazon Q) for security and data-handling implications before broader rollout.
Cloud security requirements are incorporated into architecture before systems are deployed.
High-risk cloud misconfigurations and excessive permissions are identified and remediated.
Security controls increasingly operate as automated guardrails rather than manual reviews.
Cloud environments have reliable security logging and monitoring coverage.
Cloud vulnerabilities and configuration findings have clear ownership and remediation paths.
Secure cloud patterns are documented and reusable by engineering teams.
Security becomes a standard part of cloud architecture and platform engineering decisions.
Location: Not specified in the source job description; to be confirmed with the hiring manager.
Schedule: Full-time; standard business hours.
May require flexibility for cloud security incident response or urgent remediation of high-risk findings.
Regular collaboration with Infrastructure, Platform Engineering, DevOps, Software Engineering, IAM, and Security teams to ensure alignment.
Must be able to work at a computer for extended periods
Must be able to communicate effectively, verbally and in writing, with infrastructure, engineering, and security stakeholders
Must be able to handle and access sensitive cloud infrastructure and security data in compliance with organizational data handling requirements
Must be able to respond to critical cloud security incidents outside standard working hours when required
Status: Full-time
FLSA: Exempt
Equal Employment Opportunity (EEO) Statement
Gifthealth is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. All employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity, transgender status, national origin, age, disability, veteran status, or any other legally protected status.
We celebrate diversity and are committed to creating an inclusive environment for all employees. If you do not meet every requirement but still feel you would be a great fit for this role, we encourage you to apply!
Disclaimer
This job description is intended to describe the general nature and level of work being performed. It is not intended to be an exhaustive list of all responsibilities, duties, or skills required of personnel. Gifthealth reserves the right to modify job duties or descriptions at any time.
Digital pharmacy and patient-access platform fulfilling prescriptions and supporting biopharma brands, clinics, prescribers, and patients.
Visit company websiteJobs and hiring trendsUSD 115000-150000 yearly / year
Full-time
Mid · 3+ years experience
Remote
Apply faster on company sites with our extension.