Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Cloud Security Engineer

$174.32k - $246.23k

Included Health

The Staff Cloud Security Engineer is a critical, hands‑on technical role responsible for

engineering, implementing, and automating robust security controls

within our cloud environments (AWS primarily, with GCP considerations). This role is pivotal in maturing our cloud security posture, securing Included Healths product infrastructure, and directly contributing to the prevention of unauthorized PHI exfiltration. You will

help design and develop advanced security solutions, often through code (primarily Python and Go) and automation (Terraform),

to address critical challenges in access control, development environment security, and infrastructure hardening. This role requires deep technical expertise in cloud security,

strong software development skills for building security tools and automation , and a proactive approach to risk mitigation. You will be a key technical peer to our infrastructure software and engineering teams, driving a culture of security by design and helping to implement solutions that reduce HIPAA incidents. This is a remote role reporting to the Chief Information Security Officer.

Responsibilities

Design, develop, and implement a comprehensive authorization framework for cloud resources, addressing user roles, resource‑specific restrictions, task‑based access, and granular engineering access

Lead the technical implementation of Just‑In‑Time (JIT) access control systems for production environments (systems, secrets, data) to minimize standing privileges for engineering and platform teams

Collaborate with engineering to integrate data classification (e.g., safe‑harbor annotations) with access control mechanisms, ensuring that data sensitivity directly informs access decisions

Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations, vulnerability management, compliance checks, and incident response

Write clean, maintainable, and testable code (primarily Python and Go; familiarity with Ruby is a plus) for security automation, building custom security integrations, and developing security‑focused tools

Implement and champion Infrastructure as Code (IaC) principles, specifically using Terraform, for programmatic definition, enforcement, and auditing of security configurations

Contribute to the design and implementation of centralized security controls, such as an engineering‑owned Web Application Firewall (WAF), to manage rate limiting, IP blocking, input validation, and request filtering

Partner with engineering teams to establish and implement secure practices for managing the development toolchain (code generation utilities, linters, browser extensions, CLI tools, IDE plugins) to mitigate supply chain risks

Design and help implement a secure, “blessed” mechanism for webhook testing in local development environments, blocking unauthorized tunneling tools

Define, implement, and enforce container security hardening standards (e.g., least privilege, no unnecessary utilities, limited internet access) in collaboration with engineering teams

Drive the remediation of legacy cloud environments, particularly in GCP, by inventorying, assessing, and improving security controls

Design and implement solutions for granular data access control in cloud environments, particularly addressing compliance requirements for handling sensitive data

Collaborate closely with infrastructure software, engineering, DevOps, and product teams to co‑design and integrate robust, automated security controls into systems, architectures, and CI/CD pipelines

Act as a subject matter expert on cloud security (AWS, GCP), providing guidance, code reviews (Python, Go), and technical expertise on secure cloud adoption, secure software development, and access control best practices

Support organizational change management efforts related to new security controls and practices by providing technical rationale and assisting in the development of new workflows

Conduct security assessments, threat modeling, and contribute to incident response, developing automation for prevention and faster response

Develop and maintain comprehensive documentation for security architectures, controls, automation scripts, and incident response playbooks

Qualifications

Bachelors degree in Computer Science, Information Technology, Cybersecurity, or a related field

5+ years of experience in cloud security, with a strong emphasis on designing, developing (primarily in Python and Go), and implementing security solutions in AWS

Proven hands‑on software development experience, particularly in Python and Go, for security automation, building security tools, and infrastructure management

Demonstrable experience designing and implementing robust authorization and access control frameworks (e.g., RBAC, ABAC, policy‑as‑code) and Just‑In‑Time (JIT) access solutions

Experience with Infrastructure as Code (IaC) with deep proficiency in writing and maintaining Terraform modules for security

Experience with containerization (Docker, Kubernetes/EKS), including hands‑on experience hardening containerized environments

Experience with SDLC security, CI/CD pipeline security integration, and secure software development practices

Experience with security logging, monitoring, alerting tools (e.g., SIEM, AWS CloudTrail, CloudWatch, GuardDuty), and scripting against their APIs (Python, Go)

Experience with cloud security frameworks (especially HIPAA), regulations, and standards

Pay
Zone A: $174,320 – $246,230 + equity + benefits

Zone B: $191,752 – $270,853 + equity + benefits

Zone C: $209,184 – $295,476 + equity + benefits

Zone D: $226,616 – $320,099 + equity + benefits

This range reflects the minimum and maximum target for new hire salaries for candidates based on their respective Zone. Below is additional information on Included Healths commitment to maintaining transparent and equitable compensation practices across our distinct geographic zones.

Starting base salary for you will depend on several job‑related factors, unique to each candidate, which may include education; training; skills; years and depth of experience; certifications and licensure; our needs; internal peer equity; organizational considerations; and understanding of geographic and market data. Compensation structures and ranges are tailored to each zones unique market conditions to ensure that all employees receive fair and great compensation package based on their roles and locations. Your Recruiter can share your geographic zone upon inquiry.

Benefits & Perks

Remote‑first culture

401(k) savings plan through Fidelity

Comprehensive medical, vision, and dental coverage through multiple medical plan options (including disability insurance)

Paid Time Off (PTO) and Discretionary Time Off (DTO)

12 weeks of 100% Paid Parental leave

Family Building & Compassionate Leave: Fertility coverage, $25,000 for surrogacy/adoption, and paid leave for failed treatments, adoption or pregnancies

Work‑From‑Home reimbursement to support team collaboration home office work

Your recruiter will share more about the salary range and benefits package for your role during the hiring process.

About Included Health
Included Health is a new kind of healthcare company, delivering integrated virtual care and navigation. We’re on a mission to raise the standard of healthcare for everyone. We break down barriers to provide high‑quality care for every person in every community — no matter where they are in their health journey or what type of care they need, from acute to chronic, behavioral to physical. We offer our members care guidance, advocacy, and access to personalized virtual and in‑person care for everyday and urgent care, primary care, behavioral health, and specialty care. It’s all included. Learn more at

includedhealth.com .

Included Health is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics or any other basis forbidden under federal, state, or local law. Included Health considers all qualified applicants with arrest or conviction records in accordance with the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance, and California law.

Included Health uses AI‑assisted tools at select stages of the hiring process to enhance efficiency, consistency, and communication. AI does not make hiring decisions—final decisions are made exclusively by our recruiting and hiring teams.

#J-18808-Ljbffr
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Staff Cloud Security Engineer in Richmond, VA vacancy
  •  ...Boston Medical Center is seeking an AWS Cloud Security Engineer responsible for developing and managing cloud security strategies. The role requires collaborating with various teams to enforce security policies and best practices while ensuring the availability of security... 
    Suggested

    Boston Medical Center

    Richmond, VA
    12 hours ago
  •  ...A leading technology company in the United States is looking for a Cloud Security Engineer (Staff) to define and execute security strategies across multi-cloud and hybrid environments. The successful candidate will focus on preventative security controls, design complex... 
    Suggested

    PlayStation Network

    Richmond, VA
    2 days ago
  •  ...Humata Health, Inc is seeking a Network Security & Application Engineer to design and maintain secure, scalable infrastructure across cloud environments like Azure and GCP. The role involves managing network architectures, implementing zero-trust models, and working with... 
    Suggested
    Remote work

    Humata Health, Inc

    Richmond, VA
    2 days ago
  • $153.99k - $192.48k

     ...touch thousands of lives each day, helping people achieve new levels of mobility and freedom. Could This Be For You? The Cloud Security Engineer V is responsible for working cross‑functionally with Architecture, Software Development, Cloud Infrastructure, and... 
    Suggested
    Part time
    Local area
    Relocation package
    Flexible hours

    Hanger

    Richmond, VA
    1 day ago
  •  ...EPAM Systems, Inc. is seeking a Senior Cloud Engineer to work in the United States. In this role, you will design and secure cloud infrastructure for complex enterprise environments. Responsibilities include implementing cloud security policies, managing IAM, and collaborating... 
    Suggested

    EPAM Systems Inc

    Richmond, VA
    2 days ago
  •  ...An innovative company is seeking a skilled Cloud Security Engineer to enhance its cloud infrastructures security and resilience. This role involves designing and implementing robust security solutions for AWS and Kubernetes, conducting assessments, and mentoring teams... 

    HEX

    Richmond, VA
    1 day ago
  • $92k - $195k

     ...Responsibilities Implement and maintain cloud security frameworks, ensuring compliance with NIST 800-53 Rev. 5, FedRAMP, and DoD IL...  ...or five (5) years of equivalent experience in cloud security engineering. Demonstrated experience in implementing cloud security frameworks... 

    Maxar Technologies

    Richmond, VA
    12 hours ago
  •  ...Upwind Security, Inc. is seeking an experienced Software Engineer to join their Sensor Components SW-Engineering group. In this role, youll tackle complex engineering...  ...Upwind Sensor for Windows OS, ensuring exceptional cloud security management. Your responsibilities will... 

    Upwind Security, Inc.

    Richmond, VA
    12 hours ago
  •  ...A global security firm is seeking an advanced technical cybersecurity professional to join their team in the United States. This role involves leading security initiatives focused on Microsoft Cloud Security, developing automation for SOC tools, and mentoring team members... 

    WSP

    Richmond, VA
    2 days ago
  • $84 - $89.74 per hour

     ...Cloud Security Engineer Location: Richmond, Virginia ; Charlotte, NC ; Kennesaw, GA Employment Type: Contract Role Overview A Cloud Security Engineer is sought to provide analysis of cloud cybersecurity architecture, ensuring compliance with federal regulations... 
    Hourly pay
    Contract work
    Work experience placement

    Apex Systems

    Richmond, VA
    5 days ago
  • $140k - $155k

     ...Walker & Dunlop is looking for a Senior Cloud and Software Development Security Engineer to secure its cloud and application environments, including AWS and Azure. This role involves designing security architectures, guiding developers on secure practices, and ensuring... 

    Walker & Dunlop

    Richmond, VA
    12 hours ago
  • $20k

     ...We are seeking an experienced Cloud Security Engineer to shape the security foundation of our modern cloud environments and next-generation applications. In this high-impact role, you will design cutting-edge automated security controls, harden multi-cloud infrastructure... 
    Local area
    Flexible hours

    ServiceTitan

    Richmond, VA
    2 days ago
  • $89.5k - $130k

    A healthcare organization in Massachusetts is seeking an experienced AWS Cloud Security Engineer. This role involves developing, managing, and supporting cloud security strategies while ensuring adherence to key security standards. Candidates must have solid AWS expertise... 

    Boston Medical Center

    Richmond, VA
    2 days ago
  • $153.99k - $192.48k

     ...A leading healthcare solutions provider in the United States is seeking a Cloud Security Engineer V to design and implement cloud security architecture in Microsoft Azure and lead efforts in cloud migration. The ideal candidate will have at least 8 years of experience... 

    Hanger

    Richmond, VA
    2 days ago
  •  ...Serco is looking for a Principal Information Security Systems Engineer based in Richmond, Virginia. In this role, you will coordinate risk management efforts and maintain security for cloud applications supporting the U.S. Navy. You need an active Secret security clearance... 

    Serco

    Richmond, VA
    3 days ago
  •  ...A leading cloud platform provider in the United States seeks a Security Engineer to enhance application security by developing tools and implementing monitoring systems. Candidates should possess over 6 years of experience in software engineering or security with a strong... 

    Render

    Richmond, VA
    2 days ago
  • $200k

     ...Senior Software Security Engineer (Remote, US) Up to $200k Base + Equity Join a fast-growing Series C fintech on a mission to empower working Americans with better financial tools. This is a hands-on, code-first role where Keycloak and Spring Boot are central to securing... 
    Remote work
    Home office

    Storm2

    Richmond, VA
    2 days ago
  • $204k - $281k

     ...Wiz is seeking an experienced Software Security Engineer to support its corporate platforms, focusing on developing robust solutions for enterprise...  ...development practices, including Python programming and cloud computing. The position offers a competitive salary range of... 

    Wiz

    Richmond, VA
    2 days ago
  •  ...Sysdig is seeking a Sales Engineer in the United States to drive discovery discussions, deliver product demonstrations, and ensure customer success with their cloud security solutions. The ideal candidate will have 5 to 10 years of experience in sales engineering, a solid... 

    Sysdig

    Richmond, VA
    2 days ago
  • $192k - $240k

     ...A leading fintech company in the US seeks a Senior Application Security Engineer to focus on identifying and responding to security vulnerabilities. The role involves collaboration with various engineering teams, performing penetration testing, and developing security... 

    Brex

    Richmond, VA
    2 days ago
  • $178.5k

     ...use our browser on Mac, Windows, iOS, and Android, our search engine, and the DuckDuckGo subscription. Our culture of trust, inclusivity...  ...come to the right place! Your Team and Role Working on the Security Functional Team, youll play a pivotal role in ensuring our... 
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    DuckDuckGo

    Richmond, VA
    1 day ago
  • A leading real estate technology firm is seeking a Security Operations Engineer to enhance their cloud security posture. The role demands strong hands-on technical skills in AWS and Azure environments, focusing on incident response and vulnerability remediation. Successful... 

    SitusAMC

    Richmond, VA
    4 days ago
  •  ...A leading IT solutions provider is seeking a Presales Solutions Engineer for Data Protection, a customer-facing role focused on cloud security expertise. The engineer will take a consultative approach to projects, educating teams on cybersecurity solutions and developing... 
    Remote work
    Flexible hours

    SHI GmbH

    Richmond, VA
    1 day ago
  • $144k - $227.5k

     ...A leading cloud security company is seeking a Solutions Engineer to drive sales and customer success. The role demands a strong technical background, exceptional communication skills, and the ability to advocate for the customer’s needs. Ideal candidates have over 7 years... 

    Netskope

    Richmond, VA
    12 hours ago
  • $147k - $253k

     ...Anduril Industries is hiring a Staff Security Engineer to enhance their Identity and Access Management. This role involves building an identity engine, creating applications for security, and automating identity operations. Candidates should have strong programming skills... 
    Full time

    anduril

    Richmond, VA
    2 days ago
  •  ...Zscaler, a leader in cloud security, is seeking an experienced Engineering Director to lead the ZIA team. In this role, you will drive the technical strategy, set engineering standards, mentor engineers, and collaborate with various stakeholders to ensure exceptional outcomes... 

    Framework Ventures

    Richmond, VA
    2 days ago
  •  ...A leading software company is hiring a Staff AI Product Security Architect to enhance the security of their AI-powered platform. This senior position involves establishing secure principles for AI integrations and conducting risk assessments. Candidates should have over... 

    GitLab

    Richmond, VA
    2 days ago
  •  ...create the software that powers our world. We are seeking a Staff AI Product Security Architect to join our Security Platforms & Architecture...  ...for AI integrations, creating architectural patterns that engineering teams can leverage, and ensuring our AI capabilities meet... 

    GitLab

    Richmond, VA
    1 day ago
  • $175k - $200k

     ...Sr. Staff AI Security Architect page is loaded## Sr. Staff AI Security Architectlocations: Remote...  ...and business teams. Mentor architects, engineers, and security teams on AI security best...  ...* 10+ years in security architecture (cloud, platform, or application security), including... 
    Remote work

    Penn Mutual Life Insurance Co.

    Richmond, VA
    12 hours ago
  •  ...Timings US Hours 7 pm-4 am IST Role Description As a Security Engineer II, you will play a pivotal role in ShipBob’s Information Security...  ...control frameworks and tools (IAM, RBAC, ABAC, OAuth, SAML), cloud security, network security, endpoint security, and threat... 
    Work experience placement
    Casual work
    Local area
    Remote work
    Shift work

    ShipBob Inc

    Richmond, VA
    12 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Cloud Security Engineer. Be the first to apply!