Principal Cybersecurity Cloud Engineer
Dayforce
Principal Cloud Security Engineer
The Cloud Security team is seeking a Principal Cloud Security Engineer to serve as a hands-on technical expert and trusted advisor across our cloud programs. Our team owns the security of multiple cloud environments—primarily Azure and AWS—and the implementation of security controls to meet regulatory requirements across geographies. Beyond identifying issues, we partner closely with product and platform teams to design and deliver secure cloud-based solutions.
You will lead CNAPP implementation, harden our Azure and AWS footprint, embed security into CI/CD and Terraform workflows, and support our path to FedRAMP, PBMM, and other public-sector compliance programs.
You will develop and drive the implementation of our Cloud Security Architecture and CNAPP architecture—defining secure-by-default reference patterns, guardrails, and scalable control implementations for Azure (primary) and AWS (in scope). You will partner with platform engineering, SRE, product, and compliance teams to translate architectural intent into actionable engineering work and measurable posture improvements.
You will map regulatory requirements (e.g., FedRAMP, NIST SP 800-53, PBMM, GC Cloud Guardrails, ITSG-33 or equivalent) to cloud security capabilities such as identity and access management, network segmentation, encryption and key management, logging/monitoring, vulnerability management, container/Kubernetes security, and continuous compliance. You will then engineer, implement, and operationalize these controls using cloud-native services and Wiz (policies, sensors, and workflows), integrated into Terraform and CI/CD pipelines with policy-as-code, drift detection, and automated evidence where feasible.
You'll thrive in a dynamic, fast-paced environment, operate as a self-starter, work independently, and stay relentlessly results-oriented.
What You'll Do
- Lead CNAPP implementation: Plan and execute end-to-end rollout of Wiz (and related CNAPP tooling) across Azure (and select AWS), including policy design, tuning, and alert-to-action workflows.
- Harden clouds at scale: Design and enforce guardrails (Azure Policy, Defender for Cloud plans, identity controls, network segmentation, logging/monitoring) and extend patterns to AWS where applicable.
- DevSecOps & IaC governance: Embed security into CI/CD and Terraform workflows (pre-merge checks, plan/policy gates, artifact signing, SBOMs/attestations) and establish reusable modules and policy-as-code patterns to prevent misconfigurations before deploying; enforce baselines at plan time.
- Compliance engineering: Translate FedRAMP, CIS, and other frameworks into technical controls, automated evidence, continuous monitoring, and remediation playbooks.
- Cloud security architecture & blueprint: Own and evolve the cloud security reference architecture (standardized landing zones, identity and access patterns, network segmentation, encryption standards, logging/monitoring baselines, and guardrails) for Azure (primary) and AWS (in scope); advise product and platform teams on secure designs, lead design reviews, and mentor engineers.
- Incident & posture improvement: Partner with SecOps and AppSec teams to triage findings, evaluate risks, recommend remediation steps, and drive measurable improvements across vulnerabilities, identities, data, and workloads.
- Executive advisory: Communicate risk, trade-offs, and roadmaps to senior leadership; influence prioritization through clear metrics and business outcomes.
- Build automated guardrails and drift detection/auto-remediation using Terraform (and/or Bicep/ARM where applicable), integrating controls into CI/CD to consistently enforce secure defaults.
- Kubernetes/AKS security: Partner with platform teams to harden AKS (RBAC, network policies, workload identity), implement admission controls, and operationalize Wiz Sensors and CNAPP findings into engineering workflows and secure runtime baselines.
What You Bring
- Bachelor's degree in Computer Science, Engineering, or related field (or equivalent experience).
- 10+ years in security engineering/architecture with significant cloud security experience (SaaS or technology companies preferred).
- Deep, hands-on expertise with:
- CNAPP (Wiz or equivalent) deployment at scale, policy design, tuning, automation; and Microsoft Defender for Cloud (policies, plans, recommendations, regulatory compliance, alerting).
- DevSecOps / CI/CD: integrating security tests and gates in GitHub Actions (or similar), artifact/image scanning, and automated compliance evidence; securing pipeline identities, secrets, and supply chain integrity.
- Infrastructure as Code (IaC): production-grade Terraform Enterprise/Terraform Cloud (modules, registries, workspaces), plan-time checks, and drift control.
- Policy engineering: designing and implementing cloud security policies (Azure Policy initiatives; OPA/Sentinel policy-as-code) and mapping to frameworks (NIST, CIS).
- Azure security (Entra ID/AAD, RBAC, networking, Key Vault, monitoring).
- Multi-cloud, hands-on experience with Azure and AWS services.
- Container and Kubernetes security: cluster hardening, workload identity/RBAC, network policies, admission controls, image signing/verification, runtime protection, and container registries (ACR/ECR, JFrog Artifactory).
- Security automation: scripting (e.g., Python/PowerShell) to build guardrails, detections, and tooling.
- Experience establishing and reporting KRIs/KPIs and improving cloud security posture at scale using data-driven metrics (e.g., NIST, CIS, STIG).
- Experience delivering cloud implementations in regulated environments, including U.S. Government / U.S. Public Sector requirements (FedRAMP, NIST SP 800-53) and Canadian Government / Public Sector requirements (PBMM, GC Cloud Guardrails, ITSG-33 or equivalent) — including control mapping, automation, and continuous monitoring.
- Excellent stakeholder skills—operate as a trusted advisor to product, platform, compliance, and executive teams.
- Self-starter who can work independently, communicate clearly, and drive cross-functional outcomes with a bias for automation and measurable posture improvement.
- Proven track record operating as a Cloud Security Architect across CNAPP, Wiz, Terraform, and CI/CD pipeline architectures—defining cloud policies, integrating cloud-native and CNAPP controls, and leveraging their control frameworks for continuous compliance.
- Hands-on experience securing Kubernetes (AKS) using Wiz Sensor tooling (deployment, operations, and integration with detection and remediation workflows).
Preferred Qualifications
- Microsoft AZ-500, SC-100, SC-200 certifications strongly preferred.
- One of the security certifications, such as CISSP or CCSP.
- DevOps experience with infrastructure, cloud, and application pipelines.
- Hands-on experience with container and image scanning; SAST, DAST; and penetration testing tools.
- Knowledge of large language models (LLMs) and hands-on experience designing and building generative-AI–powered agents.
- Experience with Python, Java, .NET, C#, Rego, and YAML.
What's in it for you
Dayforce is fueled by the diversity of our talented employees. We are an equal opportunity employer and consider and embrace ALL individuals and what makes them unique. We believe our employees should be happy and healthy, with peace of mind and a sense of fulfillment.
We encourage individuals to apply based on their passions.
Dayforce encourages personal and professional growth. We offer excellent time away from work programs, comprehensive wellness initiatives and recognition through competitive pay and benefits.
With a commitment to community impact, including volunteer days and our charity, Dayforce Cares we provide opportunities for you to thrive both in your career and personal life. Our focus is not just on your job but on supporting you to be the best version of yourself.
About the Salary Ranges
Please note that the salary range mentioned in this job description should serve simply as a guide. The final compensation offered may vary based on a variety of factors, including bonuses and/or incentives, or a candidate's experience, skills, budget and location. Our company is committed to providing a fair, equitable, and competitive package that reflects the value an individual brings to the organization.
Fraudulent Recruiting
Beware of fraudulent recruiting. Legitimate Dayforce contacts will use an @dayforce.com email address. We do not request money, checks, equipment orders, or sensitive personal data during the recruitment process. If you have been asked for any of the above, or believe you have been contacted by someone posing as a Dayforce employee, please refer to our fraudulent recruiting statement found here:
$142.79k - $172.5k
...Cloud Engineer Principal GDIT is seeking a Cloud Engineer Principal to support our internal GDIT Internal Government Cloud Azure and Oracle... ...services. Collaborate closely with Application, Cybersecurity, and Server/Infrastructure teams to ensure a secure, resilient...PrincipalRemote workNight shiftWeekend work- ...Job Description: Role Overview We are seeking a Principal DevOps Engineer to define and lead infrastructure automation and... ...deployment automation, working closely with Product, Networking, Cybersecurity, and Deployment teams. Key Responsibilities Define...Principal
- ...A leading pharmacy benefit manager is seeking a Principal Systems Engineer specializing in Microsoft 365 and Azure for a remote position. In this role, you will influence strategic direction and drive innovation across enterprise technology. Responsibilities include technical...PrincipalRemote work
- ...STRONG CLOUD/FIN OPS Exp seeking a highly skilled and experienced Sr. Principal Technologist specializing in Financial Operations and Governance across multiple cloud platforms, primarily AWS and Azure, with some exposure to GCP. This critical role in ensuring...Principal
- ...Principal Software Engineer - Credit Card Core Platforms Brazil, Belo Horizonte; Brazil, Campinas; Brazil, Rio de Janeiro; Brazil, Sao Paulo;... ...-Driven Engineering: Architect and integrate AI solutions (cloud-based agents) to automate infrastructure maintenance and data...Principal
$108k - $184k
...career? Come build the future of pharmacy with us.M365/Azure Principal Systems Engineer - RemoteJob DescriptionWe are seeking a Principal Systems... ...strategy, roadmap, and architectural vision for Microsoft cloud solutions across the organization.ResponsibilitiesRepresent...PrincipalWork experience placementLocal areaRemote workWork visa$140k - $190k
...About the job Senior Cloud / DevSecOps Engineer -Top Secret Clearance Required Overview: We are actively building a pipeline of... ...platforms at the intersection of: Cloud Infrastructure Cybersecurity Automation AI-enabled systems If you're...Immediate start- A cybersecurity and intelligence firm is seeking a Cyber Eviction Analyst to support critical incident response missions. The role requires extensive expertise in threat actor tools, incident mitigation, and collaborative problem-solving. Ideal candidates will possess at...Principal
- ...Principal Cybersecurity Solutions Architect As Principal Cybersecurity Solutions Architect you'll design, implement, and manage scalable Cyber... ...mentor and provide technical guidance to a team of cyber engineers and analysts, reviewing their work, and helping them solve...Principal
- ...Security - Information Systems Security Engineer ( ISSE) in Dayton, OH, Hanscom Air Force... ...Bolling Air Force Base, DC. As a Cybersecurity Engineer / Information Systems Security... ...working in a SCIF/SAPF environment. • Cloud Security Implementation experience. •...PrincipalFor contractorsWork at office
- ...leads cyber incidents assigned by the CISO, SOC Director or Sr. Principal, to resolution following industry standard response and... ...written communication skills.Must possess one or more relevant cybersecurity certification such as CISSP, CEH, GCIH, GCIA, or other SANS certifications...PrincipalImmediate start
- ...Government Services company , is seeking a Cloud DevSecOps Engineer to support KDS and our government... ...stage of the development lifecycle. Principal responsibilities will include but... ...'s degree in Computer Science, Cybersecurity, Information Technology, or related...Work experience placementLocal areaFlexible hours1 day per week
$113.2k - $237.8k
...Job Title: Cloud DevSecOps Engineer - Level 3 Job Category: Information Technology Time Type: Full time Minimum Clearance Required... ...Master's degree in Computer Science, Information Technology, Cybersecurity, or a related STEM field. • Experience: 7+ years of...Full timeContract workWork experience placementLocal areaImmediate startFlexible hours- ...Junior Cloud DevSecOps Engineer AWS & Azure Cloud Security NASA Contractor Program Support About the Role We are seeking a Junior... ...entry level position ideal for someone with foundational cybersecurity, cloud, or IT experience who wants to grow in cloud...Full timeContract workTemporary workFor contractorsFlexible hoursShift work
$10k
...Technology Partners is looking for a motivated and collaborative Cloud Consultant to join our growing team supporting modern cloud... ...inception, CTP has been instrumental in the technical design, engineering development, operational deployment, and support of key systems...PrincipalContract workTemporary workFor contractorsLocal area- A leading cybersecurity firm in Arlington, VA, seeks a Principal CNO Developer to enhance its dynamic team. This role offers hybrid work flexibility and demands... ...Windows kernel drivers and knowledge of reverse engineering tools. A Top Secret clearance or higher is...Principal
$238.7k - $365.7k
...Mountain View, CA you are expected to report to that location three times per week, at minimum. The Role The Vehicle Experiences Engine software team is a dynamic and fast paced team that designs, develops, and maintains the embedded software platform for...PrincipalLocal areaRemote workWork from homeRelocation package- ...Senior Cloud Engineer SAIC is seeking a highly skilled and experienced Senior Cloud Engineer to join our team in Alexandria, Virginia... ...-on and combines Azure cloud architecture expertise with cybersecurity to support IL4, IL5, and IL6 environments. The successful candidate...
- A leading cybersecurity firm is seeking experienced Cyber Network Defense Analysts to conduct forensic analysis and respond to cloud security incidents. The ideal candidate will have over 8 years of cybersecurity experience, strong knowledge of hybrid identity security...
- ClearFocus Technologies is looking for an experienced Senior Cloud Security Specialist in Washington, DC. The role involves enhancing cloud security posture, ensuring compliance with federal cybersecurity standards, and collaborating with various teams to implement security...
- ...The Senior Cloud & Cybersecurity Engineer will serve as a key technical SME supporting our government customer across cloud architecture, identity services, and network security. This role replaces a former senior engineer who provided advanced AWS architectural support...
- A leading cybersecurity firm located in Arlington, VA, is seeking a Cloud Forensics Analyst to support U.S. Government agency missions. The role requires in-depth knowledge of network investigations, TCP/IP protocols, and relevant experience. The successful candidate will...
- A leading cybersecurity firm is seeking a Cloud Forensics Analyst to support onsite incident response to cyber-attacks. The role involves acquiring and analyzing computer artifacts, conducting forensic investigations, and developing mitigation strategies. Candidates should...
- ...Background: The IT Security Engineering team is seeking a Senior Cloud Security Specialist with deep expertise in AWS cloud services, cloud-native... ...comprehensive knowledge in adopting and implementing federal cybersecurity requirements, including but not limited to the NIST...Local area
- ...CrowdStrike is seeking a Software Engineer to develop innovative cybersecurity solutions. Located in Washington, you will enhance crowd services and work... ...or Python, with experience in distributed systems and cloud infrastructure. The role offers competitive compensation...Work at officeRemote work
$145.6k - $209.3k
...team that succeeds together. Because at UKG, your work matters-and so do you. About the Role We are seeking a Principal Cloud Platform Software Engineer in Enterprise Solutions and Experience (ESE) org to lead the architecture and development of a cloud-native...PrincipalLocal area$126.9k - $215.3k
...Y Stock Package: Y Expiration Date: 06/03/2026 The Principal Engineer, Guest Communications Platform serves as the technical authority... ...role is responsible for defining, governing, and evolving a cloud‑native, event ‑driven, provider‑agnostic communications...PrincipalFull timeRemote workFlexible hours$99.6k - $223.4k
...Applications and help build the next generation of cloud-native EHR platforms that directly... ...outcomes. We're looking for senior engineers with deep Java expertise, exceptional... ...holders. Responsibilities Senior Principal Engineer - Cloud, AI & Healthcare Platforms...PrincipalFull timeTemporary workRemote workFlexible hours- A cybersecurity firm is seeking a Cyber Network Defense Analyst with expertise in cloud forensics to support federal missions. Responsibilities include conducting forensic investigations, developing detection logic, and collaborating with government teams. The ideal candidate...Remote job
- Dragonfli Group in Washington, DC, is looking for a Senior Cloud Security Engineer to implement security strategies in a large federal... ...Candidates should have at least 8 years of experience in cybersecurity, with a focus on cloud architecture. Comprehensive benefits...Permanent employment
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Cybersecurity Cloud Engineer. Be the first to apply!
- director data engineering Washington DC
- senior civil engineer project manager Washington DC
- principal cloud engineer Washington DC
- director systems engineering Washington DC
- engineering director Washington DC
- principal security engineer Washington DC
- principal infrastructure engineer Washington DC
- principal network engineer Washington DC
- chief engineer Washington DC
- civil engineer project manager Washington DC

