JOBSEARCHER

Cloud Security Engineer

Cloud Security Engineer Screen Engine/ASI — the leading technology innovator in media and entertainment market research, is seeking a Cloud Security Engineer to help secure, monitor, and improve our cloud-first technology environment. Work Arrangement: Hybrid – Primarily remote (Greater Los Angeles area) with bi-weekly on-site presence at our Valley Village office for in-person collaboration, meetings, project work, and on-site coverage when needed. As a Cloud Security Engineer, you will support the design, implementation, and day-to-day administration of secure cloud infrastructure with a strong emphasis on AWS, identity and access management, and security auditing. This role’s primary focus is AWS cloud security, IAM configuration and governance, security operations, and audit participation and remediation. Secondary responsibilities include Tier 2/3 support and broader enterprise security support as needed, including acting as on-site backup when the IT Director is unavailable and in-office presence is required. The ideal candidate brings a solid foundation in AWS and cloud security, strong attention to detail, and an interest in growing further in cloud security engineering. Over time, this role is expected to expand in scope toward broader DevOps engineering capabilities, practical AI adoption, greater ownership of security initiatives, and the ability to back up the IT Director in administering core productivity and collaboration environments during planned absences. Essential Duties & Responsibilities Primary Focus: AWS, Security & Auditing Support the administration and security of AWS cloud infrastructure including IAM, VPC, EC2, RDS, CloudWatch, VPN, routing, and CIDR/IP range management. Administer AWS IAM policies, roles, groups, and least-privilege access controls. Support identity governance activities including access reviews, permission cleanup, role-based access alignment, SSO integrations, MFA, and related identity security controls. Support cloud security monitoring, alert triage, vulnerability follow-up, and incident response activities. Help enforce cloud security standards, secure configuration baselines, and least-privilege practices. Participate in regular security audits across cloud infrastructure, identity systems, endpoints, and SaaS platforms. Document audit findings, control gaps, remediation actions, and maintain audit evidence and security documentation. Track remediation efforts and support alignment of security controls with established frameworks such as SOC 2, NIST CSF, ISO 27001, and CCPA. Assist with AWS infrastructure monitoring, alerting, and operational visibility using CloudWatch dashboards, alerts, and notifications. Support AWS billing review, cost visibility, and optimization tracking. Assist with infrastructure configuration and automation using Terraform and AWS Systems Manager (SSM). Secondary Focus: Tier 2/3 Support & Enterprise Security Provide Tier 2/3 technical support for cloud systems, identity platforms, remote access, and security-related issues escalated from frontline support. Support end users and internal teams with Tier 2/3 access, authentication, device, and connectivity issues that require deeper cloud or security expertise. Troubleshoot service interruptions, coordinate follow-up actions, and communicate updates to stakeholders while partnering with frontline support on issue resolution. Work on both escalated support tickets and larger cloud/security projects (e.g., IAM redesign, audit remediation, security tooling rollouts). Collaborate with the help desk / frontline support function to ensure efficient handoff of Tier 1 versus Tier 2/3 issues as business needs require. Support the administration and continuous improvement of enterprise security controls across cloud, identity, endpoint, collaboration, and SaaS environments. Participate in organization-wide security initiatives including policy implementation, security reviews, risk reduction efforts, and remediation tracking. Help assess security posture across business systems and contribute to recommendations that improve overall enterprise security resilience. Serve as an on-site backup to the IT Director for critical in-office needs at the Valley Village location when physical presence is required (e.g., hardware access, vendor visits, office-specific troubleshooting). Growth Goals Develop toward broader DevOps engineering capabilities, including infrastructure automation, deployment support, systems reliability, and operational efficiency in cloud environments. Evaluate practical AI-driven tools that can improve security operations, access reviews, audit preparation, reporting, and IT workflow efficiency. Identify responsible uses of AI for automation, analysis, and operational productivity within cloud and security functions. Stay current with emerging AI capabilities relevant to cloud security and provide recommendations for safe adoption. Over time, develop the capability to back up the IT Director in administering core productivity and collaboration environments during planned absences. Documentation & Collaboration Maintain accurate documentation for AWS configurations, IAM policies, audit records, and security procedures. Collaborate with cross-functional teams to improve security controls and support project delivery. Provide clear communication and knowledge sharing with internal stakeholders. Position Qualifications This position requires excellent project and time management skills as well as the following qualifications: Required 2–5 years of experience in cloud infrastructure, cloud security, systems administration, or a related IT/security role. Hands-on experience with AWS, especially IAM, VPC, EC2, CloudWatch, VPN, routing, and identity-related administration. Experience with IAM configuration, access control, permission reviews, security auditing, and cloud security responsibilities. Familiarity with security documentation, audit preparation, control validation, and remediation tracking. Working knowledge of SSO, MFA, least-privilege access, and identity governance concepts. Familiarity with Terraform, AWS Systems Manager (SSM), or other infrastructure automation tools. TCP/IP, DNS, VPN, and general networking fundamentals. Ability to troubleshoot Tier 2/3 operational issues and provide hands-on escalated support when needed. Preferred AWS certifications preferred, especially AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate, or AWS Certified SysOps Administrator – Associate. Familiarity with cloud security monitoring, vulnerability management, and incident response processes. Exposure to compliance or security frameworks such as SOC 2, NIST CSF, ISO 27001, or CCPA. Experience with enterprise security initiatives across SaaS, endpoint, identity, or collaboration environments. Interest in evaluating AI-driven tools for security and IT operations. Scripting and automation experience (PowerShell, Python, or Bash). Pay: $100,000.00 - $120,000.00 per year Benefits: 401(k) 401(k) matching Dental insurance Employee assistance program Flexible spending account Health insurance Health savings account Life insurance Paid time off Retirement plan Tuition reimbursement Vision insurance Work Location: Hybrid remote in Valley Village, CA 91607