{"schemaVersion":"jobsearcher.job.v1","id":"689d6361f40b6c8ac06e0da3","url":"https://jobsearcher.com/jobs/689d6361f40b6c8ac06e0da3","canonicalUrl":"https://jobsearcher.com/jobs/689d6361f40b6c8ac06e0da3","title":"Cloud Security Specialist – Platforms Engineering","description":"Xona is the navigational intelligence company bringing real-time, centimeter-level certainty to any device, anywhere on Earth.\n\nWith Pulsar – the world’s most advanced PNT satellite infrastructure in Low Earth Orbit – Xona will offer a future-proof, backwards-compatible global positioning system optimized for absolute precision, superior power, and robust protection.\n\nOverview\n\nWe are seeking a proactive and skilled Cloud Security Specialist to join our dynamic Platforms Engineering team. In this role, you will be the security champion embedded within our platform infrastructure, ensuring that our cloud environments, container orchestration platforms, and developer tooling are secure by design.\n\nYou will work closely with platform engineers, DevOps, and enterprise security teams to build secure foundational services, automate compliance guardrails, and foster a strong culture of security across the engineering organization.\n\nWe are seeking a specialized Cloud Security Engineer to anchor security into the core of our Platform Engineering team. In this role, you will be responsible for designing, implementing, and automating security guardrails across our AWS cloud infrastructure and deployment pipelines. Rather than acting as a traditional compliance-only gatekeeper, you will champion a \"shift-left\" DevSecOps culture—building secure defaults, automated policy enforcement, and self-service security tooling that empower engineering teams to move fast safely.\n\nKey Responsibilities\n\nCloud Security Architecture & Hardening: Design and enforce secure cloud patterns, zero-trust network segmentation, and hardening standards across our AWS multi-account architecture and container platforms (e.g., Kubernetes).\n\nIdentity and Access Management (IAM): Architect secure authentication, authorization, secrets management, and zero-trust networking principles across all platform services.\n\nAutomation & Guardrails: Build automated security guardrails that empower developers to move fast safely, minimizing friction while maintaining strict compliance standards (e.g., CMMC, NIST 800-171, FIPS 140-3).\n\nVulnerability & Threat Management: Conduct regular security assessments, penetration testing, threat modeling, and container vulnerability scanning; coordinate remediation efforts with platform teams.\n\nIncident Response & Forensics: Partner with SRE and operations teams to monitor security telemetry, triage cloud threats, and participate in incident response and root-cause analysis.\n\nQualifications & Requirements\n\nExperience: 4+ years of experience in cloud security, DevOps, or platform engineering, with a strong emphasis on security operations and architecture.\n\nCloud Expertise: Deep hands-on experience securing cloud environments (AWS, GCP, or Azure). Certifications such as AWS Certified Security, CISSP, or CCSK are a plus.\n\nContainer & Kubernetes Security: Strong understanding of containerization security best practices, image hardening, and Kubernetes security controls (RBAC, network policies, runtime security).\n\nScripting & Automation: Proficiency in languages such as Python, Go, or Bash, and experience with automation tools.\n\nSecurity Tooling: Familiarity with CI/CD security integrations, Static Application Security Testing (SAST), Software Bill of Materials (SBOM), Security Information and Event Management (SIEM), and cloud security posture management (CSPM) tools.\n\nPreferred Qualifications\n\nExperience implementing Zero Trust architectures within a modern enterprise.\n\nFamiliarity with Policy-as-Code frameworks (e.g., Open Policy Agent).\n\nDemonstrated passion for developer enablement and building \"security as a product\" rather than a roadblock.\n\nFor U.S. Roles: To comply with U.S. Government space technology export regulations, applicant must be a U.S. citizen, lawful permanent resident of the United States (i.e. Green Card holder), or other protected individual as defined by 8 U.S.C. 1324b(a)(3).\n\nFor U.K. Roles: To comply with U.K. regulations, this role requires Baseline Personnel Security Standard (BPSS) checks, and successful candidates must be eligible to obtain UK Security Clearance (SC).\n\nFor Canada Roles: Successful candidates must obtain and hold a security clearance at the reliability status level, and pass security assessment for the Canadian Controlled Goods Program (CGP) and ITAR.\n\nWe celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.\n\nCompensation Range: $153K - $178K","company":"Xonaspacesystems","rawCompany":"xonaspacesystems","city":"Burlingame","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-09-09T08:57:40.057Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Cloud Security Specialist – Platforms Engineering","description":"Xona is the navigational intelligence company bringing real-time, centimeter-level certainty to any device, anywhere on Earth.\n\nWith Pulsar – the world’s most advanced PNT satellite infrastructure in Low Earth Orbit – Xona will offer a future-proof, backwards-compatible global positioning system optimized for absolute precision, superior power, and robust protection.\n\nOverview\n\nWe are seeking a proactive and skilled Cloud Security Specialist to join our dynamic Platforms Engineering team. In this role, you will be the security champion embedded within our platform infrastructure, ensuring that our cloud environments, container orchestration platforms, and developer tooling are secure by design.\n\nYou will work closely with platform engineers, DevOps, and enterprise security teams to build secure foundational services, automate compliance guardrails, and foster a strong culture of security across the engineering organization.\n\nWe are seeking a specialized Cloud Security Engineer to anchor security into the core of our Platform Engineering team. In this role, you will be responsible for designing, implementing, and automating security guardrails across our AWS cloud infrastructure and deployment pipelines. Rather than acting as a traditional compliance-only gatekeeper, you will champion a \"shift-left\" DevSecOps culture—building secure defaults, automated policy enforcement, and self-service security tooling that empower engineering teams to move fast safely.\n\nKey Responsibilities\n\nCloud Security Architecture & Hardening: Design and enforce secure cloud patterns, zero-trust network segmentation, and hardening standards across our AWS multi-account architecture and container platforms (e.g., Kubernetes).\n\nIdentity and Access Management (IAM): Architect secure authentication, authorization, secrets management, and zero-trust networking principles across all platform services.\n\nAutomation & Guardrails: Build automated security guardrails that empower developers to move fast safely, minimizing friction while maintaining strict compliance standards (e.g., CMMC, NIST 800-171, FIPS 140-3).\n\nVulnerability & Threat Management: Conduct regular security assessments, penetration testing, threat modeling, and container vulnerability scanning; coordinate remediation efforts with platform teams.\n\nIncident Response & Forensics: Partner with SRE and operations teams to monitor security telemetry, triage cloud threats, and participate in incident response and root-cause analysis.\n\nQualifications & Requirements\n\nExperience: 4+ years of experience in cloud security, DevOps, or platform engineering, with a strong emphasis on security operations and architecture.\n\nCloud Expertise: Deep hands-on experience securing cloud environments (AWS, GCP, or Azure). Certifications such as AWS Certified Security, CISSP, or CCSK are a plus.\n\nContainer & Kubernetes Security: Strong understanding of containerization security best practices, image hardening, and Kubernetes security controls (RBAC, network policies, runtime security).\n\nScripting & Automation: Proficiency in languages such as Python, Go, or Bash, and experience with automation tools.\n\nSecurity Tooling: Familiarity with CI/CD security integrations, Static Application Security Testing (SAST), Software Bill of Materials (SBOM), Security Information and Event Management (SIEM), and cloud security posture management (CSPM) tools.\n\nPreferred Qualifications\n\nExperience implementing Zero Trust architectures within a modern enterprise.\n\nFamiliarity with Policy-as-Code frameworks (e.g., Open Policy Agent).\n\nDemonstrated passion for developer enablement and building \"security as a product\" rather than a roadblock.\n\nFor U.S. Roles: To comply with U.S. Government space technology export regulations, applicant must be a U.S. citizen, lawful permanent resident of the United States (i.e. Green Card holder), or other protected individual as defined by 8 U.S.C. 1324b(a)(3).\n\nFor U.K. Roles: To comply with U.K. regulations, this role requires Baseline Personnel Security Standard (BPSS) checks, and successful candidates must be eligible to obtain UK Security Clearance (SC).\n\nFor Canada Roles: Successful candidates must obtain and hold a security clearance at the reliability status level, and pass security assessment for the Canadian Controlled Goods Program (CGP) and ITAR.\n\nWe celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.\n\nCompensation Range: $153K - $178K","datePosted":"2026-09-09T08:57:40.057Z","dateModified":"2026-09-09T08:57:40.057Z","hiringOrganization":{"@type":"Organization","name":"Xonaspacesystems","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Burlingame","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"689d6361f40b6c8ac06e0da3"},"url":"https://jobsearcher.com/jobs/689d6361f40b6c8ac06e0da3"}}