JOBSEARCHER

Senior Security Engineer - Cloud Security

PagerDutyMillbrae, CAL6 LeadSeptember 22nd, 2026
Overview As a Senior Security Engineer on the Cloud Security team, you own security posture across PagerDuty’s multi-account AWS and Kubernetes environments, focusing on identity, cryptography, and platform-wide controls. You will partner with numerous engineering teams to ship security as code, while aligning with FedRAMP, CIS, and NSA/CISA guidelines. The role blends hands-on hardening with defining standards, automation, and evidence-driven risk reduction. You’ll work in a fast, AI-enabled security function that enables scalable, trusted operations. Compensation / BenefitsCompetitive salaryComprehensive benefits packageFlexible work arrangementsCompany equityESPPPaid parental leave ResponsibilitiesHarden AWS and Kubernetes environments to CIS, DISA, and FedRAMP baselines across multi-account footprintSecure EKS clusters and Istio service mesh per relevant benchmarksDesign and enforce RBAC, least-privilege workload identity, and container supply-chain controlsOwn PKI and encryption standards, including certificate lifecycle, KMS-based key management, TLS/mTLS, and encryption at rest/in transitDesign SCP guardrails and least-privilege IAM across accounts and orgsLeverage AI tooling to streamline security work and develop lightweight agentic solutionsDefine and tune detections in SIEM for Kubernetes, identity, and cryptography threats; threat hunt and incident responseAutomate security controls as code with Terraform and Python; implement policy-as-codeCoordinate with AppSec and GRC to translate hardening work into audit evidenceMentor teammates; contribute to roadmap and planning; communicate with external auditors as neededParticipate in on-call rotations as Incident Lead during cloud/Kubernetes incidents; drive containment and post-incident reviewPartner with teams to align platform controls with secure-development needs and compliance evidence Key requirements5+ years as Security Engineer in AWS-native, microservice SaaS environmentDeep expertise securing Kubernetes and containerized environments (EKS, RBAC, admission control, network policy, workload identity)Container runtime and image security; familiarity with Istio preferredStrong PKI and cryptography expertise (certificate lifecycle, TLS/mTLS, KMS or similar)Extensive AWS security service experience (IAM, Organizations/SCPs, Secrets Manager, KMS, GuardDuty, CloudTrail, Config)Ability to inform and drive detection strategy in SIEM; threat hunting for container, identity, cryptography threatsBuilder mindset for AI-assisted security automation; experience with agentic toolingIncident response and on-call experience; triage and containmentInfrastructure as Code and programming experience (Terraform and Python); Kubernetes policy-as-codeProven ability to scope ambiguous projects and drive to completion with ownershipMentoring and coachingStrong written and verbal communicationOwnership mindset and proactive planningKubernetes security (EKS, RBAC, admission control, network policy)Istio service meshRBAC and workload identity