{"schemaVersion":"jobsearcher.job.v1","id":"fdcfd6b0d9fa89b5bdfd9f52","url":"https://jobsearcher.com/jobs/fdcfd6b0d9fa89b5bdfd9f52","canonicalUrl":"https://jobsearcher.com/jobs/fdcfd6b0d9fa89b5bdfd9f52","title":"Principal Cloud Security Engineer","description":"About Invesco As one of the world's leading independent global investment firms, Invesco is dedicated to rethinking possibilities for our clients. By delivering the combined power of our distinctive investment management capabilities, we provide a wide range of investment strategies and vehicles to our clients around the world. If you're looking for challenging work, intelligent colleagues, and exposure across a global footprint, come explore your potential at Invesco.\r\nWhat's in it for you? Our people are at the very core of our success. Invesco employees get more out of life through our comprehensive compensation and benefit offerings including:\r\nFlexible paid time off\r\nHybrid work schedule\r\n401(K) matching of 100% up to the first 6% with a discretionary supplemental contribution\r\nHealth & wellbeing benefits\r\nParental Leave benefits\r\nEmployee stock purchase plan\r\nJob Description The Department Our Information Security department is to protect Invesco's information and Information assets from all internal and external, deliberate, or accidental threats. The information security team will protect data from unauthorized access while maintaining the confidentiality, integrity, and availability of information. In addition, designing and maintaining the Security Policies and Standards while adhering to legislative and regulatory requirements, providing information security training for all employees, and ensuring the business continuity of Invesco.\r\nYour Role Principal Engineer Cloud Security will work closely with technology and application teams to help them secure their cloud environment. In this role, you will partner with Infrastructure teams to provide secure cloud requirements, and ensure the solutions and infrastructure are securely designed, developed, and implemented, while enforcing conformity with technical standards and approved cloud security architectures that align to regulatory and compliance standards.\r\nYou will be responsible for: Designing, configuring, and implementing secure solutions for the firm's global cloud infrastructure in partnership with architects and engineering teams.\r\nDefining cloud security technical requirements, including IAM, network segmentation, data protection, container security, workload protection, CI/CD security, Kubernetes, microservices, SIEM integrations, and more.\r\nDeveloping security patterns and controls for Data Loss Prevention (DLP) across cloud, endpoint, and SaaS environments—including policies, detection tuning, and data governance alignment.\r\nDriving SaaS Security strategy, including secure configuration baselines, CASB/CSPM integrations, continuous monitoring, and third-party SaaS risk assessment.\r\nStrategizing and maturing cloud security solutions to improve compliance with the NIST Cybersecurity Framework, Cloud Security Alliance guidance, and Invesco policies.\r\nDeveloping and deploying infrastructure-as-code to automate and optimize cloud security controls.\r\nProviding technical support for patches, upgrades, incident response, and operational improvements.\r\nPerforming security threat modeling and design reviews for emerging cloud and SaaS technologies.\r\nThe experience you bring: 10+ years of information security experience supporting enterprise-scale security engineering and architecture programs.\r\n5+ years designing and implementing enterprise cloud security solutions across AWS, Azure, Oracle, and other major cloud providers.\r\nExperience with Terraform for deployment automation, orchestration, and security configuration management.\r\nProficiency in scripting (Python, PowerShell, JSON).\r\nExperience developing and institutionalizing security standards, blueprints, and patterns aligned to frameworks such as SOX, CSA-CCM, DORA, NIST, ISO, GDPR, and SOC1/2.\r\nHands-on experience with Data Loss Prevention programs, including policy creation, tuning, incident handling, and integrating DLP with cloud and SaaS platforms.\r\nExperience with SaaS Security technologies, such as CASB, SSPM (SaaS Security Posture Management), and SaaS risk assessment frameworks.\r\nKnowledge of cloud and endpoint security tools such as CrowdStrike and Wiz.\r\nHands-on experience with AWS native security services including Control Tower, CloudWatch, GuardDuty, CloudTrail, Config, Lambda, Trusted Advisor, AWS Organizations, Transit Gateway, AWS SSO, and others.\r\nExtensive experience with AWS services including EC2, IAM, Route53, SSM, S3, EFS, EBS, ELB, EKS, ECS, Lambda, CloudFormation, CloudFront, DynamoDB, Athena, Kinesis, and more.\r\n5+ years working in DevOps environments with applied Agile practices.\r\nExperience conducting threat modeling for cloud and SaaS technologies.\r\nWillingness to travel domestically and internationally as needed.\r\nBachelor's Degree in MIS or Computer Science preferred, or equivalent work experience.\r\nPreferred certifications: CISSP, CCSP, CCSK.\r\nPreferred cloud provider certifications (AWS, Azure, GCP).\r\nFull Time / Part Time Full time\r\nWorker Type Employee\r\nJob Exempt (Yes / No) Yes\r\nWorkplace Model Pursuant to Invesco's Workplace Policy, employees are expected to comply with the firm's most current workplace model, which as of October 1, 2025, includes spending at least four full days each week working in an Invesco office. This reflects our belief that spending time together in the office helps us build stronger relationships, collaborate more easily, and support each other's growth and development.\r\nThe above information on this description has been designed to indicate the general nature and level of work performed by employees within this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job. The job holder may be required to perform other duties as deemed appropriate by their manager from time to time.\r\nInvesco's culture of inclusivity and its commitment to diversity in the workplace are demonstrated through our people practices. We are proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, creed, color, religion, sex, gender, gender identity, sexual orientation, marital status, national origin, citizenship status, disability, age, or veteran status. Our equal opportunity employment efforts comply with all applicable U.S. state and federal laws governing non-discrimination in employment.\r\nJ-18808-Ljbffr","company":"Invesco","rawCompany":"invesco","city":"Atlanta","state":"GA","isRemote":false,"isActive":false,"createdAt":"2026-04-09T08:00:04.970Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541513","title":"Computer Facilities Management Services","slug":"computer-facilities-management-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Principal Cloud Security Engineer","description":"About Invesco As one of the world's leading independent global investment firms, Invesco is dedicated to rethinking possibilities for our clients. By delivering the combined power of our distinctive investment management capabilities, we provide a wide range of investment strategies and vehicles to our clients around the world. If you're looking for challenging work, intelligent colleagues, and exposure across a global footprint, come explore your potential at Invesco.\r\nWhat's in it for you? Our people are at the very core of our success. Invesco employees get more out of life through our comprehensive compensation and benefit offerings including:\r\nFlexible paid time off\r\nHybrid work schedule\r\n401(K) matching of 100% up to the first 6% with a discretionary supplemental contribution\r\nHealth & wellbeing benefits\r\nParental Leave benefits\r\nEmployee stock purchase plan\r\nJob Description The Department Our Information Security department is to protect Invesco's information and Information assets from all internal and external, deliberate, or accidental threats. The information security team will protect data from unauthorized access while maintaining the confidentiality, integrity, and availability of information. In addition, designing and maintaining the Security Policies and Standards while adhering to legislative and regulatory requirements, providing information security training for all employees, and ensuring the business continuity of Invesco.\r\nYour Role Principal Engineer Cloud Security will work closely with technology and application teams to help them secure their cloud environment. In this role, you will partner with Infrastructure teams to provide secure cloud requirements, and ensure the solutions and infrastructure are securely designed, developed, and implemented, while enforcing conformity with technical standards and approved cloud security architectures that align to regulatory and compliance standards.\r\nYou will be responsible for: Designing, configuring, and implementing secure solutions for the firm's global cloud infrastructure in partnership with architects and engineering teams.\r\nDefining cloud security technical requirements, including IAM, network segmentation, data protection, container security, workload protection, CI/CD security, Kubernetes, microservices, SIEM integrations, and more.\r\nDeveloping security patterns and controls for Data Loss Prevention (DLP) across cloud, endpoint, and SaaS environments—including policies, detection tuning, and data governance alignment.\r\nDriving SaaS Security strategy, including secure configuration baselines, CASB/CSPM integrations, continuous monitoring, and third-party SaaS risk assessment.\r\nStrategizing and maturing cloud security solutions to improve compliance with the NIST Cybersecurity Framework, Cloud Security Alliance guidance, and Invesco policies.\r\nDeveloping and deploying infrastructure-as-code to automate and optimize cloud security controls.\r\nProviding technical support for patches, upgrades, incident response, and operational improvements.\r\nPerforming security threat modeling and design reviews for emerging cloud and SaaS technologies.\r\nThe experience you bring: 10+ years of information security experience supporting enterprise-scale security engineering and architecture programs.\r\n5+ years designing and implementing enterprise cloud security solutions across AWS, Azure, Oracle, and other major cloud providers.\r\nExperience with Terraform for deployment automation, orchestration, and security configuration management.\r\nProficiency in scripting (Python, PowerShell, JSON).\r\nExperience developing and institutionalizing security standards, blueprints, and patterns aligned to frameworks such as SOX, CSA-CCM, DORA, NIST, ISO, GDPR, and SOC1/2.\r\nHands-on experience with Data Loss Prevention programs, including policy creation, tuning, incident handling, and integrating DLP with cloud and SaaS platforms.\r\nExperience with SaaS Security technologies, such as CASB, SSPM (SaaS Security Posture Management), and SaaS risk assessment frameworks.\r\nKnowledge of cloud and endpoint security tools such as CrowdStrike and Wiz.\r\nHands-on experience with AWS native security services including Control Tower, CloudWatch, GuardDuty, CloudTrail, Config, Lambda, Trusted Advisor, AWS Organizations, Transit Gateway, AWS SSO, and others.\r\nExtensive experience with AWS services including EC2, IAM, Route53, SSM, S3, EFS, EBS, ELB, EKS, ECS, Lambda, CloudFormation, CloudFront, DynamoDB, Athena, Kinesis, and more.\r\n5+ years working in DevOps environments with applied Agile practices.\r\nExperience conducting threat modeling for cloud and SaaS technologies.\r\nWillingness to travel domestically and internationally as needed.\r\nBachelor's Degree in MIS or Computer Science preferred, or equivalent work experience.\r\nPreferred certifications: CISSP, CCSP, CCSK.\r\nPreferred cloud provider certifications (AWS, Azure, GCP).\r\nFull Time / Part Time Full time\r\nWorker Type Employee\r\nJob Exempt (Yes / No) Yes\r\nWorkplace Model Pursuant to Invesco's Workplace Policy, employees are expected to comply with the firm's most current workplace model, which as of October 1, 2025, includes spending at least four full days each week working in an Invesco office. This reflects our belief that spending time together in the office helps us build stronger relationships, collaborate more easily, and support each other's growth and development.\r\nThe above information on this description has been designed to indicate the general nature and level of work performed by employees within this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job. The job holder may be required to perform other duties as deemed appropriate by their manager from time to time.\r\nInvesco's culture of inclusivity and its commitment to diversity in the workplace are demonstrated through our people practices. We are proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, creed, color, religion, sex, gender, gender identity, sexual orientation, marital status, national origin, citizenship status, disability, age, or veteran status. Our equal opportunity employment efforts comply with all applicable U.S. state and federal laws governing non-discrimination in employment.\r\nJ-18808-Ljbffr","datePosted":"2026-04-09T08:00:04.970Z","dateModified":"2026-04-09T08:00:04.970Z","hiringOrganization":{"@type":"Organization","name":"Invesco","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Atlanta","addressRegion":"GA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"fdcfd6b0d9fa89b5bdfd9f52"},"url":"https://jobsearcher.com/jobs/fdcfd6b0d9fa89b5bdfd9f52"}}