CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

Senior Cloud Security Engineer

Beyondfinance • Remote

Job Description

<div class="content-intro"><p class="c-mrkdwn__pre" style="text-align: left;" data-stringify-type="pre">At Beyond Finance, we've made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care,<strong> </strong>a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions, we've helped over 1 million clients on their path to a brighter future.</p> <p class="c-mrkdwn__pre" style="text-align: left;" data-stringify-type="pre">While we're proud of what we've already accomplished, we're searching for new collaborators to help us get to the next level! If you're looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.</p></div><h2>The Role</h2> <p>As a Senior Security Engineer, you'll harden the security posture of our AWS environment and our software development pipeline. Cloud Security and vulnerability management in Wiz are the primary focus.</p> <p>You'll partner with DevOps, Engineering, and our Application Security Engineer to build preventative controls across infrastructure, identity, and CI/CD. The work is hands-on: configuring tooling, reviewing architecture, hardening pipelines, and supporting application security work where your range is needed.</p> <h2>Key Responsibilities</h2> <ul> <li>Own cloud security posture across our AWS environment using Wiz and AWS-native services, reducing risk across IAM, network segmentation, container security, secrets, and data exposure.</li> <li>Establish secure defaults in our Infrastructure as Code through reusable modules, guardrails, and policy as code.</li> <li>Harden CI/CD pipelines in partnership with DevOps.</li> <li>Run vulnerability management across cloud and application findings: intake, prioritization, SLA tracking, and remediation with engineering.</li> <li>Build automation that scales the program: ingestion, deduplication, prioritization, and developer-facing workflows.</li> <li>Instrument telemetry, alerting, and runbooks for the systems you own.</li> <li>Operate and tune our WAF: managed and custom rules, rate limiting, and bot mitigation.</li> </ul> <h2>Requirements</h2> <ul> <li>5+ years of hands-on security engineering across cloud security and vulnerability management.</li> <li>Strong AWS security background: IAM, networking, container orchestration, and logging and audit.</li> <li>Hands-on experience securing CI/CD pipelines and Infrastructure as Code; Terraform required.</li> <li>Experience running or substantially contributing to a vulnerability management program.</li> <li>Working knowledge of OWASP Top 10 and threat modeling.</li> <li>Operates independently and drives projects without day-to-day oversight.</li> </ul> <h2>Nice to Have</h2> <ul> <li>Experience with our stack: Wiz, Cloudflare (WAF, Gateway, Zero Trust), GitHub Advanced Security, Spacelift, and AWS-native services.</li> <li>Hands-on WAF experience in production: writing and tuning rules, managing false positives, responding when something gets through.</li> <li>AI/ML security exposure: prompt injection, data poisoning, model abuse, and the controls that mitigate them.</li> <li>Secrets management platforms (AWS Secrets Manager, Keeper, Infisical).</li> <li>Identity security across human and non-human identities.</li> <li>PCI-regulated or financial services environment.</li> <li>Familiarity with Ruby on Rails, Python, or Go.</li> </ul> <h2>The Ideal Candidate</h2>

Job Reference ID: CF-163319 • Posted on CloudFrame Job Scanner