Posted 02 August, 2026
Sr. Cloud Security Engineer
LHH US
San Francisco, CA, US
Full Time
Job Description
Job Description
LHH is seeking a Sr. Cloud Security Engineer to join our client's team in a full-time + hybrid-role, based in San Francisco, CA. This is an emerging enterprise intelligence startup focused on enabling organizations to effectively manage and optimize a blended workforce of human employees and autonomous AI systems.
About the role: Our client is building a cloud-native, agentic AI SaaS platform on an Azure-native stack and are looking for a hands-on Sr. Cloud Security Engineer to own the intersection of platform engineering, cloud security, and DevSecOps automation. This person will turn security controls into code, strengthen the platform before go-to-market, and help protect developer velocity while raising the company's security and compliance posture.
Salary and Benefits:
Essential Job Functions :
To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to https://www.lhh.com/us/en/candidate-privacy
The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
• The California Fair Chance Act
• Los Angeles City Fair Chance Ordinance
• Los Angeles County Fair Chance Ordinance for Employers
• San Francisco Fair Chance Ordinance
Pay Details: $180,000.00 to $250,000.00 per year
Search managed by: Chris Watson
Equal Opportunity Employer/Veterans/Disabled
Military connected talent encouraged to apply
To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to https://www.lhh.com/us/en/candidate-privacy
The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
About the role: Our client is building a cloud-native, agentic AI SaaS platform on an Azure-native stack and are looking for a hands-on Sr. Cloud Security Engineer to own the intersection of platform engineering, cloud security, and DevSecOps automation. This person will turn security controls into code, strengthen the platform before go-to-market, and help protect developer velocity while raising the company's security and compliance posture.
Salary and Benefits:
- $180k to $250k + equity (DOE)
- Medical, dental, and vision insurance
- 401(k) plan w/match
- 19 days of PTO + 11 paid holidays
- Required: 8+ years of experience across DevOps, SRE, cloud security, security engineering, or platform engineering, with senior-level depth and a track record of building in fast-moving environments.
- Required: Deep hands-on experience with Terraform, including writing modules or plans from scratch and applying infrastructure-as-code practices across environments.
- Required: Strong Kubernetes and container security experience, preferably with AKS in production or near-production environments.
- Required: GitOps experience with Argo CD strongly preferred; Flux experience is also relevant if you can quickly adapt to Argo CD.
- Required: Enterprise-grade DevSecOps capability across CI/CD security, scanning automation, policy-as-code, vulnerability management, incident response, and secure release practices.
- Required: Azure security depth is preferred, including Defender for Cloud, Sentinel, Entra ID, managed identities, RBAC, PIM, Key Vault, ACR, and Azure networking. Strong AWS or GCP cloud security experience may be considered if paired with the ability to ramp quickly in Azure.
- Required: Experience contributing to compliance or certification efforts such as ISO, SOC 2, NIST, or similar frameworks, especially through evidence automation or control implementation.
- Required: Ability to work independently, identify where you can add value, and execute with limited technical oversight in a startup-style build environment.
- Required: Clear communication, sound judgment, low ego, professionalism, and a collaborative approach to working with engineering, infrastructure, security, and GRC partners.
- Nice to have: AI/ML platform security exposure, including Azure AI Foundry, OWASP LLM Top 10, MITRE ATLAS, or NIST AI RMF.
- Nice to have: Azure security certifications such as AZ-500 or SC-100, Kubernetes security certifications such as CKS, or other relevant cloud/security credentials.
- Nice to have: Experience in high-growth SaaS, startup, platform engineering, or product-led environments where security must be embedded into how software is built and shipped.
Essential Job Functions :
- Build, author, and operate secure infrastructure as code using Terraform, including reusable modules and plans created from scratch rather than only maintaining existing templates.
- Own Kubernetes platform security for AKS, including hardened baselines, network policy, admission control, runtime protection, and practical hands-on implementation of security controls.
- Drive GitOps delivery with Argo CD, including AKS manifest drift management, release automation, controlled deployment workflows, and rollback or failback patterns where needed.
- Build and operate secure CI/CD pipelines with SAST, DAST, dependency, container, and infrastructure scanning as automated quality gates without unnecessarily slowing engineering teams.
- Implement policy-as-code and Azure-native controls across the cloud landing zone, including Azure Policy and secure patterns for identity, access, and privileged operations.
- Operate and tune Azure security tooling, including Microsoft Defender for Cloud, Microsoft Sentinel, Key Vault, Entra ID, RBAC, managed identities, and PIM.
- Partner with engineering and SRE to define monitoring policies, alert triggers, and incident response workflows for the platform.
- Help operationalize the vulnerability management program, including remediation workflows, prioritization, ownership, and reduce false positives across scanning and WAF-related processes.
- Support secure software supply chain practices, including signed images, SBOMs, provenance, hardened base images, and policy-enforced registries.
- Contribute technical evidence and automation to support ISO 27001 / 42001 and SOC 2 certification efforts, in partnership with GRC and infrastructure stakeholders.
To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to https://www.lhh.com/us/en/candidate-privacy
The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
• The California Fair Chance Act
• Los Angeles City Fair Chance Ordinance
• Los Angeles County Fair Chance Ordinance for Employers
• San Francisco Fair Chance Ordinance
Pay Details: $180,000.00 to $250,000.00 per year
Search managed by: Chris Watson
Equal Opportunity Employer/Veterans/Disabled
Military connected talent encouraged to apply
To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to https://www.lhh.com/us/en/candidate-privacy
The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
- The California Fair Chance Act
- Los Angeles City Fair Chance Ordinance
- Los Angeles County Fair Chance Ordinance for Employers
- San Francisco Fair Chance Ordinance
