This role offers a rare chance to build cloud security and IAM maturity programs from the ground up rather than caretake an existing one, with the Senior Cloud Security Engineer owning compliance, identity strategy, and security automation across both AWS and Azure as a senior individual contributor. Success here means shaping the roadmap leadership acts on, not just executing someone else's plan, with visible influence across Cloud Engineering, Information Security, and executive stakeholders within the first 90 days.
OUR COMPANY
Our company operates cloud infrastructure across AWS and Azure at a scale where security and identity management directly affect how fast the business can move. We invest in strong technical foundations, infrastructure as code, automated compliance, and mature access governance, because we would rather build guardrails once than firefight forever. This role sits at the center of that investment, partnering closely with Cloud Operations and Engineering to keep security built in rather than bolted on.
KEY PERFORMANCE OBJECTIVES (FIRST 12 MONTHS)
1: Cloud Security Framework Compliance (First 90 Days, Ongoing Through Year One)
Outcome: Complete an assessment of current security framework compliance across AWS and Azure in the first 30 days, deliver a prioritized remediation roadmap by day 90, and keep compliance scores improving through the first 6 months and beyond.
Impact: Closes framework gaps before they surface as audit or compliance findings, and gives leadership a clear, prioritized view of security posture instead of an ad hoc issue list.
How: By running structured assessments against framework benchmarks, maintaining security baselines and hardening guides, and translating framework requirements into Terraform modules and IaC guardrails that get enforced automatically.
IAM Maturity Roadmap (First 90 Days, Phase 1 By 6 Months)
Outcome: Map the current state of IAM across AWS, Azure, and integrated tooling in the first 30 days, present a phased IAM maturity roadmap to leadership by day 90, and deliver Phase 1 (least-privilege enforcement, access reviews in place) within the first 6 months.
Impact: Moves the organization from fragmented, ad hoc access to one governed by least-privilege and centralized oversight, closing off a major source of unmanaged access risk before it becomes an incident.
How: By assessing current IAM architecture end-to-end, then building out role-based and attribute-based access, federation, and access review processes essentially from the ground up.
Security-as-Code and Automation (Ongoing, Established Within First 6 Months)
Outcome: Turn security framework requirements and IAM controls into enforced, production-grade code, Terraform modules and Python/PowerShell automation, so compliance and access control are checked and enforced automatically rather than tracked in manual checklists.
Impact: Eliminates the gap between documented policy and actual environment state, and frees the security function from re-doing the same manual checks every cycle.
How: By writing Terraform modules that enforce controls as code integrated into CI/CD pipelines, and by building Python and PowerShell automation for assessments, remediation workflows, and compliance reporting.
4: Security Governance and Cross-Functional Partnership (Ongoing)
Outcome: Serve as the security subject matter expert in cloud architecture reviews and change advisory processes, and mentor Cloud Operations and Engineering teams on security best practices, so security judgment shapes decisions before they ship rather than gatekeeping after the fact.
Impact: Embeds security into how the organization designs and changes its cloud environment, and builds security capability across other teams rather than making the security function a bottleneck.
How: By reviewing architecture and change proposals as the security voice in the room, coaching Cloud Operations and Engineering on secure defaults and practices, and presenting security strategy in terms both technical and executive audiences can act on.
5: Cloud Security Incident Response Leadership (Ongoing)
Note: this objective is derived primarily from the job description rather than the hiring manager's intake answers.
Outcome: Lead incident response for cloud security events end-to-end, from detection through resolution, and drive the post-incident review process to convert findings into concrete follow-up actions.
Impact: Shortens the time from detection to containment during real security events, and turns each incident into a source of durable improvement rather than a one-off fire drill.
How: By acting as incident commander or lead responder for cloud security events, coordinating with Cloud Operations and Engineering during response, and documenting and tracking corrective actions after each incident closes.
PowerPlan is an EOE
Please note that this is a hybrid role that involves a combination of onsite work from our corporate office as well as work from home. While we strive to accommodate flexible working arrangements when sensible, there will be times when onsite work is required. This could include scheduled office days, team meetings, client meetings, or special events.