Security Engineer

2 days ago

Oregon State, United States Caylent Full-time
Caylent is an AI-first cloud services company that helps organizations turn ambitious ideas into meaningful business impact. As an AWS Premier Tier Services Partner and a charter member of Anthropic’s Claude Partner Network, we combine deep expertise in AWS, artificial intelligence, and Anthropic’s Claude platform to help customers modernize their technology, build intelligent products, and move AI from experimentation into production. Our capabilities span generative and agentic AI, cloud migration and modernization, cloud-native application development, data and analytics, DevOps, managed services, security and compliance, and customer experience transformation. We are a fully remote global company with employees in Canada, the United States and Latin America. We celebrate the culture of each of our team members and foster a community of technological curiosity. The right candidate is someone who has a mix of AWS skills, networking familiarity, curiosity in emerging AI technologies, and a knack for tying it all together securely. ... Your mission will be helping improve Caylent’s security and compliance posture across AWS and various SaaS environments, improving our vulnerability management processes, and keeping Caylent safe against an onslaught of ever-evolving actors and tactics. Review or conduct regular security and vulnerability assessments leveraging automated and non-automated methods on cloud-based and mobile workloads. Periodically monitor/audit implementations and ensure they are functioning properly. Identify and advise on technical security requirements, review and approve security architecture and control implementations Develop and tune automated tests and rules, and monitor alerts and alarms for deviations from security standards, particularly using AWS tools such as Inspector, CloudTrail, CloudWatch, GuardDuty, Lambda, and Security Hub. Identifying, engineering, and building/updating/integrating new and existing security tooling, including cloud-native services Advise project teams on current and projected technical security risks, and recommend mitigation strategies to control risk. Assist internal development teams in defining and updating application threat models and in interpreting security policies, standards, and control requirements. Design vulnerability scans of cloud-based and mobile applications and infrastructure to identify weaknesses, coordinate with app teams to confirm validity of findings, and recommend and assist with mitigations as needed. Work with the security governance team to develop and interpret security standards, and build automated and self-service capabilities that validate application security and compliance status against these standards Research and identify best practices to harden and secure cloud workloads including cloud native, containers, and Kubernetes clusters at scale Develop and perform developer-focused training in support of security program goals Bachelor's Degree or 2-4 years experience in IT / security roles ~3+ years of experience in AWS or other public cloud environments ~ Experience with IAC languages such as YAML, Terraform, and/or CDK. ~ Experience with scripting languages and tools (bash, powershell, etc) ~ Experience using a modern programming language such as Python, Node.js (preferredD) ~ Others (optional): Typescript, GoLang, Java, C#, Rust, etc Experience working with software and app teams throughout the full Software Development Lifecycle (SDLC) Experience with code-defined infrastructure, configuration management tools, and CI/CD AWS security tooling for scanning, monitoring and alerting tools (Inspector, CloudTrail, CloudWatch, GuardDuty, Lambda, Security Hub) A thorough understanding of operational best practices for security in the cloud Proven experience building security reference architecture for all-in AWS cloud deployments A solid understanding of network and web-related protocols (e.g., Experience with Cloud Native patterns with services like AWS Lambda, API Gateway, etc. Familiarity with and day-to-day knowledge of AI tooling such as Claude and Chatgpt. AWS Security Specialty or Professional Level Certification and/or an Anthropic certification. Ability to explain/showcase how AI has transformed workloads / processes for you. Experience and a familiarity of application frameworks such as (RMF, FedRAMP, DoD CC SRG, NIST 800-53, NIST 800-171) Previous experience providing training in RMF or explaining cyber security concepts to others in a training like environment Experience with being on-call / part of an on-call rotation 100% remote work ~ Generous holidays and flexible PTO ~ Competitive phantom equity ~ Peer bonus awards ~ Equipment & Office Stipend ~ Work with an amazing worldwide team and in an incredible corporate culture NOTE: This position requires current legal authorization