Senior Cloud Security Engineer

5 days ago


New York, New York, United States Gibson Dunn Full time

Gibson Dunn is a leading global law firm, advising clients on significant transactions and disputes. Our exceptional teams craft and deploy creative legal strategies that are meticulously tailored to every matter, however complex or high-stakes. The firm's work is distinguished by a unique combination of precision and vision.

Based in any U.S. Office, the Senior Cloud Security Engineer plays a critical role in the InfoSec team, leading the design, implementation, and assessment of cloud security controls across the firm's hybrid infrastructure. This position ensures compliance with Information Security and IS policies while aligning with industry best practices for cloud security.

This role reports to the Senior Director, Information Security Operations and collaborates closely with the IT Architect, Cloud Administrators, and senior leadership on cloud operations. The Senior Cloud Security Engineer will interface with technical teams, legal and compliance stakeholders, external auditors, and cloud service providers.

Responsibilities include:

  • Designing and implementing security controls across multi-cloud environments (e.g., Azure, AWS, GCP).
  • Conducting continuous assessments of cloud-based infrastructure, applications, and services.
  • Reviewing cloud architecture and configurations to validate security posture and data protection.
  • Leading threat modeling, risk assessments, and vulnerability management for cloud-native services.
  • Administering cloud security testing, including penetration testing, misconfiguration audits, and incident simulations.
  • Collaborating with DevOps and engineering teams to embed security into CI/CD pipelines and cloud deployments.
  • Driving remediation of security findings and ensuring alignment with regulatory and compliance frameworks.
  • Maintaining expertise in cloud security trends, tools, and threat intelligence.
  • Leading security reviews of cloud perimeter defenses (e.g., WAFs, cloud-native firewalls, DDoS protection).
  • Managing cloud security controls and endpoint protection platforms (e.g., Defender for Cloud, CrowdStrike, Cloudflare, Proofpoint TAP).
  • Overseeing cloud security monitoring and logging.
  • Coordinating incident response and disaster recovery planning for cloud workloads.
  • Conducting gap analyses and compliance audits across cloud environments (e.g., ISO, NIST, SOC 2, HIPAA).
  • Evaluating third-party cloud services and integrations for security risks.
  • Providing technical guidance and mentorship to engineers and cross-functional teams.
  • Developing and maintaining cloud security policies, playbooks, and documentation.
  • Participating in a rotating on-call schedule to provide after-hours support and ensure timely resolution of critical issues.

Qualifications:

  • Deep knowledge of cloud platforms (Azure, AWS, GCP) and associated security services.
  • Experience with regulatory frameworks and standards (SOC, GLBA, HIPAA, GDPR).
  • Familiarity with DevSecOps practices and infrastructure-as-code tools
  • Strong communication skills to engage technical and non-technical audiences.
  • Proven ability to lead complex security initiatives and drive cross-team collaboration.
  • Commitment to continuous learning and staying current with emerging cloud threats and technologies.

Experience:

  • Bachelor's degree in Computer Science, Information Systems, or related field.
  • Cloud security certifications (e.g., CCSP, AWS Certified Security – Specialty, Azure Security Engineer).
  • Minimum 10 years of experience in information security, with 5+ years focused on cloud security.

Gibson Dunn will consider for employment qualified Applicants with Criminal Histories in a manner consistent with the requirements of local law.

Compensation & Benefits:

The annual compensation range for this position is $150-170k. The salary offered within this range will depend upon qualifications and other operational considerations.

Benefits offered for this position include health care; retirement benefits; paid days off, including sick time, and vacation time; parental leave; basic life insurance; Flexible Spending Accounts; as well as discretionary, performance-based bonuses.



  • New York, New York, United States Orbis Group Full time

    Senior Cloud Security Engineer (Infrastructure and Security) – New York – Competitive Salary + Competitive Package + Opportunity to work with an Ambitious, Young, Growing OrganisationThis young and agile company, providing identity risk solutions is currently seeking a Senior Cloud Security Engineer with a focus on Infrastructure and Security to join...


  • New York, New York, United States Dune Security Full time

    Company Overview:Dune Security's User Adaptive Risk Management solution proactively prevents insider threats and social engineering by simulating multi-channel attacks, scoring user risk, and adapting training and controls in real time. Powered by AI, we quantify employee risk with comprehensive data and automatically deliver user-adaptive training and...


  • New York, New York, United States Sigma Full time

    About The RoleSigma is seeking a Senior Security Engineer to join our growing Cyber Security team. As a Senior Security Engineer, you will advance Sigma's Security strategy by shaping and evolving security architecture in alignment with business objectives. As a Senior Engineer, you will be focused on our Cloud/SaaS Security, designing, building, and...


  • New York, New York, United States Movate Full time

    Role SummaryWe are seeking a highly skilledSenior Security Engineer (Level 3)to design, implement, and optimize our enterprise security controls. This role requires deep technical expertise infirewalls,endpoint detection & response (EDR),SIEM engineering, andemail security platforms. The ideal candidate will act as a technical SME, lead advanced threat...


  • New York, New York, United States The Planet Group Full time

    Job Title: Senior Azure Cloud Engineer / Architect (Azure Landing Zones) Location: New York, NY (Hybrid – 3 Days Onsite at Midtown Manhattan Office, 2 Days Remote)Salary Range: $200,000Annual BonusBenefits: Full medical/dental/vision, 401(k) match, 20 PTO daysEmployment Type: Full-Time, Direct Hire?? Senior Cloud Engineer/Architect - Azure Landing Zone...


  • New York, New York, United States Bowman Williams Full time

    Cloud Systems Engineer (Level 2) – Hybrid NYCCareer path: Senior Cloud Engineer → Solutions Architect / vCIOAbout UsFinancially backed, fast-growing cloud and security-focused MSP with steady MRR growth.Investing heavily in people, tools, and scalable processes to support long-term expansion.Operates a proactive, efficient service model — engineers...


  • New York, New York, United States Method Security Full time

    About Method SecurityMethod Security is dedicated to reshaping cybersecurity in an era where AI-driven threats are growing rapidly. Our mission is to defend critical institutions—such as government, defense, and key commercial sectors—against these sophisticated threats by building cutting-edge, autonomous defense solutions. We bring together expertise...

  • GCP Cloud Engineer

    2 weeks ago


    New York, New York, United States Publicis Sapient Full time

    Job DescriptionSenior Associate GCP Cloud EngineerAs a Senior Associate Cloud Engineer, you will be responsible for designing, implementing, and maintaining cloud infrastructure solutions to ensure high availability, scalability, and security. You will work closely with engineering teams to optimize cloud environments and support business-critical...


  • New York, New York, United States Dune Security Full time

    1. Company OverviewDune Security is the world's first User Adaptive Risk Management solution. Powered by AI, we quantify employee risk with comprehensive data and automatically deliver user-adaptive training and intervention. For higher-risk users, our platform integrates seamlessly with the broader security stack to dynamically implement controls. Backed by...


  • New York, New York, United States S&P Global Full time

    About The RoleGrade Level (for internal use):11S&P Global CorporateSegment:S&P Global Global EnergyThe Role: Cloud & Application Security EngineerLocation:NY or NJ (hybrid 2 days onsite)The Team:Part of the SPGE Technology Security team accountable for the overall cyber security of the division. This role would instill values of enablement, accountability,...