Hex logo

Cloud Security Engineer

Hex

New York, NYRemoteFull-time$200–265K/yrPosted 6mo agoVerified open 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$200–265K/yr
Location
New York, NYRemote
Schedule
Full-time
Work Authorization
Not specified

Job overview

Hex is hiring a Cloud Security Engineer. Hex is seeking an experienced Cloud Security Engineer to ensure the security and resilience of its cloud infrastructure, lead cloud security practices, and work closely with infrastructure and engineering teams to protect cloud‑native applications.

Key focus areas include Design, implement, and manage security solutions and controls for AWS environments and Kubernetes clusters, Build, deploy, and maintain infrastructure‑as‑code using Terraform, and Conduct security assessments, threat modeling, and audits on cloud infrastructure.

Successful candidates bring 5+ Years Cloud Security Engineering Experience. Important skills include AWS, Kubernetes, Terraform, Cloud Security Engineering, Cluster Hardening, and Role-Based Access Control (RBAC). Preferred (not required): IAM, GuardDuty, Security Hub, and CloudTrail.

Skills & qualifications

RequiredNice to have

Skills

AWSKubernetesTerraformCloud Security EngineeringCluster HardeningRole-Based Access Control (RBAC)Network PoliciesContainer Vulnerability ManagementSecure Software Development Lifecycle PracticesCI/CD SecurityDevSecOps MethodologiesProblem-SolvingCommunicationLeadershipSOC 2ISO 27001GDPRHIPAAPCI DSSIAMGuardDutySecurity HubCloudTrailFirewallsWizPantherCloud Infrastructure SecurityCloud Security PracticesCloud-Native Application SecuritySecurity Solutions DesignSecurity Controls ImplementationSecurity Controls ManagementInfrastructure as CodeSecurity AssessmentsThreat ModelingAuditsCI/CD Pipeline SecurityCloud Security Incident MonitoringCloud Security Incident ResponseCompliance RequirementsSecure Software Development LifecycleIsolation/Sandboxing MethodsCI/CD PipelinesCoachingKubernetes SecurityDesign Security SolutionsImplement Security SolutionsManage Security SolutionsBuild Infrastructure-as-CodeDeploy Infrastructure-as-CodeMaintain Infrastructure-as-CodeConduct Security AssessmentsAudits on Kubernetes DeploymentsMonitor Cloud Security IncidentsRespond to Cloud Security IncidentsCompliance Requirements Related to Cloud SecurityMentor EngineersAdvocate for Cloud SecurityCNAPP SolutionsSIEM SolutionsAWS IAMAWS GuardDutyAWS Security HubAWS CloudTrailAWS WAFCI/CDDevSecOpsIncident ManagementGDPR CompliancePCI DSS ComplianceSecurity AuditsTypeScriptReactApollo GraphQLReduxExpressPostgreSQLRedisHelmRBACPythonIncident Monitoring and ResponseCompliance (SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS)Cloud Security

Qualifications

5+ Years Cloud Security Engineering ExperienceAWS Certified Security – SpecialtyCertified Kubernetes Security Specialist (CKS)Terraform Associate CertificationSANS Security CertificationsOffSec Security Certifications

Benefits

Medical Insurance
Paid Time Off
Dental Insurance
Vision Insurance

Full job description

About the role

We are looking for an experienced Cloud Security Engineer to join Hex’s security team. You will be responsible for ensuring the security and resilience of our cloud infrastructure, providing leadership in cloud security practices, and collaborating closely with our infrastructure and engineering teams to secure our cloud-native applications.


About the role:

  • Design, implement, and manage security solutions and controls for AWS environments and Kubernetes clusters, including appropriate isolation/sandboxing methods for Hex’s RCE-as-a-Service platform
  • Build, deploy, and maintain infrastructure-as-code using Terraform, ensuring robust security standards are enforced.
  • Conduct security assessments, threat modeling, and audits on AWS cloud infrastructure and Kubernetes deployments.
  • Collaborate with development and operations teams to embed security best practices into CI/CD pipelines.
  • Monitor and respond to cloud security incidents, identifying root causes and recommending remediation actions.
  • Provide expertise in compliance requirements related to cloud security (e.g., SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS).
  • Mentor engineers and advocate for cloud security across the organization.

About you:

  • 5+ years of experience in cloud security engineering, with extensive expertise in AWS.
  • Demonstrated proficiency with Kubernetes security including cluster hardening, role-based access control (RBAC), network policies, and container vulnerability management.
  • Expert-level knowledge and hands-on experience with Terraform.
  • Familiarity with AWS security services (e.g., IAM, GuardDuty, Security Hub, CloudTrail, WAF).
  • Familiarity with CNAPP solutions such as Wiz
  • Familiarity with SIEM solutions such as Panther
  • Solid understanding of secure software development lifecycle practices, CI/CD security, and DevSecOps methodologies.
  • Relevant certifications such as AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), and Terraform Associate certification are highly desirable.
  • Bonus points for security certifications from SANS or OffSec.
  • Excellent problem-solving, communication, and leadership skills.

Our Engineering team

We’re a group of engineers who are forging new ground together and love partnering with Security on our journey to pull ahead of our competition. You can read about how we think through problems as well as how we learn from mistakes on our blog here:


Our stack

Our product is a web-based notebook and app authoring platform. Our frontend is built with Typescript and React, using a combination of Apollo GraphQL and Redux for managing application state and data. On the backend, we also use Typescript to power an Express/Apollo GraphQL server that interacts with Postgres, Redis, and Kubernetes to manage our database and Python kernels. Our backend is tightly integrated with our infrastructure and CI/CD, where we use a combination of Terraform, Helm, and AWS to deploy and maintain our stack.


In addition to our unique culture, Hex proudly offers a competitive total rewards package, including but not limited to, market-benched salary & equity, comprehensive health benefits, and flexible paid time off.

The salary range for this role is: $200,000 - $265,000

The salary range shown may be a reflection of additional factors such as geographical location and skill ranges/levels we’re open to. Placement in the salary range will be decided upon completion of the interview process, taking into account factors like leaving room for growth, internal fairness & parity, your demonstrated skills, and the depth of your experience. Our Recruiting team will be able to provide more details during the interview process.

By submitting an application the candidate consents to the use of their personal information in accordance with the Hex Privacy policy: https://learn.hex.tech/docs/trust/privacy-policy.

Hex Technologies uses AI-assisted tools as part of our application review process, including for resume screening and fraud detection. These tools help our team evaluate applications and verify applicant information. All AI-generated recommendations are reviewed by a member of our recruiting team before any hiring decision is made. No application is automatically rejected based solely on an AI tool's output.

You've read the whole posting — now see how you match it.