Eositsolutions
Network Cloud Security Engineer
United States of America
Posted August 11, 2026
Job description
WHO WE ARE:
EOS IT Solutions is a global technology and logistics company delivering complex technology infrastructure, deployment and managed services to some of the world's largest organizations.
For this engagement, EOS is seeking highly technical Cloud Security Engineers to support a large-scale enterprise AI environment. This is a hands-on engineering engagement focused on implementing, automating, testing and operationalizing cloud security controls across AWS, Azure and Google Cloud.
This is not a strategy-only, assessment-only or GRC role. Successful engineers will be expected to work directly in cloud environments, infrastructure-as-code, security tooling and automation to deliver measurable security improvements.
THE ROLE
We are seeking experienced Cloud Security Engineers to help secure and harden a complex, multi-cloud AI environment.
Engineers will work across one or more of four primary security workstreams:
• Identity & Credential Security
• Cloud Data-Plane & Network Security
• Cloud Logging, Detection & Response
• External Attack Surface & Kubernetes Security
The ideal candidate will have deep expertise in at least one or two of these areas and sufficient breadth to collaborate across the broader cloud-security program.
We are particularly interested in engineers who can take a security requirement and turn it into a working production control — including code, Terraform/IaC, automation, testing, documentation and operational handoff.
KEY RESPONSIBILITIES
Cloud Security Engineering
• Design, implement and validate security controls across AWS, Azure and/or GCP.
• Translate security requirements into production-ready technical solutions.
• Develop and maintain infrastructure-as-code using Terraform or similar technologies.
• Automate repetitive security and infrastructure processes using Python, Go, scripting or other appropriate tools.
• Work directly with cloud infrastructure, platform, DevOps and security teams.
• Troubleshoot complex cloud-security issues and develop practical remediation plans.
• Test security controls and provide evidence of implementation and effectiveness.
• Document technical designs, configurations, procedures and operational requirements.
• Support rapid remediation of identified security gaps.
WORKSTREAM 1 — IDENTITY & CREDENTIAL SECURITY
Help eliminate long-lived and static credentials while improving identity attribution and least-privilege access.
Responsibilities may include:
• Implementing workload identity and federation.
• OIDC-based authentication.
• IAM/RBAC design and implementation.
• Short-lived credentials and token-based authentication.
• Service-account and machine identity remediation.
• AWS, Azure, GCP and GitHub identity integrations.
• Credential discovery and remediation automation.
• Preventive guardrails to prevent creation of new static credentials.
• Least-privilege access controls.
• Identity federation and access governance.
Ideal background: Cloud IAM, identity engineering, workload identity, OIDC, RBAC, federation and cloud security automation.
WORKSTREAM 2 — CLOUD DATA-PLANE & NETWORK SECURITY
Reduce the potential blast radius of compromised credentials, workloads and cloud resources.
Responsibilities may include:
• GCP VPC Service Controls / service perimeters.
• AWS security and organizational guardrails.
• Azure identity federation and token exchange.
• Cross-account and cross-tenant restrictions.
• Data-access controls.
• Egress allowlists and restrictions.
• Cloud network security.
• Segmentation and isolation.
• Secure cloud landing zones.
• Infrastructure-as-code implementation of security controls.
Ideal background: Cloud security architecture/engineering, cloud networking, AWS/GCP/Azure security controls and infrastructure automation.
WORKSTREAM 3 — CLOUD LOGGING, DETECTION & RESPONSE
Close visibility gaps and improve the ability to detect and respond to security events.
Responsibilities may include:
• AWS CloudTrail and cloud audit logging.
• Azure Activity Logs.
• GCP logging and audit telemetry.
• Kubernetes/AKS logging.
• GitHub and application security telemetry.
• SIEM integration.
• Security detection engineering.
• Behavioral analytics.
• Alerting and monitoring.
• Automated security response and credential containment.
• Security-event investigation and remediation.
• Building automation around security operations.
Ideal background: Cloud detection engineering, SIEM, security automation, cloud logging, SOC engineering and incident response.
WORKSTREAM 4 — EXTERNAL ATTACK SURFACE & KUBERNETES SECURITY
Reduce internet-facing exposure and harden cloud-native workloads.
Responsibilities may include:
• Kubernetes/EKS/AKS/GKE security.
• Container security.
• Cloudflare WAF and DDoS controls.
• Public-facing application protection.
• Public storage exposure remediation.
• Internet-facing resource inventory.
• Cloud security posture management.
• Vulnerability identification and remediation.
• Wiz or comparable cloud-security platforms.
• Kubernetes configuration and security hardening.
• Helm/IaC-based security implementation.
• Attack-surface validation and testing.
Ideal background: Kubernetes security, DevSecOps, cloud infrastructure security, WAF/DDoS, CSPM and attack-surface management.
REQUIRED QUALIFICATIONS
• 5+ years of experience in cloud infrastructure, cloud security, DevSecOps, security engineering or a closely related discipline.
• Strong hands-on experience with AWS, Azure and/or GCP.
• Demonstrated experience implementing cloud security controls in production environments.
• Strong understanding of cloud identity, access management and security architecture.
• Experience with Terraform, infrastructure-as-code or comparable automation technologies.
• Experience with scripting or programming, preferably Python, Go or similar.
• Experience working with production infrastructure and troubleshooting complex technical issues.
• Ability to collaborate directly with cloud infrastructure, platform, DevOps and security teams.
• Strong technical documentation and communication skills.
• Ability to work independently in a fast-moving, highly technical environment.
PREFERRED QUALIFICATIONS
• Experience across multiple cloud platforms, particularly AWS, Azure and GCP.
• Kubernetes / EKS / AKS / GKE security experience.
• OIDC, workload identity and federation.
• GCP VPC Service Controls.
• AWS organizational/security guardrails.
• Azure Entra ID and cloud federation.
• CloudTrail, Azure Activity Logs and GCP audit logging.
• SIEM and security detection engineering.
• Cloudflare, WAF and DDoS protection.
• Wiz or comparable CSPM/CNAPP platforms.
• DevSecOps and CI/CD security.
• Secrets management.
• Cloud incident response.
• FedRAMP, NIST, IL4/IL5 or other high-compliance environments.
• Experience supporting AI/ML or GPU-intensive infrastructure.
• Experience in large-scale enterprise or hyperscale cloud environments.
WHAT WE ARE LOOKING FOR
We are looking for engineers who build, not simply advise.
The strongest candidates will be able to explain:
"Here was the security problem. Here's what I personally implemented. Here's the code/IaC/automation I used. Here's how I tested it. And here's how we know it worked."
Candidates may come from different technical backgrounds. We do not expect every engineer to be an expert across all four workstreams.
A candidate with deep expertise in one area and strong working knowledge across the others can be an excellent fit.
The EOS pay range for this job is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, experience, education, knowledge, skills, and abilities, as well as internal equity, market data, or other laws.
EOS is committed to creating a diverse and inclusive work environment and is proud to be an equal opportunity employer. We invite you to consider opportunities at EOS regardless of your gender; gender identity; gender reassignment; age; religious or similar philosophical belief; race; national origin; political opinion; sexual orientation; disability; marital or civil partnership status or other non-merit factor.
#INDNAMER