Cloud Security Operations Engineer

Posted 7 Days Ago
Be an Early Applicant
San Jose, CA, USA
In-Office
57-106 Hourly
Mid level
Artificial Intelligence • Cloud • Hardware • Software • Semiconductor
The Role
Design, implement, and maintain cloud security controls across multi-cloud environments (AWS, Azure, GCP, IBM Cloud). Integrate security into IaC, manage IAM and DLP, configure monitoring/CSPM/CNAPP, lead cloud incident response, automate with scripting/serverless, enforce compliance and OS/container hardening, and coordinate remediation with platform and application teams.
Summary Generated by Built In
At Cadence, we hire and develop leaders and innovators who want to make an impact on the world of technology.

Job Title: Cloud Security Operations Engineer

Location: San Jose, California

Reports to: Senior Cloud Security Architect

Job Overview:

We are seeking a skilled and passionate Cloud Security Operations Engineer to join our dynamic Information Security team. In this role, you will be responsible for designing, implementing, and maintaining robust security controls across our public cloud environments, including AWS, Azure, GCP, and IBM Cloud. As a hands-on technical expert, you will play a crucial role in enhancing our cloud security posture, with a primary focus on data protection and incident management. This position offers the opportunity to work in a collaborative environment, where you will contribute to the security and resilience of our cloud infrastructure.

Job Responsibilities:

1. Secure Architecture and Engineering

  • Design and deploy secure reference architectures across multi-cloud environments.

  • Integrate security into Infrastructure-as-Code (IaC) using tools like Terraform, CloudFormation, and ARM Templates.

  • Implement cloud-native security controls: VPCs, WAFs, DDoS, and endpoint protections.

  • Ensure data protection via encryption, KMS/HSM, and DLP policies.

2. Identity and Access Management (IAM)

  • Design, implement, and audit IAM policies, roles, service accounts, and federation models using least-privilege principles.

  • Configure MFA, SSO, and PAM solutions for secure cloud access.

3. Monitoring, Detection, and Response

  • Configure and maintain cloud-native security tools (e.g., AWS Security Hub, Microsoft Defender for Cloud, Google Security Command Center).

  • Integrate cloud logs with SIEM systems for threat detection.

  • Lead incident response efforts for cloud-related security events.

  • Continuously monitor cloud environments using CSPM, CNAPP, and cloud-native security tools to identify, prioritize, and remediate security misconfigurations and policy violations.

  • Track and manage cloud security findings through remediation workflows.

  • Partner with Cloud Platform, Infrastructure, and Application teams to coordinate remediation of identified security risks and vulnerabilities.

  • Conduct root cause analysis of recurring cloud security issues and recommend preventive controls and automation improvements.

4. Cloud Data Loss Prevention (DLP) Management

  • DLP Alert Triage and Investigation: Monitor, triage, and investigate all DLP alerts and events. Differentiate between policy violations, potential insider threats, and false positives, escalating confirmed incidents to the Incident Response team.

  • Tool Optimization and Tuning: Serve as the subject matter expert (SME) for Cloud DLP tools (e.g., Microsoft Purview, Google DLP, dedicated CASB solutions). Continuously tune policies and rulesets to minimize alert fatigue while maintaining high fidelity.

  • Reporting and Compliance: Generate regular reports on DLP effectiveness, policy violations, and risk trends for leadership and compliance/audit teams (e.g., SOC 2, HIPAA, GDPR).

  • Data Classification Integration: Collaborate with Governance, Risk, and Compliance (GRC) teams to ensure DLP policies align with the corporate data classification framework.

5. Automation and DevSecOps

  • Develop automation scripts (Python, PowerShell, Bash) and serverless functions (AWS Lambda, Azure Functions, Google Cloud Run).

6. Cloud Security Posture Management & Compliance

  • Continuously assess AWS, Azure, and GCP environments using CSPM platforms to identify misconfigurations, excessive permissions, exposed resources, compliance gaps, and other security risks.

  • Develop, maintain, and enforce cloud security baselines aligned with industry standards, regulatory requirements, and organizational security policies.

  • Perform periodic cloud security assessments and audits using CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and internal security standards.

  • Drive remediation of findings identified through CSPM monitoring, security assessments, audits, compliance reviews, and risk assessments.

  • Support internal and external audits by providing cloud security evidence, compliance reporting, and remediation status updates.

7. Secure Access and Network Security Controls

  • Enforce secure access patterns by eliminating unnecessary public exposure and implementing private endpoints, bastion hosts, AWS Systems Manager Session Manager, and least-privilege network segmentation.

  • Enforce private connectivity architectures by leveraging:

    • AWS PrivateLink

    • Azure Private Endpoints

    • Google Private Service Connect

  • Eliminate unnecessary public exposure of cloud workloads, services, and management interfaces.

  • Design and maintain least-privilege network segmentation and cloud-native firewall controls across multi-cloud environments.

8. Cloud Workload Security and Hardening

  • Establish and maintain secure cloud operating system baselines using CIS Benchmarks and vendor-recommended hardening standards.

  • Perform periodic reviews and validation of operating system, virtual machine, and container security configurations.

  • Collaborate with Infrastructure and Platform teams to implement hardened images and golden image standards.

  • Monitor and remediate deviations from approved OS hardening baselines.

Job Qualifications:

Technical Expertise

  • Deep knowledge of at least one cloud platform (AWS, Azure, or GCP).

  • Proficiency in scripting: Python (preferred), PowerShell, Unix shell scripting.

  • Strong understanding of networking and cloud-native network security.

  • Experience with CSPM/CNAPP platforms such as CloudGuard Dome9, Wiz, Prisma Cloud, Microsoft Defender for Cloud, or similar solutions.

  • Strong knowledge of CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and industry cloud security best practices.

  • Familiarity with securing OS and containerized environments (Docker, Kubernetes).

  • Experience implementing secure cloud network architectures, private endpoints, bastion access patterns, and zero-trust security principles.

  • Experience supporting cloud compliance, audit readiness, and regulatory assessments.

Education & Certification

  • Bachelor’s degree in computer science, Information Security, or related field (or equivalent experience).

  • Preferred Certifications:

    • AWS Certified Solutions Architect – Associate

    • AWS Certified Security – Specialty

    • Microsoft Certified: Azure Administrator Associate

    • Microsoft Certified: Azure Security Engineer Associate

    • Google Cloud: Associate Cloud Engineer

    • Google Cloud: Professional Cloud Security Engineer

    • (ISC)² Certified Cloud Security Professional (CCSP)

    • (ISC)² Certified Information Systems Security Professional (CISSP)

Soft Skills

  • Strong analytical and problem-solving abilities.

  • Excellent communication and collaboration skills, especially with DevOps and engineering teams.

Cadence is committed to equal employment opportunity and employment equity throughout all levels of the organization. We strive to attract a qualified and diverse candidate pool and encourage diversity and inclusion in the workplace. 

Travel: N/A

The hourly range for California is $57.21 to $106.25 per hour. You may also be eligible to receive incentive compensation: bonus, equity, and benefits. Please note that the hourly range is a guideline and compensation may vary based on factors such as qualifications, skill level, competencies and work location. Our benefits programs include: paid vacation and paid holidays, 401(k) plan with employer match, employee stock purchase plan, a variety of medical, dental and vision plan options, and more.

We’re doing work that matters. Help us solve what others can’t.

Skills Required

  • Deep knowledge of at least one cloud platform (AWS, Azure, or GCP)
  • Experience with public cloud platforms including AWS, Azure, GCP, IBM Cloud
  • Proficiency in scripting (PowerShell, Unix shell/Bash); Python scripting
  • Experience with Infrastructure-as-Code: Terraform, CloudFormation, ARM Templates
  • Experience with CSPM/CNAPP platforms (CloudGuard Dome9, Wiz, Prisma Cloud, Microsoft Defender for Cloud, or similar)
  • Experience with cloud-native security tools and SIEM integration (AWS Security Hub, Microsoft Defender for Cloud, Google SCC)
  • Experience implementing IAM, MFA, SSO, PAM and least-privilege access models
  • Experience managing DLP tools and alert triage (Microsoft Purview, Google DLP, CASB solutions)
  • Familiarity securing OS and containerized environments (Docker, Kubernetes) and OS hardening/CIS Benchmarks
  • Strong understanding of networking and cloud-native network security (private endpoints, bastions, PrivateLink/Private Endpoints/Private Service Connect)
  • Experience with incident response, monitoring, remediation workflows, and root cause analysis
  • Knowledge of compliance frameworks and standards (CIS Benchmarks, CSA CCM, NIST) and audit readiness
  • Bachelor's degree in computer science, information security, or related field (or equivalent experience)
  • AWS Certified Solutions Architect, AWS Security Specialty, Azure/Azure Security, Google Cloud security certs, CCSP or CISSP
  • Strong communication and collaboration skills with DevOps and engineering teams

Cadence Design Systems Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Cadence Design Systems and has not been reviewed or approved by Cadence Design Systems.

  • Equity Value & Accessibility A discounted ESPP with a lookback feature and equity included in total compensation make ownership broadly accessible and potentially meaningful. Structured compensation at an industry leader adds predictability to equity participation.
  • Healthcare Strength Medical, dental, and vision coverage are described as solid, with mental‑health/EAP and fertility support enhancing the offering. The breadth across core care and family‑building needs strengthens the healthcare package.
  • Leave & Time Off Breadth Global Recharge Days, volunteer time off, and companywide breaks indicate a comprehensive time‑off framework. In addition, many salaried roles are described as having flexible or generous PTO policies.

Cadence Design Systems Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Jose, CA
8,216 Employees
Year Founded: 1988

What We Do

Cadence enables electronic systems and semiconductor companies to create the innovative end products that are transforming the way people live, work and play. Cadence® software, hardware and IP are used by customers to deliver products to market faster. The company's Intelligent System Design strategy helps customers develop differentiated products—from chips to boards to intelligent systems—in mobile, consumer, cloud, data center, automotive, aerospace, IoT, industrial and other market segments. Cadence is listed as one of Fortune Magazine's 100 Best Companies to Work For.

Similar Jobs

Gusto Logo Gusto

Data Scientist

Fintech • HR Tech
Easy Apply
Hybrid
San Francisco, CA, USA
4405 Employees
133K-193K Annually

Boeing Logo Boeing

Associate ASIC and/or FPGA Design and Verification Engineer

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
El Segundo, CA, USA
170000 Employees
99K-133K Annually

Boeing Logo Boeing

Command and Data Handling/Networking Subsystem Engineers - Space Autonomy Systems - (Associate, Experienced, or Lead)

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
El Segundo, CA, USA
170000 Employees
100K-207K Annually

Boeing Logo Boeing

Project Manager

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
El Segundo, CA, USA
170000 Employees
168K-228K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account