Cloud Security Enginee
Applied Intuition is at the forefront of powering the future of physical AI. Founded in 2017 and now valued at an incredible $15 billion, we are the Silicon Valley company creating the essential digital infrastructure to bring intelligence to every moving machine on the planet. From autonomous vehicles to advanced robotics, our solutions empower leaders in automotive, defense, trucking, construction, mining, and agriculture.
Trusted by eighteen of the top 20 global automakers, alongside the United States military and its allies, Applied Intuition delivers transformative physical intelligence. We operate globally, with headquarters in Sunnyvale, California, and offices in Washington, D.C.; San Diego; Ft. Walton Beach, Florida; Ann Arbor, Michigan; London; Stuttgart; Munich; Stockholm; Bangalore; Seoul; and Tokyo. Learn more about our mission at applied.co.
Our Collaborative Environment
We thrive on in-person collaboration. Our expectation is that full-time employees primarily work from their Applied Intuition office 5 days a week. We also understand the importance of flexibility and trust our employees to manage their schedules responsibly. This may include occasional remote work, starting the day with morning meetings from home before heading to the office, or leaving earlier when needed to accommodate family commitments. This in-office expectation does not apply to contractor positions.
Your Mission as a Cloud Security Engineer
Are you a highly focused Cloud Security Engineer driven by the challenge of securing cutting-edge multi-cloud environments? At Applied Intuition, your expertise will be fundamental to safeguarding our critical infrastructure. Working closely with our Corporate Security & Infrastructure team, you will be instrumental in designing, implementing, and maintaining robust security across diverse multi-cloud platforms (AWS, Azure, GCP, OCI), with a deep focus on Kubernetes cluster hardening.
You will be at the forefront of establishing impenetrable guardrails, enforcing stringent Identity and Access Management policies, and proactively managing our Cloud Security Posture (CSPM) to prevent insecure deployments and ensure unwavering compliance in a rapidly evolving, high-stakes environment.
What You'll Do
Multi-Cloud Infrastructure Security: Architect, implement, and maintain secure infrastructure across heterogeneous multi-cloud environments (AWS, Azure, GCP, OCI), proactively establishing cloud-specific robust guardrails to prevent insecure deployments and configurations from the outset.
Kubernetes Cluster Hardening: Design, implement, and rigorously enforce security best practices and policies specifically tailored for cloud-native Kubernetes clusters, including granular Role-Based Access Control (RBAC), sophisticated network policies, and admission controllers.
Identity & Access Management (IAM) Mastery: Develop, implement, and enforce comprehensive security policies and procedures related to user authentication and authorization across all systems. Manage user identities (including traditional Active Directory, email platforms, and cloud solutions) and rigorously enforce the principle of least privilege across Cloud, cloud service, and container levels.
Container Security Lifecycle: Ensure the end-to-end security of container images, registries, and runtime environments through the effective deployment and utilization of tools like Docker, Podman, and advanced container scanning solutions.
Infrastructure-as-Code (IaC) Security: Drive security by managing infrastructure and security policies through version-controlled Git repositories using tools such as Terraform, CloudFormation, or AWS CDK, ensuring consistent, auditable, and secure deployments.
Cloud Security Posture Management (CSPM): Administer and optimize CSPM tools such as Wiz to continuously detect, prioritize, and orchestrate the remediation of misconfigurations and compliance drifts across our entire cloud footprint.
Compliance Automation: Develop and implement automation for compliance checks and generate necessary evidence for audits across the multi-cloud environment, streamlining regulatory adherence and reporting.
Runtime Security Protection: Implement and manage solutions to monitor and protect running applications and containers from threats throughout their operational lifecycle.
What You'll Need to Succeed
Bachelor's degree in computer science or a relevant technical field.
5+ years of industry experience in software engineering or security engineering, with a proven track record in designing and building secure, production-grade cloud systems.
Extensive, demonstrable experience with Kubernetes from a security perspective, including securing containerized workloads, enforcing RBAC, and cloud-native secret management.
Experience leveraging AI to rapidly identify, validate, and remediate security issues without impacting operations.
Deep operational security expertise with AWS (mandatory), coupled with highly preferred practical experience deploying and securing infrastructure across Azure, GCP, or OCI.
Proficiency in Infrastructure-as-Code (IaC) tools such as Terraform, CloudFormation, or AWS CDK for deploying and managing secure environments.
Hands-on expertise in configuring, monitoring, and driving remediation through Cloud Security Posture Management (CSPM) platforms like Wiz.
A strong background in designing and enforcing complex Identity & Access Management (IAM) and least-privilege architectures across both multi-cloud and traditional on-premises directory environments.
Experience working with container security, image scanning, and runtime protection tools.
Bonus Points If You Have
Advanced industry certifications related to cloud and container security (e.g., AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), Certified Kubernetes Administrator (CKA)).
Strong proficiency in programming or scripting languages commonly used for security automation and backend development (e.g., Go/Golang, Python, or C++).
Prior experience automating compliance frameworks and generating audit evidence across a multi-cloud footprint.
Experience securing and operating in air-gapped or highly constrained on-premises computing environments.
Compensation at Applied Intuition for eligible roles includes base salary, equity, and benefits. Base salary is a single component of the total compensation package, which may also include equity in the form of options and/or restricted stock units, comprehensive health, dental, vision, life and disability insurance coverage, 401k retirement benefits with employer match, learning and wellness stipends, and paid time off. Note that benefits are subject to change and may vary based on jurisdiction of employment.
Applied Intuition pay ranges reflect the minimum and maximum intended target base salary for new hire salaries for the position. The actual base salary offered to a successful candidate will additionally be influenced by a variety of factors including experience, credentials & certifications, educational attainment, skill level requirements, interview performance, and the level and scope of the position.
Don’t meet every single requirement? If you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.
Applied Intuition is an equal opportunity employer and federal contractor or subcontractor. Consequently, the parties agree that, as applicable, they will abide by the requirements of 41 CFR 60-1.4(a), 41 CFR 60-300.5(a) and 41 CFR 60-741.5(a) and that these laws are incorporated herein by reference. These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity or national origin. These regulations require that covered prime contractors and subcontractors take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status or disability. The parties also agree that, as applicable, they will abide by the requirements of Executive Order 13496 (29 CFR Part 471, Appendix A to Subpart A), relating to the notice of employee rights under federal labor laws.
FOR US-BASED ROLES: Applied Intuition is committed to providing an accessible and inclusive application and interview experience to applicants who are disabled veterans and other applicants with disabilities or medical conditions. Reasonable accommodations are available, requesting an accommodation will not affect your candidacy in any way, and you are not required to disclose the nature of your disability or medical condition in order to make a request. If you require an accommodation please contact [email protected]. We will work with you!