[Remote] Staff Cloud Security Engineer
Note: The job is a remote job and is open to candidates in USA. Ro is building a new healthcare system where patients are in control, leveraging technology as a core component of care delivery. The Staff Cloud Security Engineer will be responsible for maintaining and operating secure cloud infrastructures, implementing security measures, and collaborating with various teams to ensure a secure platform solution.ResponsibilitiesMaintain and Operate Secure Cloud Infrastructure: Lead the ongoing maintenance and operation of secure cloud infrastructures, focusing on AWS and cloud-native technologies. Ensure environments are resilient, compliant, and secure through multi-layered protection strategiesCloud Native Application Protection: Secure applications built for cloud environments by automating security assessments, monitoring runtime environments, and integrating security practices into the development lifecycle. Focus on containers, serverless architectures, and virtual machines, adapting to emerging threatsCloud Workload and Data Protection: Implement robust security controls for cloud workloads and data, including containers, virtual machines, and serverless architectures. Protect against threats while maintaining performance and scalability, using encryption, data loss prevention, and access controlsKubernetes and Cloud Security Hardening: Lead security hardening across all cloud security layers, with a focus on Kubernetes clusters and cloud-native environments. Secure container runtimes, implement stringent network policies, manage secrets securely, and ensure resilience against attacks at scaleCollaborate on Secure Platform Solutions: Partner with infrastructure, product security, security engineering, and engineering teams to design and implement secure platform solutions. Provide expertise in developing Infrastructure as Code (IaC), CI/CD pipelines, and deployment processes, ensuring security is integrated throughout the development lifecycleAutomation of Security Operations: Develop and deploy automation solutions to enhance security operations, reduce manual efforts, and ensure consistent security practices. Create reusable templates and modules for secure infrastructure to enable rapid, secure deploymentsSecurity Incident Response: Contribute to incident response efforts, including detection, analysis, containment, and recovery. Work with internal and external stakeholders to minimize the impact of incidents and prevent future occurrencesCompliance, Risk Management, and Data Governance: Ensure cloud infrastructures comply with standards such as SOC 2, HIPAA, and HITRUST. Implement automated compliance checks, data governance practices, and reporting to maintain alignment with these frameworks and protect data integrityTechnical Leadership and Mentorship: Act as a technical leader and mentor, promoting a security-first mindset. Guide best practices in cloud security and data protection, and integrate secure practices into the organization’s culture and processesSkills7+ years of experience in cloud security engineering and architecture, with advanced expertise in AWS, Azure, or Google Cloud PlatformDeep understanding of cloud security principles and best practices, with proven experience in implementing and managing cloud-native security tools at scaleExtensive knowledge of fundamental security technologies, including firewalls, IDS/IPS, endpoint protection, IAM, encryption, and DLPExpertise with key tooling: Cloud Security Posture Management (CSPM), Cloud Native Application Protection Platforms (CNAPPs), Cloud Workload Protection Platforms (CWPPs) and Data Security Posture Management (DSPM)Expertise in securing and hardening cloud workloads, including containers, serverless architectures, and virtual machines, with a track record of enhancing security postureAdvanced experience with Infrastructure as Code (IaC) tools like Terraform, CloudFormation, and Pulumi, and expertise in integrating security into CI/CD pipelinesHigh proficiency in programming or scripting languages for developing complex security automation solutionsComprehensive understanding of cloud and network security, with experience in securing cloud architecture across multiple environmentsDemonstrated ability to perform in-depth security reviews of SaaS product architecture and its supporting infrastructure, with a focus on driving improvementsFamiliarity with and ability to implement compliance standards HIPAA, HITRUST, CIS, NIST 800-53 and others with a low-touch approachStrong leadership and communication skills, with a proven track record of collaborating with cross-functional teams, including product teams and developers, to drive a security-first culture, effect change across the organization and further the cloud security roadmapBenefitsFull medical, dental, and vision insurance + OneMedical membershipHealthcare and Dependent Care FSA401(k) with company matchFlexible PTOWellbeing + Learning & Growth reimbursementsPaid parental leave + Fertility benefitsPet insuranceStudent loan refinancingVirtual resources for mindfulness, counseling, and fitnessCompany OverviewRo is a direct-to-patient healthcare company with a mission of helping patients achieve their health goals by delivering the easiest, most effective care possible. It was founded in 2017, and is headquartered in New York, NY, US, with a workforce of 201-500 employees. Its website is https://ro.co.Company H1B SponsorshipRo has a track record of offering H1B sponsorships, with 1 in 2026, 8 in 2025, 6 in 2024, 5 in 2023, 12 in 2022, 4 in 2021, 2 in 2020. Please note that this does not guarantee sponsorship for this specific role.