1

Cloud Security Engineer Jobs in Santa Rosa, CA (NOW HIRING)

Own cloud security posture on GCP, bake security into CI/CD and the supply chain, and help shape how Doxel uses AI safely. What You'll Do * Work with DevOps team to build out golden paths that ...

The Role As a Principal Security Engineer focused on Software Security Engineering at Block, you will be a technical leader reporting to the CISO responsible for setting the bar for security ...

... security teams, and product teams to define and implement infrastructure best practices Own and ... engineering, Cloud, or as a software engineering staff member Strong programming and scripting ...

We collaborate with engineers and business partners from across Apple and provide cloud ... Experience optimizing cloud infrastructure to balance cost, security, and performance while meeting ...

We collaborate with engineers and business partners from across Apple and provide cloud ... Experience optimizing cloud infrastructure to balance cost, security, and performance while meeting ...

We collaborate with engineers and business partners from across Apple and provide cloud ... Experience optimizing cloud infrastructure to balance cost, security, and performance while meeting ...

We collaborate with engineers and business partners from across Apple and provide cloud ... Experience optimizing cloud infrastructure to balance cost, security, and performance while meeting ...

Cloud Data Engineer

Napa, CA · On-site

$115K - $151K/yr

Redwood Credit Union is looking for a Cloud Data Engineer, responsibilities include designing ... security measures, including encryption, access controls, and auditing, to protect sensitive ...

Cloud Data Engineer

Santa Rosa, CA · On-site

$115K - $151K/yr

Redwood Credit Union is looking for a Cloud Data Engineer, responsibilities include designing ... security measures, including encryption, access controls, and auditing, to protect sensitive ...

Cloud Data Engineer

Napa, CA · On-site

$115K - $151K/yr

Redwood Credit Union is looking for a Cloud Data Engineer, responsibilities include designing ... security measures, including encryption, access controls, and auditing, to protect sensitive ...

Cloud Data Engineer

Santa Rosa, CA · On-site

$115K - $151K/yr

Redwood Credit Union is looking for a Cloud Data Engineer, responsibilities include designing ... security measures, including encryption, access controls, and auditing, to protect sensitive ...

DevOps Engineer (Founding Team)

Bodega Bay, CA · On-site

$62.50 - $85.75/hr

We're looking for a DevOps engineer who can own infrastructure from Day 1 -- automating everything from CI/CD and observability to cloud governance and security. You'll work with a highly technical ...

Senior Salesforce Engineer

Bodega Bay, CA · Remote

$128K - $157K/yr

Data Cloud experience is nice to have but not required. * This team highly values SFDC ... security audits (CPRA/CCPA, SOX, etc.), technical documentation, training, system support and ...

next page

Showing results 1-20

Cloud Security Engineer information

See Santa Rosa, CA salary details

$67.2K

$167K

$224.7K

How much do cloud security engineer jobs pay per year?

As of Jul 31, 2026, the average yearly pay for cloud security engineer in Santa Rosa, CA is $167,032.00, according to ZipRecruiter salary data. Most workers in this role earn between $156,300.00 and $173,300.00 per year, depending on experience, location, and employer.

What are some common challenges Cloud Security Engineers face when securing multi-cloud environments?

Cloud Security Engineers often encounter challenges related to managing consistent security policies across multiple cloud providers, each with its own tools and configurations. Ensuring data visibility, controlling access, and monitoring threats in a multi-cloud setup requires advanced knowledge of automation and security orchestration. Collaboration with development and operations teams is essential to address misconfigurations and integrate security best practices early in the deployment lifecycle. Staying updated with evolving cloud-native security solutions is also crucial to effectively mitigate emerging threats.

What is the difference between Cloud Security Engineer vs Cloud Security Analyst?

AspectCloud Security EngineerCloud Security Analyst
Primary RoleDesigns, implements, and manages security solutions for cloud environmentsMonitors, analyzes, and responds to security threats in cloud systems
Skills & CertificationsCloud security certifications (e.g., CCSP, AWS Security Specialty), scripting, cloud architectureSecurity certifications (e.g., CompTIA Security+, CISSP), threat analysis, monitoring tools
Work EnvironmentHands-on technical work, cloud platforms, security architectureSecurity monitoring, incident response, analysis tools
Employer & Industry UsageCloud service providers, enterprise IT teams, cybersecurity firmsSecurity operations centers, IT departments, consulting firms

While both roles focus on cloud security, the Cloud Security Engineer primarily develops and implements security solutions, whereas the Cloud Security Analyst monitors and responds to security incidents. Both roles require cloud security certifications and are vital in protecting cloud environments.

What are the key skills and qualifications needed to thrive as a Cloud Security Engineer, and why are they important?

To thrive as a Cloud Security Engineer, you need a strong understanding of cloud platforms (like AWS, Azure, or Google Cloud), networking, and cybersecurity principles, often backed by a degree in computer science or a related field. Familiarity with tools such as SIEM systems, encryption technologies, and certifications like AWS Certified Security or CISSP is typically required. Strong analytical thinking, problem-solving skills, and effective communication help you anticipate threats and work collaboratively with development and operations teams. These abilities are crucial to ensure the security, compliance, and resilience of cloud-based infrastructure in dynamic IT environments.

Is cloud security engineer a good career?

A cloud security engineer is a valuable role focused on protecting cloud infrastructure and data, requiring skills in security protocols, cloud platforms like AWS or Azure, and certifications such as CISSP or CCSP. The role offers strong job growth, competitive salaries, and opportunities to work in various industries, making it a promising career choice for those interested in cybersecurity and cloud technology.

Can you make $500,000 a year in cyber security?

Cloud Security Engineers with extensive experience, advanced certifications, and specialized skills can potentially earn $500,000 or more annually, especially in high-demand markets or senior leadership roles. Achieving this level often requires a combination of technical expertise, strategic responsibilities, and sometimes executive-level positions within organizations. Most cybersecurity professionals, including cloud security engineers, earn lower salaries, but top-tier roles and consulting can reach or exceed this figure.

What engineers make $500,000?

Senior cloud security engineers with extensive experience, advanced certifications (such as CISSP or CISA), and expertise in security architecture can earn $500,000 or more annually, especially in high-demand industries or large organizations. Achieving this level often requires a combination of technical skills, leadership, and strategic responsibilities.

What are Cloud Security Engineers?

Cloud Security Engineers are IT professionals who design, implement, and maintain secure cloud-based systems and services. They are responsible for protecting cloud infrastructure, applications, and data from cyber threats by developing security policies, monitoring for vulnerabilities, and responding to incidents. Their work ensures that organizations can safely leverage cloud technologies while complying with security standards and regulations. Cloud Security Engineers often collaborate with other IT teams to integrate security best practices into cloud deployments.

What does a cloud security engineer do?

A cloud security engineer is responsible for designing, implementing, and maintaining security measures for cloud-based systems and infrastructure. They monitor for vulnerabilities, configure security tools, and ensure compliance with security standards, often using platforms like AWS, Azure, or Google Cloud. Strong knowledge of network security, encryption, and security certifications such as CISSP or CCSP is typically required.
What cities near Santa Rosa, CA are hiring for Cloud Security Engineer jobs? Cities near Santa Rosa, CA with the most Cloud Security Engineer job openings:
Infographic showing various Cloud Security Engineer job openings in Santa Rosa, CA as of July 2026, with employment types broken down into 89% Full Time, 5% Part Time, and 6% Contract. Highlights an 83% Physical, 5% Hybrid, and 12% Remote job distribution, with an average salary of $167,032 per year, or $80.3 per hour.

Senior Security Engineer, Platform Security

Block

Bodega Bay, CA • On-site

$135K - $186K/yr

Other

Re-posted 27 days ago


Block rating

7.9

Company rating: 7.9 out of 10

Based on 16 frontline employees who took The Breakroom Quiz

10th of 21 rated payment service providers


Job description

Block builds simple, powerful tools that make progress towards an economy that's truly open to all.

Each of our brands unlocks different aspects of the economy for more people. Square makes commerce and financial services accessible to sellers. Cash App is the easy way to spend, send, and store money. Afterpay is transforming the way customers manage their spending over time. TIDAL is a music platform that empowers artists to thrive as entrepreneurs. Bitkey is a simple self-custody wallet built for bitcoin. Proto is a suite of bitcoin mining products and services. Together, we're helping build a financial system that is open to everyone. Join us.

The Role

The Platform Security team is responsible for securing Block's cloud, compute, and network infrastructure across multiple business units including Square, Cash, and Afterpay.

We discover, track, and enable the business to remediate the most critical security risks across Block's cloud ecosystems (AWS and GCP). We drive the creation of cloud security policy and best practices, measure and aggregate deviations from these policies, and develop capabilities to estimate security risk based on cloud signals and business context. This work drives Block's cloud security strategy and is the lens through which Block measures progress of our cloud security posture over time.

We believe that the secure option should be the easiest option for our users. We're looking for a strong Senior Platform Security Engineer with a deep understanding of securing cloud infrastructure and services at scale to help us execute on this vision.

You Will
  • Architect and evolve cloud security guardrails. Design and implement SCPs, GCP org policies, and IAM controls that shape how Block uses cloud infrastructure for years to come.
  • Build automation to discover, measure, and contextualize security issues. Develop integrations with CSPM/DSPM tools and internal platforms to surface and prioritize findings.
  • Own the cloud security exception lifecycle. Build and maintain the tooling and processes that allow teams to request, review, and track security exceptions at scale
  • Partner with platform teams to deliver solutions that permanently eliminate entire categories of cloud security risk.
  • Deliver key cloud security assurance functions. Balance the need to remediate critical misconfigurations and sensitive data exposures with being responsible stewards of our developers' time.
  • Develop risk-based prioritization. Build data pipelines and dashboards that aggregate security signals and help leadership understand posture trends.
  • Respond to and triage cloud security alerts. Support on-call rotations, investigate findings, and help engineers resolve issues quickly.
  • Produce quality software that stands the test of time and scales across Block's multi-cloud footprint.
  • Think, build and iterate in an AI-augmented environment. 
You Have
  • 5+ years of experience as a software or security engineer 
  • 4+ years of experience securing infrastructure running on AWS and/or GCP at scale.
  • Deep experience with Infrastructure-as-Code. Terraform (including securing Terraform pipelines), SCPs, GCP org policies, and understanding of best practices and pitfalls when deploying guardrails at organizational scale.
  • Experience with cloud security posture management (CSPM) tools such as Wiz, and familiarity with DSPM concepts (sensitive data discovery, classification, and remediation).
  • Strong understanding of IAM. AWS IAM policies, roles, SCPs, permission boundaries; GCP IAM, service accounts, and org-level constraints.
  • Experience maturing the cloud security posture of large, complex, multi-account/multi-project environments.
  • Demonstrated ability to successfully deliver complex, multi-faceted projects from concept to launch.
  • Demonstrated fluency with AI-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot, or similar agentic coding tools) in real production work
Bonus If You Have
  • Experience with Kubernetes security (pod security policies, network policies) in environments like EKS or GKE.
  • Familiarity with BI and data exploration tools like Looker and Snowflake for building security metrics and dashboards.
  • Experience building or operating security exception/risk acceptance workflows at scale.
  • Familiarity with cloud networking and network segmentation strategies.
  • Ability to work well cross-functionally and communicate with audiences who may not have a security or engineering background.
  • Experience supporting multi-business-unit organizations with varying compliance and regulatory requirements.

We're working to build a more inclusive economy where our customers have equal access to opportunity, and we strive to live by these same values in building our workplace. Block is an equal opportunity employer evaluating all employees and job applicants without regard to identity or any legally protected class. We will consider qualified applicants with arrest or conviction records for employment in accordance with state and local laws and "fair chance" ordinances.
We believe in being fair, and are committed to an inclusive interview experience, including providing reasonable accommodations to disabled applicants throughout the recruitment process. We encourage applicants to share any needed accommodations with their recruiter, who will treat these requests as confidentially as possible. Want to learn more about what we're doing to build a workplace that is fair and square? Check out our I+D page.

While there is no specific deadline to apply for this role, U.S. roles are typically open for an average of 55 days before being filled by a successful candidate. Please refer to the date listed at the top of this job page for when this role was first posted.


What Block employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom