About the Role
Merci Technologies is seeking a Cloud Security Engineer to secure the cloud environments and workloads that power one of our enterprise clients. As the organization scales its footprint across AWS and Azure, this role owns the controls, guardrails, and secure-by-design practices that keep that growth from outpacing security. You will work hands-on across infrastructure, platform, and DevOps boundaries, embedding security into how cloud resources are provisioned, configured, and operated rather than bolting it on afterward.
The day to day blends engineering and risk reduction. You will operate cloud security posture management tooling and drive findings to remediation, build security checks directly into infrastructure-as-code pipelines, harden container and Kubernetes workloads, and define the identity, network, and data protection controls that govern the environment. Just as important, you will partner with platform and DevOps teams so that security becomes part of the CI/CD workflow and a shared responsibility rather than a gate. This role suits an engineer who is equally comfortable writing Terraform, reading a CSPM finding, and explaining cloud risk to an architecture review board. This is a fully remote position open to Contract or Full-Time candidates.
Key Responsibilities
- Implement and manage cloud security controls and guardrails across AWS and Azure environments
- Operate cloud security posture management (CSPM) tooling and drive misconfiguration findings to closure
- Embed security into infrastructure-as-code pipelines using Terraform, CloudFormation, or equivalent
- Secure container and Kubernetes workloads, including image scanning, admission control, and runtime protection
- Define and enforce identity, network segmentation, encryption, and data protection controls in the cloud
- Partner with platform and DevOps teams to integrate security into CI/CD workflows
- Support cloud incident detection and response, including logging, alerting, and SIEM integration
- Contribute to cloud security architecture standards and reference patterns
Required Qualifications
- 4 to 8 years of cloud security or cloud engineering experience
- Hands-on experience securing AWS, Azure, or GCP production environments
- Working knowledge of infrastructure-as-code with Terraform or CloudFormation
- Experience with CSPM and cloud-native security tooling
- Solid understanding of container and Kubernetes security concepts
Preferred Qualifications
- AWS Certified Security Specialty, CCSP, or Azure Security Engineer Associate certification
- Certified Kubernetes Security Specialist (CKS)
- Experience with cloud detection and response or SIEM integration at scale
- Familiarity with DevSecOps practices and policy-as-code tools such as OPA
What You Will Bring
You believe security should move at the speed of the cloud, not slow it down. You can write the automation that catches a misconfiguration before it ships, and you can sit with a DevOps team and make security feel like a partnership rather than a roadblock. You stay current as cloud services evolve and you translate that knowledge into practical guardrails.