Job Summary:
True Anomaly is a company focused on building technology that secures the space domain. As a Senior Cloud Security Engineer, you will be responsible for implementing security controls and building security tooling for cloud platforms, particularly in multi-cloud environments like Azure and AWS, while collaborating closely with engineering teams.
Responsibilities:
โข Build security tooling, automation, and services for cloud securityโimplementing secure patterns that engineering teams can adopt
โข Implement security best practices and provide technical input on cloud security, IAM architecture, network security, and infrastructure-as-code
โข Implement and maintain security controls that strengthen the security posture of our cloud environments across Azure and AWS
โข Implement secure-by-default cloud infrastructure including IAM, network architecture (VPCs, subnets, NACLs, Security Groups, Transit Gateways), data protection, encryption, and security monitoring
โข Operate and maintain PKI infrastructure for cloud environmentsโincluding private CA hierarchies (AWS Private CA, AD CS), certificate lifecycle management, mTLS for service-to-service authentication, and load balancer certificate management
โข Operate and maintain HashiCorp Vault as the central secrets management platformโincluding Vault PKI engine, dynamic secrets, authentication methods, and policy management. You'll build and maintain this infrastructure, not just configure managed services
โข Partner with Kubernetes Security Engineer to implement unified PKI infrastructure across cloud and container environments, providing input on design decisions. Collaborate on K8s IAM integration, network policies, node security, and CSI driver security
โข Design and troubleshoot multi-account and multi-VPC network topologiesโdiagnosing connectivity issues and security group misconfigurations across cloud environments
โข Build automation and tooling to enforce security policies, detect misconfigurations, and respond to threats in cloud environments
โข Execute cloud security posture management (CSPM), threat detection, and incident response projects
โข Implement security improvements to infrastructure-as-code, CI/CD pipelines, and deployment processes
โข Partner with engineering teams to implement secure cloud architectures for new capabilities and workloads
โข Build security testing tools, CLI utilities, and dashboards to continuously validate security controls
โข Solve complex security challenges in multi-cloud environments
โข Leverage AI tools to accelerate development and automate security workflows
Qualifications:
Required:
โข Active security clearance or ability to obtain and maintain security clearance
โข Experience securing production cloud environments at scale, with strong understanding of cloud security models, attack patterns, and defensive strategies across Azure and AWS
โข Strong software development skills in Python (preferred) and/or Go with experience building security tooling and automation
โข Strong software engineering fundamentals: comfortable with data structures, algorithms, API design, debugging production systems, and working across multiple languages
โข Strong Terraform skills including module design and infrastructure-as-code security best practices
โข Experience building security tooling or automation used by engineering teams
โข Strong experience with cloud networking and troubleshooting across AWS and Azure: VPCs/VNets, subnets, NACLs/NSGs, Security Groups, Transit Gateways/Virtual WAN, VPC peering, route tables, and VPN/ExpressConnectโyou can debug 'why can't X talk to Y' across multi-account/multi-subscription network topologies
โข Hands-on experience with cloud security tools (CSPM, CWPP, SIEM) and infrastructure-as-code security (Terraform, CloudFormation)
โข Strong knowledge of IAM, encryption, logging/monitoring, and cloud-native security patterns
โข DevSecOps mindset with experience embedding security into development and operations workflows
โข Proven ability to assess risk, prioritize work, and execute complex security projects
โข Track record of solving complex technical problems
โข Comfortable diving into unfamiliar codebases and leveraging AI to bridge knowledge gaps
โข Strong communication skills and ability to collaborate effectively across teams
Preferred:
โข Strong PKI knowledge with hands-on experience working with certificate infrastructureโincluding certificate lifecycle management, mTLS implementation, certificate-based authentication, and X.509/TLS troubleshooting
โข Hands-on experience operating HashiCorp Vault in productionโincluding Vault PKI, dynamic secrets engines, and authentication methods. Experience integrating Vault with Kubernetes, AWS, and Azure auth methods is a plus
Company:
True Anomaly develops space security technologies, including spacecraft, software platforms, and mission systems for orbital operations. Founded in 2022, the company is headquartered in Centennial, USA, with a team of 201-500 employees. The company is currently Growth Stage.