Job Summary:
PayCargo is the world's leading online payment solution that is revolutionizing the shipping and cargo world. The Senior Engineer, Cloud Security is responsible for strengthening and operating security controls across a modernizing platform, focusing on implementing and operating security controls while partnering with various teams to ensure the security and availability of PayCargo's global payments platform.
Responsibilities:
โข Monitor the perimeter, cloud, and endpoint environments for threats, misconfigurations, and anomalous activity across AWS and Microsoft Entra ID
โข Operate and tune security tooling, including CrowdStrike, Microsoft Defender, and CloudWatch and SNS logging and alerting
โข Triage security alerts, drive incident response, and lead root cause analysis with clear, durable follow-up
โข Maintain and improve on-call and escalation workflows (e.g., PagerDuty) so security events are handled consistently
โข Run periodic access reviews and enforce least privilege across AWS IAM and IAM Identity Center, Microsoft Entra ID, and SaaS platforms
โข Strengthen RBAC/ABAC, MFA, and SSO, SAML2, and OAuth2/OIDC patterns across internal and customer-facing systems
โข Reduce standing access and broad repository or local admin privileges in favor of bounded, auditable access
โข Operate the federated access model, including SAML-based assumed access to AWS (via CommonFate Granted) and GitHub OIDC for pipelines, so people and CI receive least-privilege, time-bound access without static credentials
โข Operate the PKI, including AWS Private CA and ACM, certificate issuance and rotation, CRLs, and mTLS trust stores on load balancers
โข Administer Entra ID groups and the Tailscale ACLs that gate network access
โข Govern dependency and supply-chain risk using Dependabot and approved-package practices, and keep secrets in AWS Secrets Manager and SSM Parameter Store
โข Support SOC 1 Type 2, SOC 2, and PCI DSS obligations by owning the implementation of controls and the evidence behind them
โข Coordinate penetration testing, remediation tracking, and verification of fixes
โข Produce clean, repeatable audit evidence and reduce last-minute audit scrambles
โข Translate compliance requirements into operational controls engineers can follow without constant guidance
โข Help enforce containment for AI and model usage, including stateless model access, whitelisted egress, and approved destinations
โข Support tokenization and PII-protection patterns so sensitive data is not exposed to model providers
โข Review AI-assisted workflows and applications for security boundaries, logging, and blast-radius reduction
โข Partner with DevOps and Engineering to embed security into the Terraform and GitHub Actions pipelines, environments, and deployment paths
โข Work with Compliance on audits and frameworks (SOC, PCI, ISO 27001) and on auditor-facing reporting
โข Advise Product and Architecture on secure-by-design patterns and practical trade-offs
โข Implement and operate the security controls, boundaries, and egress rules defined in the platform architecture owned by the Director of Cloud & AI Platform Architecture
โข Provide clear status, escalate risks early, and document controls, runbooks, and decisions
Qualifications:
Required:
โข 5+ years of hands-on security engineering, cloud security, or security operations experience preferred
โข Strong working knowledge of AWS security and identity services, plus an enterprise identity provider such as Microsoft Entra ID or Okta
โข Hands-on experience with endpoint and threat tooling such as CrowdStrike and Microsoft Defender
โข Practical experience with SOC and/or PCI DSS controls, audits, and evidence
โข Strong understanding of IAM, RBAC/ABAC, MFA, SSO, SAML2, OAuth2/OIDC, JWT, including common failure modes, and least-privilege design
โข Hands-on experience with PKI and certificates, including a certificate authority such as AWS Private CA, TLS and mTLS, and certificate issuance, rotation, and revocation
โข Experience with incident response, logging and alerting, and root cause analysis
โข Ability to convert security and compliance requirements into repeatable operational controls
โข Strong communication and documentation skills, and the ability to influence without direct authority
โข Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent practical experience
โข 5+ years of hands-on security engineering, cloud security, or security operations experience preferred
โข Demonstrated experience operating production security controls in cloud environments
โข Experience supporting SOC, PCI, or comparable audits and frameworks
โข Payments, fintech, SaaS, or logistics experience is a plus
Preferred:
โข Security certifications such as CISSP, CISM, CCSP, or equivalent
โข Experience coordinating penetration testing and managing remediation
โข Familiarity with secure AI/LLM patterns, data tokenization, and egress control
โข Experience securing CI/CD pipelines (GitHub Actions), GitHub/ZenHub, and Terraform-based infrastructure-as-code
โข Experience with zero-trust network access such as Tailscale or Zscaler, and SSO brokers such as CommonFate Granted
โข Experience in payments, fintech, SaaS, or other regulated, high-volume environments
โข Familiarity with ISO 27001 and SaaS security posture management
Company:
PayCargo is an online payment settlement system for the Global Freight Maritime industry. Founded in 2007, the company is headquartered in Coral Gables, USA, with a team of 201-500 employees. The company is currently Growth Stage.