Haystack
← Back to Jobs
Technology

Senior Cloud Security Engineer - Application & Platform Security - Boston

Motion Recruitment Partners, LLCBoston, MA🇺🇸United StatesPosted 28 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Job Description

A respected global investment management firm is seeking a Senior Cloud Security Engineer to join its technology risk and cybersecurity organization. The firm has a long-standing reputation for active investment management, fundamental research, and global collaboration, supported by a sophisticated technology ecosystem spanning cloud infrastructure, investment applications, analytics platforms, and enterprise services.

As a Senior Cloud Security Engineer, you will focus on securing cloud-hosted applications and platforms used by investment professionals, researchers, and business teams worldwide. Unlike traditional cloud security roles that concentrate on infrastructure hardening, governance, or threat detection, this position is centered on application security within cloud environments. You will work directly with software engineering teams to identify security risks early in the development lifecycle and ensure cloud-native applications are designed, built, and deployed securely.

In this role, you will lead initiatives involving secure software development, cloud application protection, API security, and security testing automation. You will help establish security standards across modern application architectures, review new services before production deployment, and develop tooling that enables engineering teams to identify and remediate vulnerabilities independently. The ideal candidate enjoys working closely with developers and views security as a product-enabling function rather than a compliance exercises.

Required Skills & Experience
  • Experience securing cloud-native applications in AWS and/or Azure
  • Strong understanding of application security principles
  • Experience with Secure SDLC methodologies
  • Knowledge of API security, authentication, and authorization frameworks
  • Experience with SAST, DAST, SCA, and application security testing tools
  • Understanding of OWASP Top 10 and common web application vulnerabilities
  • Experience securing CI/CD pipelines and deployment workflows
  • Proficiency in Python, Java, C#, or similar programming languages
  • Familiarity with microservices and distributed application architectures
  • Knowledge of container technologies and Kubernetes

Desired Skills & Experience
  • 5+ years of cybersecurity, application security, or cloud security experience
  • Experience working with enterprise software development teams
  • Financial services or asset management experience
  • Experience implementing security champions programs
  • Familiarity with API gateways and cloud application firewalls
  • Experience with secrets management platforms
  • Security certifications such as CSSLP, CISSP, CCSP, or GIAC certifications
  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field

What You Will Be Doing

Daily Responsibilities
  • 100% Hands On
  • Conduct security reviews for cloud-based applications and services
  • Partner with development teams to identify and remediate security vulnerabilities
  • Implement application security tooling within development and deployment pipelines
  • Perform threat modeling exercises for new cloud initiatives and business applications
  • Develop security standards and reusable patterns for cloud-native development
  • Assess application architectures for potential security weaknesses and design flaws
  • Automate application security testing and vulnerability validation processes
  • Improve API security controls and authentication mechanisms
  • Support remediation efforts for findings identified through penetration testing and security assessments
  • Educate engineering teams on secure coding best practices and emerging application security threats

The Offer
  • Bonus OR Commission eligible

You will receive the following benefits
  • Medical Insurance
  • Dental Benefits
  • Vision Benefits
  • Paid Time Off (PTO)
  • 401(k) (including match, if applicable)

Applicants must be currently authorized to work in the US on a full-time basis now and in the future.

Skills

Microservices
AWS
OWASP
Azure
C#
Java
Kubernetes
Penetration Testing
Python

Similar jobs