Haystack
← Back to Jobs
Technology
ES

Cloud Security Vulnerability Management Engineer

Estuate Inc.United States🇺🇸United StatesPosted Oct 8, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
Yesterday
AWSAzureGoogle CloudPrisma

Job Description

Job description:
Role: Cloud Security VM Engineer
REMOTE

Role Summary Cloud Security Engineer responsible for triaging and analyzing vulnerabilities across multi-cloud environments (AWS, Google Cloud Platform, Azure) using CNAPP platforms, providing actionable remediation guidance to stakeholders across infrastructure and application security domains.


Key Responsibilities

  • Triage, prioritize, and track cloud vulnerabilities surfaced through CNAPP tooling (e.g., Upwind, Wiz, Prisma Cloud), correlating findings across infrastructure and application layers
  • Analyze cloud misconfigurations, CVEs, and runtime risks across AWS, Google Cloud Platform, and Azure.
  • Translate vulnerability/security issue findings into clear, stakeholder-ready remediation guidance and  verify proper fixes are implemented and validated post-remediation before closure
  • Record and report operational metrics including MTTR and MTTD to measure program effectiveness and drive continuous improvement in remediation velocity
  • Partner with VM, App Sec, and cloud engineering teams to drive remediation workflows and track closure SLAs
  • Support cloud security governance by maintaining visibility into asset exposure, attack surface, and risk posture across multi-tenant environments
  • Contribute to security runbooks, risk scoring frameworks, and remediation playbooks aligned to business risk

Required Qualifications

  • 4+ years in cloud security with hands-on experience in AWS, Google Cloud Platform, and Azure
  • Proficiency with CNAPP platforms for vulnerability triage and cloud posture management
  • Strong foundation in infrastructure security (IaC, networking, compute) and application security (SAST/DAST, container security, secrets management)
  • Experience communicating technical risk to non-technical stakeholders with clear remediation priorities
  • Familiarity with vulnerability management tools such as Tenable, Qualys, or equivalent

Preferred Qualifications

  • Experience with CNAPP platforms like Upwind, Wiz or Orca Security
  • Experience with integrating CNAPP findings into SIEM/SOAR or ticketing platforms (e.g., ServiceNow VRM)
  • Cloud certifications: AWS Security Specialty, Google Cloud Platform Professional Security Engineer, or AZ-500

Similar jobs