Cloud Security Engineer
Job Description
Join Gordon Food Service in a hybrid role where you help strengthen cloud protection across infrastructure and applications. In this position, you will define, document, and implement cloud security best practices and standards, collaborate closely with DevOps teams, and build security-focused automation that supports CI/CD. The work is grounded in process adoption, continuous threat awareness, and practical guidance for engineering teams building and running secure environments.
Responsibilities
- Drive adoption of Enterprise Information Security (EIS) team processes and disciplines within cloud environments (including Risk Management, Vulnerability Management, Secure Application Development, Secure Environment Configuration, Identity Management, and more).
- Provide cloud configuration and deployment expertise to Gordon Food Service.
- Analyze cloud platform vulnerabilities and guide resolution with management-level support.
- Study, define, and implement secure provisioning, configuration, and operational aspects of on and off-premise cloud environments.
- Write and maintain configuration and deployment solutions via code to support security requirements in CI/CD.
- Research and stay current on the evolving cloud threat landscape, adapting protection strategies to address emerging threats.
- Perform security risk assessments, including risk analysis for new cloud-related technologies or tools.
- Conduct internal penetration testing against new or modified software solutions.
- Coordinate external security assessments, including “grey-box” web application penetration tests.
- Provide security-focused cloud architecture guidance to software engineers across the organization.
- Write, maintain, and assist with secure coding, configuration standards, and best practices for custom software development.
- Interface with various teams across the organization in day-to-day activities.
Requirements
- Bachelor’s Degree in Computer Science or a related field (preferred).
- 5+ years of information technology experience, including software engineering, DevOps, and/or system engineering, or an equivalent combination of education, training, and experience required.
- Knowledge of security concepts such as SAST, DAST, RBAC, least privilege, secrets management, scanning tools, network security concepts, and the CIA triad.
- Strong written and verbal communication, along with organizational and problem-solving capabilities.
- Ability to multitask, prioritize, and work independently or in a team environment.
- Experience with public cloud providers including Google Cloud Platform (GCP), AWS, and Azure.
- Experience with application containerization and container orchestration technologies.
- Experience with cloud-specific networking for mesh and least-privilege network access.
- Experience with software-defined networking, including routing, bridging, VLANs, and switches.
- Experience with build tools, configuration management tools, and provisioning tools.
- Experience with the languages used in cloud development and configuration.
- Experience automating build and release processes.
- Knowledge of Unix/Linux.
- Knowledge of spreadsheet, word processing, presentation, email, and internet software applications, particularly Google Apps.
When you will work
- Monday to Friday, 8am to 5pm
- Hybrid schedule: 4 days in office in Wyoming, MI or Atlanta, GA with 1 day remote
Technologies
- Google Cloud Platform (GCP), AWS, Azure
- SAST, DAST, RBAC, secrets management, scanning tools
- Application containerization, container orchestration technologies
- Cloud specific networking technology, mesh, least privilege network access
- Software defined networking, routing, bridging, VLANs, switches
- Build tools, configuration management tools, provisioning tools
- Unix/Linux, Google Apps