Principal Cloud Security Engineer
Aws Security
Azure Security
Cloud
Cloud Infrastructure
Cloud Platform
Cloud Platforms
Cloud Technology
Cybersecurity Tools
DevOps
DevSecOps
Google Cloud Security
Identity and Access Management
Information Security
InfoSec
Infrastructure As Code
Risk Management
Security Automation
Security Compliance
Security Standards
Solution Architecture
Job Description
Secure and harden Rocket Lab’s cloud footprint across vendor platforms, code pipelines, and automation in an onsite role in Long Beach, CA.
Responsibilities
- Design, implement, and maintain security controls for hybrid cloud environments spanning IaaS, PaaS, SaaS, and FaaS solutions
- Design and develop custom automation to support cyber team objectives
- Provide security support for internal and external design reviews related to security
- Perform security assessments and risk analyses to identify vulnerabilities and define mitigations for automated infrastructure, including public cloud, CI/CD pipelines, and agentic systems
- Partner with Infrastructure Operations to implement and manage IAM solutions that control access to cloud resources and applications
- Create documentation, plans, and proofs of concept for cybersecurity platform improvements
- Configure and monitor cloud security tools and services
- Collaborate with development teams to apply security best practices across the SDLC, DevOps, and MLOps processes
- Maintain systems to stay current on emerging threats, vulnerabilities, and DevSecOps/MLOps best practices, and recommend proactive actions to strengthen security posture
- Advise and support internal teams on incident response, compliance, and security awareness training
- Participate in ongoing security audits, assessments, and compliance reviews to support adherence to regulatory requirements and industry standards
Requirements
- 12+ years experience in scripting languages, including Bash, PowerShell, or Python
- 12+ years experience with configuration management and/or Infrastructure as Code tools such as Puppet, Ansible, or Terraform
- Bachelor’s degree (or equivalent years of work experience), with 16+ years total work experience
- Proven experience in cloud security architecture, design, and implementation across AWS, Azure, and Google Cloud
- Hands-on experience with cloud security tools and services, including AWS Security Hub, Azure Security Center, and Google Cloud Security Command Center
- Experience working under US Government compliance regimes such as CMMC, NIST, and DISA STIG, plus ITIL/Change Review systems
- Experience with vulnerability management systems such as Tenable and Bringa
- Experience with CLI scanning tools including Trivy and OpenSCAP
- Extensive experience with git-driven version control platforms such as GitHub, GitLab, and Bitbucket
- Strong understanding of networking concepts, encryption techniques, and secure communication protocols
- Experience with databases including PostgreSQL and SQLite, plus data formats such as Parquet and Arrow
- Proficiency in analytics systems including PowerBI and Jupyter, and vendor-agnostic assessment engines such as Cloud Custodian and Panther
- U.S. citizenship required, due to program requirements
Technologies
- Bash, PowerShell, Python
- Puppet, Ansible, Terraform
- AWS, Azure, Google Cloud
- AWS Security Hub, Azure Security Center, Google Cloud Security Command Center
- CMMC, NIST, DISA STIG, ITIL
- Tenable, Bringa
- Trivy, OpenSCAP
- GitHub, GitLab, Bitbucket
- PostgreSQL, SQLite
- Parquet, Arrow
- PowerBI, Jupyter
- Cloud Custodian, Panther
- IaaS, PaaS, SaaS, FaaS
- CI/CD, SDLC, DevOps, MLOps, DevSecOps, IAM
These qualifications would be nice to have
- Advanced degree in computer science, information technology, cybersecurity, or equivalent career experience
- Involvement with community cybersecurity organizations
- Experience with AWS GovCloud / Azure GCC High
- Experience with CI/CD pipeline security
- Experience with Tier 2 cloud vendors
- Experience with hybrid cloud engineering
- Experience with SAST and DAST testing
- Experience with secrets management including vaults and HSMs
- Experience with cloud incident response / forensics
- Experience with log aggregators such as Graylog, ELK, or Splunk
Important information
- US offices only: Rocket Lab employees must be a U.S. citizen, lawful U.S. permanent resident (current Green Card holder), or lawfully admitted as a refugee or granted asylum, or be eligible to obtain required authorizations from the U.S. Department of State and/or U.S. Department of Commerce as applicable
- Reasonable accommodation: Applicants requiring accommodation for the application/interview process should contact Giulia Johnson at [email protected]
- Response timeline: A response to requests may take up to two business days
- New Zealand offices only: Background checks will be undertaken prior to any employment offers, including nationality checks, based on eligibility to access equipment and data regulated by the United States’ International Traffic in Arms Regulations
- Ineligibility note for New Zealand offices: Applicants may be ineligible if they do not hold citizenship of Australia, Japan, New Zealand, Switzerland, the European Union, or a country part of NATO, or if they hold ineligible dual citizenship or nationality
Location: Long Beach, CA (onsite)
Compensation: USD 152,300 - 165,000 per year
Experience: 12+ years
Education: Bachelor’s degree (or equivalent years of work experience)
Similar Jobs
S