Security Engineer – Cloud Security (AWS)
Amazon Web Services
Aws Inspector And Security Hub
Cloud
Cloud Computing
Cloud Platforms
Cloud Security
Data Security
DevSecOps
Facilities Management
Identity and Access Management
Information Security
InfoSec
IT Services
Risk Governance
Risk Management
Security
Security As Code
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Job Description
Xcel Energy offers a hybrid Security Engineer role focused on building and running a cloud security program that reduces risk through visibility, guardrails, and automation. You will work across AWS environments, coordinate remediation with responsible teams, and help strengthen security practices for DevSecOps and cloud-hosted applications.
Responsibilities
- Build and mature the AWS cloud security program with clear ownership, processes, and workflows.
- Identify, prioritize, and communicate cloud security risk across environments and stakeholders.
- Implement preventative controls and guardrails to reduce risk before deployment.
- Use automation and integration to reduce manual effort and improve consistency in security checks and workflows.
- Support remediation by driving findings to the appropriate owners and tracking outcomes.
- Act as the primary cloud security engineer for AWS environments, including commercial, GovCloud, dev, and test accounts.
- Leverage AWS native security capabilities such as Inspector, Security Hub, and related services to identify and analyze risk.
- Maintain visibility across IAM, network configuration, logging, monitoring, and workload security posture.
- Identify issues including overly permissive access, unused accounts, misconfigurations, and exposure risks.
- Develop and implement guardrails, policies, and controls to prevent insecure configurations and reduce attack surface.
- Promote hardened images, containers, and standardized builds to reduce risk at deployment.
- Integrate cloud security findings into existing workflows and coordinate remediation with responsible teams.
- Collaborate with Cloud Platform, SAP, Enterprise Architecture, and other teams to implement meaningful security improvements.
- Partner with Application Security to support DevSecOps practices, including CI/CD pipeline integration, gates, and automation.
- Support SAP cloud security needs and maintain awareness of SAP-specific risks within AWS environments.
- Use APIs, scripting, and integration to automate data collection, analysis, and workflow execution.
- Analyze cloud risk in context and communicate clear, actionable recommendations to stakeholders.
- Support logging and monitoring setup and integration while deferring operational ownership to SOC/IR teams.
Requirements
- Minimum 5 years of experience in information security.
- Strong hands-on experience with AWS cloud environments and security concepts.
- Strong understanding of AWS IAM, networking, logging, monitoring, and workload security.
- Experience using AWS native security tools such as Inspector, Security Hub, or equivalent.
- Strong understanding of DevSecOps, CI/CD pipelines, and application security fundamentals.
- Basic understanding of SAP environments in cloud-hosted architectures.
- Experience identifying and communicating risk related to cloud configurations and architecture.
- Strong analytical and complex technical problem-solving skills.
- Ability to communicate technical risk clearly to non-technical stakeholders.
- Experience with APIs, scripting, or automation for data integration and workflow execution.
- Ability to operate independently and build a program with limited oversight.
Technologies
- AWS
- Inspector
- Security Hub
- IAM
- CI/CD pipelines
- DevSecOps
- APIs
- Scripting
- Automation
- Containers
- SAP
- Azure
- GovCloud
Benefits
- Annual Incentive Program
- Medical/Pharmacy Plan
- Dental
- Vision
- Life Insurance
- Dependent Care Reimbursement Account
- Health Care Reimbursement Account
- Health Savings Account (HSA) (if enrolled in eligible health plan)
- Limited-Purpose FSA (if enrolled in eligible health plan and HSA)
- Transportation Reimbursement Account
- Short-term disability (STD)
- Long-term disability (LTD)
- Employee Assistance Program (EAP)
- Fitness Center Reimbursement (if enrolled in eligible health plan)
- Tuition reimbursement
- Transit programs
- Employee recognition program
- Pension
- 401(k) plan
- Paid time off (PTO)
- Holidays
- Volunteer Paid Time Off (VPTO)
- Parental Leave
Preferred Qualifications
- Experience across multiple cloud environments, including AWS multi-account and GovCloud architectures.
- Experience supporting Azure cloud environments.
- Experience implementing preventative security controls such as guardrails, policy enforcement, or pipeline gating.
- Experience improving data quality and visibility across multiple cloud and security data sources.
- Experience working with enterprise cloud platform, networking, or architecture teams.
Certifications
- AWS Certified Security – Specialty required.
- AWS Certified Solutions Architect – Professional or AWS Certified DevOps Engineer – Professional preferred.
Location and Compensation
Denver, CO (Hybrid): three days per week in the office. Must be located within Xcel Energy territory and reasonably close to an Xcel Energy facility. Denver, Colorado and Minnesota areas preferred.
Salary Range: USD 97,600 - 138,600 per year.