KeyStep

Cloud Security Lead

Cleo
Remote US
about 1 month ago
full-timeremote

Skills & Technologies

AWSTerraformCI/CDSaaSCloudCloud ArchitectureCloud InfrastructureIAMSecurity ArchitectureEncryptionStrategyDriftData ProtectionInnovation

Job Description

Cleo is seeking a Lead Cloud Security Engineer to design, implement, and continuously improve security controls across our cloud infrastructure and SaaS environments.

This role is responsible for strengthening Cleo’s AWS security posture, embedding secure-by-default cloud guardrails, and partnering closely with Platform and Engineering teams to reduce infrastructure risk without slowing innovation.

The ideal candidate is hands-on, technically deep in AWS, and experienced in building scalable cloud security capabilities in a high-growth SaaS environment.

What You Will Be Doing

Cloud Security Architecture

Design and implement secure cloud architecture patterns

Establish guardrails for AWS accounts and services

Strengthen multi-account strategy and segmentation

Improve IAM design, permission boundaries, and least-privilege models

Review major infrastructure changes for security impact

Cloud Detection and Visibility

Implement and tune cloud-native detection capabilities

Integrate AWS security services into centralized monitoring

Identify misconfigurations and excessive permissions

Improve signal-to-noise ratio in cloud alerts

Infrastructure as Code Security

Embed security controls into Terraform or other IaC workflows

Enforce policy-as-code guardrails

Ensure IaC scanning is integrated into CI/CD pipelines

Reduce configuration drift across environments

Vulnerability and Configuration Management

Oversee cloud misconfiguration detection and remediation

Track infrastructure vulnerability exposure

Reduce critical vulnerability exposure window

Partner with Platform teams to automate remediation

Data Protection and Encryption

Ensure proper encryption standards across storage and databases

Manage KMS usage and key lifecycle best practices

Strengthen logging and monitoring coverage

Incident Response Support

Lead cloud-focused investigations during security incidents

Improve forensic readiness in AWS

Harden logging and evidence retentio

Company & Role Analysis

JobSeeker+
Likely perks
Private MedicalPension25+ Days HolidayStock OptionsLearning BudgetFlexible Hours
Culture & working style

Neutral 2–4 sentence summary of what working at this company is like, drawn from public reviews and press coverage. Tone, collaboration style, pace, benefits highlights.

Market salary range

£45,000 – £60,000 (Glassdoor, Levels.fyi, 2025)

Unlock the full analysis for this job
Sign in to unlock →

Similar roles

See more
Tec Partners
London, UK
£66,000 – £72,000
Contract
about 20 hours ago

Salary: £66,000 - 72,000 per year Requirements: Hands-on experience with GCP security services (e.g. IAM, VPC, Security Command Centre) Prov…

View Job
EPAM Systems
London, UK
£80,486 – £80,486
Full-time
2 days ago

We are seeking a highly skilled Lead Cloud Security Systems Engineer to design, implement and enhance our cloud security frameworks focusing…

View Job
Revybe IT Recruitment Ltd
M12AG
£85,000 – £90,000
Full-time
3 days ago

Cloud Security Architect Manchester – Hybrid, 3 days a week in the office. Commutable from Stockport, Wigan, Bolton, Rochdale, Bury, Sale,…

View Job
Tec Partners
London, UK
£66,000 – £72,000
Contract
6 days ago

Salary: £66,000 - 72,000 per year Requirements: Hands-on experience with GCP security services (e.g. IAM, VPC, Security Command Centre) Prov…

View Job
Apply NowApply with CV Improver