Principal Cloud Security Engineer
Pax8, Inc ยท Remote, United States
About The Role
โ๏ธ Principal Cloud Security Engineer | Remote | USA & Canada
Pax8 is hiring a Principal Cloud Security Engineer across the USA and Canada to shape and secure the future of our cloud marketplace, protecting the infrastructure powering millions of platform interactions through modern cloud, platform, and AI-enabled security practices.
๐ Build the Security Foundations of the Future
This is a rare opportunity to become the technical authority for cloud security within Pax8's Platform Security function. You'll influence how security is designed, implemented, and governed across a rapidly evolving cloud ecosystem while partnering directly with engineering leaders responsible for some of the most critical technology in our business.
As technology, automation, and AI continue transforming the cloud marketplace, you'll help define the standards that allow innovation to happen safely at scale. You'll have the autonomy to set direction, solve complex security challenges, and create patterns that engineering teams can adopt globally.
๐ Join a Company Changing the Cloud Marketplace
At Pax8, we're building the technology marketplace of the future through cloud innovation, AI-powered insights, and a thriving global partner ecosystem. Today we support more than 39,000 partners, work with 130+ vendors, and help hundreds of thousands of businesses embrace modern technology.
Learn more about our journey through our US About page and US Newsroom, where you'll see how we're continuing to innovate, grow and invest in the future of technology.
๐ What You'll Be Doing
โ๏ธ Establish Secure-by-Design Cloud Standards
Create and evolve security baselines for cloud infrastructure, container platforms, platform tooling, and third-party services, ensuring security controls remain effective as our technology landscape grows.
๐ก๏ธ Strengthen Identity & Access Controls
Define modern least-privilege approaches across cloud identities, service accounts, platform access models, and containerized workloads, reducing risk while enabling engineering productivity.
โ๏ธ Secure the Software Delivery Lifecycle
Lead security governance across build and deployment platforms, helping engineering teams implement resilient controls that protect code, pipelines, secrets, and software supply chains.
๐ Validate Security Architecture at Scale
Evaluate network segmentation strategies, cloud connectivity patterns, workload isolation approaches, and platform architecture decisions to reduce attack surface and limit blast radius.
๐ Drive Visibility Through Security Metrics
Create meaningful security posture reporting that translates technical findings into business context, enabling informed risk decisions and continuous improvement.
๐ Define Security Patterns for Engineering Teams
Develop reference architectures, engineering standards, and decision records that make secure implementation easier and more consistent across the organisation.
๐ค Become a Trusted Technical Partner
Work closely with DevOps, Site Reliability Engineering, and Platform Engineering teams, embedding security expertise into architecture reviews, operational planning, and strategic initiatives.
๐ฏ The Impact You'll Have
Your work will directly influence the resilience, scalability, and security posture of the technology platform that powers Pax8's marketplace. You'll help engineering teams move faster with confidence, reduce operational risk, strengthen compliance readiness, and ensure security remains an accelerator rather than a blocker to innovation.
This role combines deep technical expertise with organisation-wide influence, allowing you to shape platform security practices that affect teams, partners, and customers globally.
โ What Success Looks Like
You'll thrive in this role if you bring
- Extensive experience securing modern cloud and infrastructure platforms.
- Deep practical expertise across Amazon Web Services services including identity, networking, encryption, logging, secrets management, containers, and data services.
- Demonstrated success creating security standards, architectural guidance, and governance frameworks that engineering teams genuinely adopt.
- Proven ability to influence technical decisions without relying on reporting-line authority.
- Advanced knowledge of Kubernetes security, workload isolation, access controls, network controls, and container governance.
- Strong understanding of software delivery security, platform automation, and modern deployment pipelines.
- Hands-on experience reviewing infrastructure as code and ensuring security controls are embedded into engineering workflows.
- Experience assessing SaaS and platform technologies through threat modelling and security architecture reviews.
- Familiarity with cloud security posture management and platform governance tooling beyond simple alert review.
- Knowledge of security considerations for emerging AI and agent-based workloads.
- Experience operating within multi-tenant environments where scale, availability, and data isolation are critical.
- The ability to balance pragmatism and risk management while remaining a trusted advisor to engineering teams.
๐ Trust and Hiring
At Pax8, we care deeply about building genuine, trust based relationships โ starting with how we hire.
To protect our business, our teams, and our customers, we use a range of measures throughout the recruitment process to help confirm authenticity and prevent fraud. These safeguards are designed to be fair, respectful, and proportionate, and may evolve as risks change. By applying, you acknowledge that we take steps to verify identity and representation during hiring. If you're applying as your authentic self, you have nothing to worry about โ we're excited to meet you.
We also use thoughtfully applied AI-enabled tools to support our hiring process. These tools may assist with tasks such as reviewing or prioritising applications, but hiring decisions
Similar roles you might like
See all โThis is an external listing. JobSpring does not represent or verify the employer. Report this listing
