Senior Cloud Controls Engineer $69.72/hr

Veterans Sourcing Group

  • Alpharetta, GA
  • 1 day ago
  • $69.72 Per Hour

Highlights

Our vision is to deliver Programs that protect and enable the business, ensure secure delivery of services to our clients, adjust to address the risks presented by an evolving threat landscape, meet regulatory expectations, and offer highly attractive career opportunities. Cyber Data Risk & Resilience: The mission of Cyber Data Risk & Resilience (CDRR) is to deliver first-line defences to manage risks to Firm technology, information and cyber threats through risk identification, control management and assurance.

Numbers & Facts

LocationAlpharetta, GA

Description

Senior Cloud Controls Engineer
Alpharetta, GA - hybrid
12 months+


Profile Description:
The Cloud Security Engineering team enables the firm to securely adopt and scale cloud-native technologies across the enterprise. You will work alongside highly skilled professionals in an environment that values intellectual rigor, technical depth, and collaboration. This role offers the opportunity to contribute to enterprise-scale cloud security while supporting standards, engineering practices and risk governance. We design, implement and operationalize security controls that govern the use of cloud services at scale across Microsoft Azure, AWS, and GCP.
We are seeking a Senior Cloud Controls Engineer to contribute to cloud security research and control engineering in a fast-paced, highly technical environment. This role partners with engineering, architecture, risk and business stakeholders to ensure secure, scalable, and compliant cloud adoption.

What you'll do in the role:
Design and implement deploy-time security controls for cloud services across Azure, AWS, and GCP, using OPA (Rego) and Regula
Translate firm-wide configuration baseline requirements into enforceable policy-as-code controls integrated directly into Terraform workflows and CI/CD pipelines
Contribute across the control implementation lifecycle: requirement interpretation, policy authoring, testing, optimization, and deployment within engineering pipelines.
Establish and maintain reusable policy libraries and modules to ensure consistency and scalability of controls across services and environments.
Provide deep technical expertise in Terraform, infrastructure-as-code patterns, and pipeline orchestration, ensuring secure and efficient deployments.
Define and implement testing strategies for policy validation, including unit and integration testing.
Identify gaps where requirements cannot be enforced at deploy-time and propose compensating controls or alternative enforcement points.
Contribute to the evolution of a unified control framework, enabling consistent control logic across deploy-time and runtime evaluation points
Contribute to cloud security strategy and standards.
Technical Expertise & Collaboration
Serve as a senior technical contributor for deploy-time control implementation, helping shape technical approaches and support high-quality delivery.
Provide hands-on technical guidance and peer support in OPA/Rego, Regula, Terraform, and secure pipeline design.
Participate in code reviews, design discussions, and knowledge sharing to strengthen engineering quality and consistency across the team.
Partner with platform engineering, security architecture, and application teams to improve implementation clarity and reduce delivery friction.
Communicate complex technical concepts clearly to engineering teams, stakeholders, and senior leadership.
Contribute to engineering best practices for infrastructure-as-code, policy development, testing, and review processes.

What you'll bring to the role:
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
7+ years of hands-on experience in cloud security engineering, with a strong focus on infrastructure-as-code and deployment pipelines.
Proven experience designing and implementing policy-as-code controls using OPA/Rego and/or Regula in production environments.
Deep hands-on expertise with Terraform, including module design, state management, and secure configuration patterns.
Strong experience integrating security controls into CI/CD pipelines, including gating and enforcement mechanisms.
Demonstrated ability to translate security requirements into automated, testable, and enforceable deploy-time controls.
Solid understanding of cloud security architectures across AWS, Azure, and/or GCP, including IAM, networking, and data protection controls.
Experience implementing control validation and testing strategies, including policy unit testing, pipeline validation, and drift detection.
Familiarity with CSPM platforms and the ability to align deploy-time controls with runtime detection and compliance models.
Strong understanding of modern threat models, attack paths, and misconfiguration risks in cloud environments, and how to mitigate them through preventive controls.
Experience building and maintaining reusable policy libraries and shared control frameworks at enterprise scale.
Experience working as a senior engineer on complex technical initiatives, including task prioritization, delivery planning, and contribution to technical direction.
Demonstrated ability to mentor peers and share expertise, particularly in policy-as-code, Terraform, and secure pipeline practices.

What you can expect from Brokerage
We are committed to maintaining the first-class service and high standard of excellence that have defined Brokerage for over 85 years. At our foundation are five core values — putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back — that guide our more than 80,000 employees in 1,200 offices across 42 countries. At Brokerage, you will find trusted colleagues, committed mentors and a culture that values diverse perspectives, individual intellect, and cross-collaboration. Our Firm is differentiated by the caliber of our diverse team, while our company culture and commitment to inclusion define our legacy and shape our future, helping to strengthen our business and bring value to clients around the world. Learn more about how we put this commitment to action: Brokerage.com/diversity. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits in the industry.
Brokerage is an equal opportunities employer. We work to provide a supportive and inclusive environment where all individuals can maximise their full potential. Our skilled and creative workforce is comprised of individuals drawn from a broad cross section of the global communities in which we operate and who reflect a variety of backgrounds, talents, perspectives, and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing, and advancing individuals based on their skills and talents.

Cyber Data Risk & Resilience:
The mission of Cyber Data Risk & Resilience (CDRR) is to deliver first-line defences to manage risks to Firm technology, information and cyber threats through risk identification, control management and assurance. This allows the business to operate and grow in a secure and legally compliant manner. Our vision is to deliver Programs that protect and enable the business, ensure secure delivery of services to our clients, adjust to address the risks presented by an evolving threat landscape, meet regulatory expectations, and offer highly attractive career opportunities.

Similar Jobs

See more jobs