Information Security Engineer 4 – Contingent (Posture Management Engineer)
Location Options:
-
Charlotte, NC
-
Phoenix/Chandler, AZ
-
Dallas/Irving, TX
Contract Type: Contingent
About the Role:
We are seeking an experienced Information Security Engineer 4 – Posture Management to join a dynamic Cloud Security team within the Vulnerability & Patch Management space. You will play a key role in supporting cloud security initiatives, focusing on Cloud Security Posture Management (CSPM), engineering automation, and ensuring secure cloud configurations across public cloud platforms. This role is ideal for a motivated self-starter who thrives in a fast-paced, collaborative environment.
Key Responsibilities:
-
Lead the migration and engineering of CSPM capabilities to a new Cloud Native Application Protection Platform (CNAPP).
-
Act as a subject matter expert (SME) on CSPM tools, roadmap features, and best practices.
-
Enable and tune cloud security detection for misconfigurations, configuration drift, and ad-hoc developer scans.
-
Transform security requirements into automated policies using Rego or similar Policy-as-Code tools.
-
Collaborate with teammates, vendors, and partners to ensure policy development automation success.
-
Lead technical discussions, design, and develop complex security solutions.
-
Troubleshoot and resolve escalated CSPM support cases.
-
Contribute to internal code repositories and maintain high-quality documentation.
-
Train team members on policy automation tooling and methodologies.
-
Work effectively with a virtual team across multiple locations and time zones.
Required Skills & Experience:
-
5+ years of Information Security Engineering experience.
-
4+ years of experience with Terraform or similar automation tools.
-
2+ years of hands-on experience with Azure and Google Cloud platforms, workloads, configurations, and hardening practices.
-
1+ year experience with Rego or Resource Query Language (RQL) policy development.
-
Strong programming and automation skills with Python.
-
Experience with REST API integration, data extraction, and transformation.
-
Familiarity with CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
-
Strong verbal and written communication skills, with the ability to work independently and collaboratively.
-
Experience with Microsoft Office and collaboration tools (Teams, SharePoint, Visio, etc.).
-
Experience in Agile/Scrum or Kanban team environments.
Desired Skills:
-
Deep experience with CNAPP/CSPM tools (engineering or support).
-
Expertise in Policy-as-Code (PaC) automation and Infrastructure as Code (IaC).
-
Knowledge of DevSecOps, cloud deployment automation, and automated testing.
-
Intermediate to advanced experience with Kubernetes (AKS/GKE/OCP).
-
Familiarity with cloud security frameworks (CSA, CIS, NIST).
-
Experience in change and incident management for large-scale environments.
-
Security certifications such as CISSP, CISM, CISA, CRISC, GIAC, or CCSK.
-
Azure and/or Google Cloud certifications are a plus.
What You’ll Gain:
-
Opportunity to work on high-impact cloud security initiatives.
-
Collaborate with a global, cross-functional security team.
-
Hands-on experience with cutting-edge CSPM and CNAPP technologies.
-
Exposure to advanced automation, policy engineering, and cloud security best practices.
