Cadence logo

Cloud Security Operations Engineer - Cadence - San Jose, United States

Cloud Security Engineer

Posted: July 22, 2026
Posted 2 days ago
Last seen in crawl: July 23, 2026 (today)
Estimated Expiry: August 26, 2026
Role & Management
Role Level:Mid-Level
Management Tier:No People Management
Job Type

Job Description

At Cadence, we hire and develop leaders and innovators who want to make an impact on the world of technology. Job Title: Cloud Security Operations Engineer Location: San Jose, California Reports to: Senior Cloud Security Architect Job Overview: We are seeking a skilled and passionate Cloud Security Operations Engineer to join our dynamic Information Security team. In this role, you will be responsible for designing, implementing, and maintaining robust security controls across our public cloud environments, including AWS, Azure, GCP, and IBM Cloud. As a hands-on technical expert, you will play a crucial role in enhancing our cloud security posture, with a primary focus on data protection and incident management. This position offers the opportunity to work in a collaborative environment, where you will contribute to the security and resilience of our cloud infrastructure. Job Responsibilities: 1. Secure Architecture and Engineering - Design and deploy secure reference architectures across multi-cloud environments. - Integrate security into Infrastructure-as-Code (IaC) using tools like Terraform, CloudFormation, and ARM Templates. - Implement cloud-native security controls: VPCs, WAFs, DDoS, and endpoint protections. - Ensure data protection via encryption, KMS/HSM, and DLP policies. 2. Identity and Access Management (IAM) - Design, implement, and audit IAM policies, roles, service accounts, and federation models using least-privilege principles. - Configure MFA, SSO, and PAM solutions for secure cloud access. 3. Monitoring, Detection, and Response - Configure and maintain cloud-native security tools (e.g., AWS Security Hub, Microsoft Defender for Cloud, Google Security Command Center). - Integrate cloud logs with SIEM systems for threat detection. - Lead incident response efforts for cloud-related security events. - Continuously monitor cloud environments using CSPM, CNAPP, and cloud-native security tools to identify, prioritize, and remediate security misconfigurations and policy violations. - Track and manage cloud security findings through remediation workflows. - Partner with Cloud Platform, Infrastructure, and Application teams to coordinate remediation of identified security risks and vulnerabilities. - Conduct root cause analysis of recurring cloud security issues and recommend preventive controls and automation improvements. 4. Cloud Data Loss Prevention (DLP) Management - DLP Alert Triage and Investigation: Monitor, triage, and investigate all DLP alerts and events. Differentiate between policy violations, potential insider threats, and false positives, escalating confirmed incidents to the Incident Response team. - Tool Optimization and Tuning: Serve as the subject matter expert (SME) for Cloud DLP tools (e.g., Microsoft Purview, Google DLP, dedicated CASB solutions). Continuously tune policies and rulesets to minimize alert fatigue while maintaining high fidelity. - Reporting and Compliance: Generate regular reports on DLP effectiveness, policy violations, and risk trends for leadership and compliance/audit teams (e.g., SOC 2, HIPAA, GDPR). - Data Classification Integration: Collaborate with Governance, Risk, and Compliance (GRC) teams to ensure DLP policies align with the corporate data classification framework. 5. Automation and DevSecOps - Develop automation scripts (Python, PowerShell, Bash) and serverless functions (AWS Lambda, Azure Functions, Google Cloud Run). 6. Cloud Security Posture Management & Compliance - Continuously assess AWS, Azure, and GCP environments using CSPM platforms to identify misconfigurations, excessive permissions, exposed resources, compliance gaps, and other security risks. - Develop, maintain, and enforce cloud security baselines aligned with industry standards, regulatory requirements, and organizational security policies. - Perform periodic cloud security assessments and audits using CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and internal security standards. - Drive remediation of findings identified through CSPM monitoring, security assessments, audits, compliance reviews, and risk assessments. - Support internal and external audits by providing cloud security evidence, compliance reporting, and remediation status updates. 7. Secure Access and Network Security Controls - Enforce secure access patterns by eliminating unnecessary public exposure and implementing private endpoints, bastion hosts, AWS Systems Manager Session Manager, and least-privilege network segmentation. - Enforce private connectivity architectures by leveraging: AWS PrivateLink, Azure Private Endpoints, Google Private Service Connect. - Eliminate unnecessary public exposure of cloud workloads, services, and management interfaces. - Design and maintain least-privilege network segmentation and cloud-native firewall controls across multi-cloud environments. 8. Cloud Workload Security and Hardening - Establish and maintain secure cloud operating system baselines using CIS Benchmarks and vendor-recommended hardening standards. - Perform periodic reviews and validation of operating system, virtual machine, and container security configurations. - Collaborate with Infrastructure and Platform teams to implement hardened images and golden image standards. - Monitor and remediate deviations from approved OS hardening baselines. Job Qualifications: Technical Expertise - Deep knowledge of at least one cloud platform (AWS, Azure, or GCP). - Proficiency in scripting: Python (preferred), PowerShell, Unix shell scripting. - Strong understanding of networking and cloud-native network security. - Experience with CSPM/CNAPP platforms such as CloudGuard Dome9, Wiz, Prisma Cloud, Microsoft Defender for Cloud, or similar solutions. - Strong knowledge of CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and industry cloud security best practices. - Familiarity with securing OS and containerized environments (Docker, Kubernetes). - Experience implementing secure cloud network architectures, private endpoints, bastion access patterns, and zero-trust security principles. - Experience supporting cloud compliance, audit readiness, and regulatory assessments. Education & Certification - Bachelor’s degree in computer science, Information Security, or related field (or equivalent experience). - Preferred Certifications: AWS Certified Solutions Architect – Associate, AWS Certified Security – Specialty, Microsoft Certified: Azure Administrator Associate, Microsoft Certified: Azure Security Engineer Associate, Google Cloud: Associate Cloud Engineer, Google Cloud: Professional Cloud Security Engineer, (ISC)² Certified Cloud Security Professional (CCSP), (ISC)² Certified Information Systems Security Professional (CISSP). Soft Skills - Strong analytical and problem-solving abilities. - Excellent communication and collaboration skills, especially with DevOps and engineering teams.

Company Information

Cadence logo
Technology
Headcount: 1,000 - 10,000
Current open roles at Cadence on JobCrawls
LocationActive listings
Remote - Global130
Kato Scholari, Finland1
Current role mix at Cadence on JobCrawls
Role typeActive listings
Software Engineer16
Application Engineer14
Product Engineer10
Lead Design Engineer4
Design Engineer4
Systems Engineer4
Principal Design Engineer3
Distributed Systems Engineer3
Senior Principal Design Engineer3
Intern2
Program Manager2
Senior Principal Software Engineer2
Customer Engagement Engineer2
Formal Verification Engineer2
Application Engineering2
Design Engineering Architect2
Customer Design Engineer1
Legal Intern1
Signal and Power Integrity1
Business Systems Analyst1
Cloud Support Engineer1
CAE/FEA Senior AE1
ASIC Verification1
HR Intern1
Design Engineering Intern1
Product Engineering Architect1
Technical Recruiter1
Lead Software Engineer1
Lead Scientific Developer1
Business Development Director1
System Engineer1
HR Business Partner1
Product Validation Engineer1
Emulation Design Engineer1
Senior System Engineer1
Software Test Engineer1
Product Operations1
Storage Engineer1
Principal DFT Engineer1
HR M&A Leader1
AI Security Architect1
Scientific Software Developer1
Global Account Group Director1
Account Technical Executive1
System Engineering & Integration1
AI Engineer1
Verification Engineer1
IT Internship1
Customer Engagement Manager1
Intern AI-Driven Flow Validation1
Data Center Technical Executive1
Revenue Accounting Manager1
Software Engineering Intern1
Solutions Engineer1
Product Manager1
Layout Design Engineer1
Principal Software Engineer1
Product Engineer System Verification1
AI Forward Deployment Engineer1
Application Engineering Intern1
Product Validation1
Software Security Director1
Software Security Architect1
Digital Implementation Architect1
Order Administration1
Digital Implementation Engineer1
Sales Administrator1
Server Farm Engineer1
Software Intern1
Signal Integrity Engineer1
Infrastructure Architect1
Scientific Sales1
Current role-level mix at Cadence on JobCrawls
Role levelActive listings
Mid-Level129
Senior2

Cadence appears in 131 indexed job postings in JobCrawls' Finland dataset since April 2024. In that historical index, the strongest location signals for this employer are Remote - Global and Kato Scholari, Finland.

Data shown is based on historical job postings from our database.

Job Details

Responsibilities

  • Design and deploy secure reference architectures across multi-cloud environments
  • Integrate security into Infrastructure-as-Code (IaC) using Terraform, CloudFormation, and ARM Templates
  • Implement cloud-native security controls including VPCs, WAFs, DDoS, and endpoint protections
  • Design, implement, and audit IAM policies and federation models using least-privilege principles
  • Configure and maintain cloud-native security tools and integrate logs with SIEM systems
  • Lead incident response efforts for cloud-related security events
  • Monitor cloud environments using CSPM and CNAPP to remediate misconfigurations and policy violations
  • Manage Cloud Data Loss Prevention (DLP) alert triage, tool optimization, and compliance reporting
  • Develop automation scripts using Python, PowerShell, and Bash
  • Perform cloud security assessments and audits using CIS Benchmarks, CSA CCM, and NIST
  • Enforce secure access patterns and private connectivity architectures (e.g., AWS PrivateLink, Azure Private Endpoints)
  • Establish and maintain secure cloud OS baselines and harden container security configurations

Requirements

  • Deep knowledge of at least one cloud platform (AWS, Azure, or GCP)
  • Proficiency in scripting: Python (preferred), PowerShell, Unix shell scripting
  • Strong understanding of networking and cloud-native network security
  • Experience with CSPM/CNAPP platforms such as CloudGuard Dome9, Wiz, Prisma Cloud, Microsoft Defender for Cloud, or similar
  • Strong knowledge of CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and industry cloud security best practices
  • Familiarity with securing OS and containerized environments (Docker, Kubernetes)
  • Experience implementing secure cloud network architectures, private endpoints, bastion access patterns, and zero-trust security principles
  • Experience supporting cloud compliance, audit readiness, and regulatory assessments
  • Bachelor’s degree in computer science, Information Security, or related field (or equivalent experience)

Skills & Technologies

AWSAzureGCPIBM CloudTerraformCloudFormationARM TemplatesPythonPowerShellBashAWS Security HubMicrosoft Defender for CloudGoogle Security Command CenterSIEMCSPMCNAPPMicrosoft PurviewGoogle DLPCASBDockerKubernetesAWS PrivateLinkAzure Private EndpointsGoogle Private Service Connect

Education Level

Bachelor
18 hours agoContent Complete

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.