The Cloud Security Engineer will build and manage a comprehensive cloud security program, including inventory management, posture assessment, and workflow automation. They will also integrate cloud telemetry into the enterprise security stack and operate the program in a steady state.
This is a remote position.
About This Opportunity
CTI Staffing is partnering with a well-established, growth-focused organization in a regulated industry to find a Cloud Security Engineer for their IT Security engineering team. This is a fully remote contract role with right-to-hire potential.
This team is building a cloud security program from the ground up across a multi-cloud, SaaS-heavy environment. You'll own the program end to end, from inventory and posture assessment through workflow automation and steady-state operations, in a fast-moving, AI-forward security organization.
What You'll Do
- Build an authoritative inventory of cloud accounts and SaaS applications across AWS, Azure, GCP, and OCI, and integrate it into a ServiceNow CMDB
- Run cloud security posture assessments against CIS, CSA, and NIST CSF 2.0 baselines
- Document and risk-rank misconfigurations across IAM, network exposure, logging, and encryption, and map findings to owners
- Design and build a cloud account onboarding and monitoring workflow in ServiceNow
- Integrate cloud telemetry into the enterprise security stack and tune detections in the SIEM
- Author operational runbooks and operate the program in steady state with weekly status reporting
- Apply AI frontier models to accelerate inventory analysis, assessments, and documentation
Requirements
What You Bring
Must-Have:
- Hands-on multi-cloud security experience across AWS, Azure, and GCP (OCI a plus)
- Strong grasp of CSPM concepts and tooling; able to assess IAM, network exposure, logging/telemetry, and encryption/key management
- ServiceNow build experience: workflow development and CMDB integration (this is the core deliverable)
- SIEM and log-pipeline integration experience, including cloud log forwarding
- Proficiency applying AI frontier models (ChatGPT Enterprise, Claude) to security engineering work, with an understanding of governed enterprise AI use
- Strong documentation skills and the discipline to run steady-state operations
- US Citizenship required (right-to-hire engagement; no sponsorship available)
Nice-to-Have:
- CrowdStrike (Falcon Cloud Security / NG-SIEM), SSPM, DSPM, Zscaler, Cribl, or Okta experience
- Insurance, financial services, or other regulated-industry background (GLBA, NY DFS 500)
- Infrastructure-as-code familiarity (Terraform)
- Cloud/security certifications (AWS/Azure/GCP security specialties, CCSP, CISSP, GIAC)
Technical Environment:
- AWS, Azure, GCP, OCI
- ServiceNow (CMDB, SecOps, workflow development)
- CrowdStrike, SSPM, DSPM, Zscaler, Cribl, Okta
- Enterprise AI platforms (ChatGPT Enterprise, Claude)
What Success Looks Like:
- Complete, authoritative cloud and SaaS inventory live in the CMDB within the first month
- Risk-ranked posture findings mapped to owners with a working ServiceNow dashboard
- Cloud onboarding workflow operational and telemetry flowing into the SIEM by end of engagement