Back to Search
Overview
Senior

Senior Cloud Security Engineer

Confirmed live in the last 24 hours

ExtraHop

ExtraHop

Compensation

$150,000 - $180,000/year

Remote
Hybrid
Posted March 18, 2026

Job Description

At ExtraHop, we’re on a mission to protect and empower the connected enterprise. We reveal what is happening in the very infrastructure that sustains businesses, lives, and communities, and ensure the integrity of networks, data, systems, and processes. Organizations rely on ExtraHop to provide visibility into the cyber threats, vulnerabilities, and network performance issues that evade their existing security and IT tools. With this insight, organizations can investigate smarter, stop threats faster, and keep operations running.

Our mission is fueled by a profound social and moral responsibility to be the best at what we do, ensuring a secure world where everyone can thrive. If this sounds like a place you’d like to spend the next chapter of your career, we’d love to hear from you. 

Position Summary

Do you like securing complex cloud services and infrastructure? Want to be a part of a collaborative team that builds solutions that protect some of the biggest networks in the world? ExtraHop is seeking a Sr. Product Security Engineer, experienced with modern cloud system development and infrastructure-as-code practices to build and operate product security program capabilities, tools, and processes that allow us to keep pace with a rapidly changing security landscape, reduce security risk and enable organizational success.

We're looking for candidates with a mix of cloud security, infrastructure security, security information and event management (SIEM) technologies, DevOps, and software development experience, who enjoy working in a collaborative environment and taking direct action to identify, remediate and prevent vulnerabilities and security issues.

You must have experience securing cloud environments and modern computing infrastructure, deploying and operating SIEM tools, and strong familiarity with Infrastructure-as-Code and container technologies.

Key Responsibilities

  • Implement and operate Splunk Cloud Platform and Enterprise Security, including setting up log ingestion from required source systems and ensuring correct parsing and categorization of log events for effective SIEM operations
  • Implement and operate endpoint detection and response (EDR) and network detection & response (NDR) solutions
  • Develop system configuration and hardening standards and coordinate with other teams to ensure compliance with those standards
  • Define standards for secure configuration of application and infrastructure components
  • Perform threat modeling, security design reviews, code reviews, and consultations with other staff
  • Build and improve vulnerability management processes and tooling to support system owners to successfully remediate issues
  • Perform, automate and streamline patching and vulnerability remediation activities
  • Develop and deliver training on cloud security issues, best practices and internal policies
  • Select, implement and manage cloud security tools including cloud security posture management (CSPM), network/host/container/IaC vulnerability scanners and configuration auditing
  • Participate in manual pen testing of new + existing systems
  • Perform and/or lead security investigation and incident response activities
  • Participate in an on-call rotation with occasional after-hours paging to review carefully prioritized security detections

 

Required Qualifications

  • Bachelor’s degree or equivalent experience in computer science, engineering, or information technology
  • 8+ years of experience in security engineering, software development and/or DevOps, with a focus on securing complex systems and modern cloud infrastructure
  • Strong experience securing AWS cloud platform and services, including the implementation of guardrails using service control policies (SCPs), IaC policies, CSPM, or similar strategies
  • Experience implementing Splunk Enterprise Security to monitor cloud-based systems
  • Experience working with container-based environments (Kubernetes, Docker, LXC, etc.)
  • Experience securing cloud-based web applications, APIs, data and infrastructure
  • All R&D Employees will be required to attend 2 mandatory in-person events every year. These events are typically held in our offices in downtown Seattle and run 4-5 days each
  • Must be a U.S. citizen or
pythongoawsgcpazurekubernetesdockermachine learningaidevops