Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cloud Security Engineer image - Rise Careers
Job details

Cloud Security Engineer

Who You Are:


You are a cloud security specialist with a strong background in AWS environments. You have a deep understanding of AWS security services, cloud architecture, and best practices to protect sensitive data and mitigate risks. You enjoy collaborating with cross-functional teams to ensure security is embedded throughout the cloud lifecycle from design to deployment and monitoring. You are proactive, detail-oriented, and passionate about staying ahead of emerging security threats.


Does this sound like you? If so, keep reading and apply today!


What You'll Do:
  • Design and implement security controls and configurations for AWS services, including EC2, S3, VPC, IAM, EKS, Lambda, RDS, and more.
  • Conduct risk assessments, vulnerability scans, and penetration testing on AWS infrastructure to identify and remediate security gaps.
  • Develop and enforce IAM policies, roles, and permissions to ensure least-privilege access across AWS environments.
  • Configure and manage AWS security tools such as AWS Security Hub, GuardDuty, CloudTrail, AWS Config, and Inspector to monitor and respond to threats.
  • Implement encryption mechanisms for data at rest and in transit using AWS KMS (Key Management Service) and other cryptographic tools.
  • Collaborate with DevOps teams to integrate security into CI/CD pipelines using tools like AWS CodePipeline and third-party solutions.
  • Respond to security incidents, perform root cause analysis, and recommend corrective actions to prevent recurrence.
  • Ensure compliance with industry standards and regulations (e.g., SOC 2, ISO27001) within AWS environments.
  • Stay up-to-date with emerging cloud security threats, AWS updates, and best practices to proactively enhance security posture.
  • Document security processes, architectures, and incident reports for internal and audit purposes.


What You Have:
  • 3+ years of experience in cloud security, with at least 2 years focused on AWS environments.
  • Strong knowledge of AWS security services (e.g., IAM, GuardDuty, CloudTrail, KMS, WAF) and their practical application.
  • Experience with infrastructure-as-code (IaC) tools like Terraform or AWS CloudFormation for secure deployments.
  • Familiarity with scripting languages (e.g., Python, Bash) for automation of security tasks.
  • Understanding of networking concepts (e.g., VPC, subnets, security groups, NACLs) and their security implications in AWS.
  • Proven ability to conduct threat modeling, vulnerability management, and incident response in cloud environments.
  • Excellent problem-solving skills and attention to detail.
  • Strong communication skills to collaborate with technical and non-technical stakeholders.


Extras you bring:
  • Experience with container security (e.g., Docker, Kubernetes) in AWS ECS or EKS.
  • Familiarity with compliance frameworks and audit processes.


Why Join Polly?
  • We are attacking a trillion-dollar market with gross inefficiencies and seeking to transform the way an entire industry operates 
  • You will have an impact on the design, architecture and implementation of markets that are often called the engine of US economy
  • We value drive for excellence, independent thinking, teamwork and curiosity
  • You will work with both government backed and industry leading companies to create a digital pipeline that facilitates real time trading of loans
  • We have an experienced leadership team that previously built large and impactful platforms 
  • Outstanding opportunity for professional growth and upward mobility 
  • Direct engagement with the decision makers and senior business leaders 
  • Competitive salaries
  • 100% paid medical/vision/dental/disability/life insurance 
  • Unlimited PTO
  • Hybrid environment; 3x weekly in an innovation hub in San Francisco or Dallas


Let's get to know each other.


Polly has pioneered the next generation of mortgage capital markets technology with its cutting-edge, data-driven platform. Its enterprise-grade solutions, including the industry's only cloud-native, commercially scalable product, pricing, and eligibility (PPE) engine and first-of-its-kind Polly/™ AI platform, empower the nation's top banks, credit unions, and mortgage lenders to increase profitability, automate workflows, and revolutionize the loan officer and broker experiences. As a mortgage technology trailblazer, Polly is committed to driving meaningful value and ROI through best-in-class innovation that enables unlimited configurability, flexibility, granularity, and scalability. Polly was founded by a seasoned team of mortgage capital markets and technology experts and is headquartered in San Francisco, California. Recognized as a pioneer in mortgage capital markets, as well as in culture and career development, Polly was named to Forbes' America's Best Startup Employers in 2025. This evaluation was based on three key criteria: Employer Reputation, Employee Satisfaction, and Company Growth.


To learn more, follow Polly on LinkedIn or visit www.polly.io. Polly is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, age, color, national origin, religion, sex, gender identity, sexual orientation, marital status, pregnancy status, disability status, veteran status, or any other legally protected status. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.


Beware of recruitment scams impersonating the Polly brand or our employees. Our team communicates only through official Polly channels, and we will never ask for sensitive information over text or conduct text-only interviews. If you are ever suspicious or in doubt, reach out to us directly at peopleteam@polly.io. We care deeply about this network and your experience. 

Polly Glassdoor Company Review
4.8 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Polly DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Polly
Polly CEO photo
Unknown name
Approve of CEO

Average salary estimate

$110000 / YEARLY (est.)
min
max
$90000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cloud Security Engineer, Polly

If you're a Cloud Security Engineer looking for your next big opportunity, consider joining Polly! As a leading player in the mortgage capital markets technology arena, we’re seeking someone with a robust background in AWS environments and a passion for securing cloud architectures. Your day-to-day tasks will revolve around designing and implementing security controls for our AWS services, conducting risk assessments, developing IAM policies, and leveraging AWS security tools like Security Hub and GuardDuty to safeguard our infrastructure. You’ll also collaborate with our DevOps teams to enhance CI/CD pipelines, ensuring security best practices are baked in from day one. We’re all about proactive approaches, so we need you to stay ahead of emerging threats while documenting security processes for continuous improvement. At Polly, you won’t just be maintaining the status quo; you’ll be involved in shaping the future of how we operate within the ever-evolving financial services landscape. If you have over 3 years of experience in cloud security, with at least 2 years directly working with AWS, you could be the perfect fit to help us tackle significant market inefficiencies. We value your skills in scripting languages and embrace your experience with container security. Plus, you'll uncover new opportunities for professional growth while working alongside industry leaders in a hybrid environment. Join us in reshaping technology and making a lasting impact!

Frequently Asked Questions (FAQs) for Cloud Security Engineer Role at Polly
What are the key responsibilities of a Cloud Security Engineer at Polly?

As a Cloud Security Engineer at Polly, you'll be tasked with designing and implementing security controls for a variety of AWS services. This includes conducting risk assessments and vulnerability scans to identify security gaps, developing IAM policies to ensure least-privilege access, and integrating security into CI/CD pipelines. Additionally, you'll monitor AWS tools for threats and respond to security incidents.

Join Rise to see the full answer
What qualifications do you need for the Cloud Security Engineer role at Polly?

To qualify for the Cloud Security Engineer position at Polly, candidates should have over 3 years of experience in the cloud security domain, with a minimum of 2 years specifically focused on AWS environments. A strong understanding of AWS security services, infrastructure-as-code tools, and familiarity with networking concepts is essential.

Join Rise to see the full answer
What tools will I work with as a Cloud Security Engineer at Polly?

In your role as a Cloud Security Engineer at Polly, you’ll work with AWS security tools such as AWS Security Hub, CloudTrail, GuardDuty, and KMS. You will also use infrastructure-as-code tools like Terraform or AWS CloudFormation for secure deployments, along with scripting languages for automation of security tasks.

Join Rise to see the full answer
What opportunities for growth are available for a Cloud Security Engineer at Polly?

Polly is committed to professional growth, offering outstanding opportunities for upward mobility. As a Cloud Security Engineer, you'll engage directly with decision-makers and have the chance to influence the design and architecture of crucial processes, ensuring your contributions make a significant impact on the organization.

Join Rise to see the full answer
Can you describe the work environment for a Cloud Security Engineer at Polly?

At Polly, the work environment is hybrid, allowing flexibility in where you work. You'll engage with talented colleagues in an innovation hub located in either San Francisco or Dallas, while also enjoying the option to work remotely. This blend fosters collaboration, creativity, and contribution to a cutting-edge company.

Join Rise to see the full answer
Common Interview Questions for Cloud Security Engineer
What are the most critical AWS security services?

In your response, emphasize the importance of services like IAM, GuardDuty, CloudTrail, and KMS. Each of these services plays a critical role in ensuring security within AWS environments, and it would be beneficial to discuss their practical applications in your previous experience.

Join Rise to see the full answer
Can you explain how you manage IAM policies?

Highlight your experience with developing IAM roles and policies, focusing on the principle of least privilege. Discuss specific scenarios where you implemented IAM roles and the impact on secure access within AWS environments.

Join Rise to see the full answer
Describe your experience with vulnerability management.

Provide details of past engagements where you conducted vulnerability scans and penetration tests. Discuss the tools used, your methodology in identifying security gaps, and how you remediated any findings.

Join Rise to see the full answer
How do you prioritize security tasks?

Outline your approach to prioritizing security tasks based on risk assessment findings. Consider discussing how you balance ongoing monitoring with incident response activities while collaborating with other team members.

Join Rise to see the full answer
What is your approach to handling security incidents?

Explain your systematic approach to responding to security incidents, including detection, containment, eradication, and recovery phases. Providing a real-life example can illustrate your method effectively.

Join Rise to see the full answer
What tools do you use for automation in security?

Reflect on your familiarity with automation and scripting languages. Discuss how tools like Terraform or AWS Lambda combined with scripting languages enhance efficiency in security deployment.

Join Rise to see the full answer
Discuss your experience with container security.

Talk about any experience you have with container technologies such as Docker and Kubernetes. Discuss how you have implemented security measures in AWS EKS or ECS to protect containerized applications.

Join Rise to see the full answer
How do you keep up with emerging security threats?

Share your strategies for staying informed, such as following industry journals, attending webinars, joining security forums, or participating in relevant training. Highlight specific resources that aid in your continuous professional development.

Join Rise to see the full answer
Can you provide an example of a successful security project you've managed?

Choose a project that showcases your leadership and technical skills. Discuss the project's objectives, your role, the challenges faced, and the successful outcomes achieved.

Join Rise to see the full answer
What compliance frameworks are you familiar with?

Mention specific compliance frameworks like SOC 2 or ISO27001 that you've worked with in the past. Discuss how you've maintained compliance in AWS environments and any audits you have participated in.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Polly Remote No location specified
Posted yesterday

Be part of Polly's growth story as a Sales Development Representative, engaging with top executives and helping transform the mortgage industry.

Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
The Y (YMCA) Hybrid Denver, Colorado, United States
Posted 11 days ago

Join CommonSpirit Health as a Senior Revenue Cycle IT Support Analyst and drive performance and compliance in healthcare revenue cycle operations.

Photo of the Rise User
Posted 9 days ago
Talent Worx Remote No location specified
Posted 5 days ago

Join Talent Worx as a Cloud Specialist to leverage cloud technologies and optimize client operations.

Photo of the Rise User
Datacom Remote No location specified
Posted 7 days ago

Datacom is looking for a Senior Practice Lead – AIOps to manage a team of engineers and drive excellence in systems and applications management.

Photo of the Rise User
Posted 11 days ago

Hastings Direct is looking for a Technology Risk Executive to enhance their Information Security team and drive compliance in a fast-paced environment.

Polly's mission is to help capital markets and secondary teams operate smarter, more efficiently, and more profitably with best-in-class, end-to-end technology configured for each of our customers’ unique workflows and business needs.

98 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Diversity ChampionBadge Future MakerBadge Rapid Growth
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 3, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!