Staff Security Engineer, Cloud

ALSO
Palo Alto
Workplace: OnsiteFull timeUSD 205,000 - 240,000 annuallyFunction: CybersecurityExperience: 10+ yearsSkills: ["Ownership","Autonomy"]

Own cloud security end to end for a connected, software-defined EV platform built on AWS, Kubernetes, and microservices. Set security architecture and implement controls yourself in Go—covering identity/IAM, container hardening, supply-chain security, detection/response, and the vehicle-to-cloud trust boundary. Serve as the company’s go-to security expert while partnering with backend teams to run penetration tests, manage vulnerabilities, and ship security-as-code guardrails.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
ALSO
ALSO
18 hours ago

Staff Security Engineer, Cloud

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 18 hours agoStatus: Live

Job Summary

Own cloud security end to end for a connected, software-defined EV platform built on AWS, Kubernetes, and microservices. Set security architecture and implement controls yourself in Go—covering identity/IAM, container hardening, supply-chain security, detection/response, and the vehicle-to-cloud trust boundary. Serve as the company’s go-to security expert while partnering with backend teams to run penetration tests, manage vulnerabilities, and ship security-as-code guardrails.
Location: Palo Alto
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own cloud security end to end across AWS, Kubernetes, and the microservices platform, including threat modeling in architecture reviews before code exists.
  • •Design and implement identity and access at scale (workload identity, org-wide IAM, least privilege, secrets management, certificate/key lifecycle) including mutual TLS between services and with vehicles.
  • •Harden containers and orchestration using image provenance, admission control, runtime/network policy, service mesh configuration, and microservice isolation.
  • •Secure the software supply chain with SBOM generation, dependency/image scanning, signed artifacts, and CI/CD pipelines that fail closed on critical issues.
  • •Run detection and response for security logging/telemetry, meaningful alerting, runbooks, on-call incident handling, and blameless postmortems that drive real fixes.

Pay and Benefits

Salary: USD 205,000 - 240,000 annually
Perks:Health InsuranceDentalVisionFsaHsa401k MatchFlexible Time

Key Requirements

  • •10+ years in backend and infrastructure engineering, with a substantial portion owning security in production.
  • •Expert, hands-on AWS security experience including IAM, VPC/network design, KMS, Secrets Manager, GuardDuty, Security Hub, CloudTrail, Config, and org-level guardrails (SCPs).
  • •Deep Kubernetes and container security experience, including RBAC, admission controllers, pod security standards, network policy, and runtime detection with real cluster operations.
  • •Fast, fluent Go experience designing, reviewing, and shipping production code.
  • •Applied identity protocols and cryptography (OAuth2, OIDC, JWT, SAML, mutual TLS, PKI) plus threat modeling and secure architecture reviews as routine practice.
Experience:10+ yearsCloudKubernetesMicroservices
Skills:OwnershipAutonomy
Tech Stack:GoAWSKubernetesMicroservicesTelemetry streamingRemote diagnosticsAWS IAMVPCNetwork designKMSSecrets ManagerGuardDutySecurity HubCloudTrailAWS ConfigSCPsEKSECSECRLambda

Company Brief

ALSO
ALSO is an electric micromobility company spun out of Rivian that designs small, vertically integrated EVs (e-bikes and multi‑form-factor small vehicles) for consumers and commercial partners, focusing on efficiency, affordability, and integrated connectivity.
Industry: Electric Vehicles
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Headquarters: Palo Alto, United States
Founded: 2025
WebsiteLinkedIn