远程工作雷达

高级云安全工程师

Senior Cloud Security Engineer

开发工程限定地区(需当地身份)
公司Greystar
薪资$140,000 - $170,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

关于GREYSTAR

GREYSTAR 是一家领先的、完全整合的全球房地产平台,提供在机构级租赁住房领域的物业管理、投资管理、开发和建筑服务的专业知识。总部位于南卡罗来纳州查尔斯顿,GREYSTAR 在全球 260 多个市场管理并运营超过 3500 亿美元的房地产,业务遍及北美、欧洲、南美洲和亚太地区。GREYSTAR 是美国最大的公寓运营商,全球管理超过一百万套/床位。在其平台上,GREYSTAR 管理的资产接近 790 亿美元,包括超过 340 亿美元的开发资产和超过 365 亿美元的监管资产。GREYSTAR 由 Bob Faith 于 1993 年创立,旨在成为租赁住宅房地产行业世界级服务的提供商。如需了解更多信息,请访问。

职位描述摘要

高级云安全工程师是 GREYSTAR 在云安全方面的实战专家,战略方向由信息科技高级总监制定——其他工程师、架构师和领导者在需要对云安全做出专业且有依据的决策时会向你寻求帮助。这不是一个事后审查安全的角色:你将定义 GREYSTAR 云环境中的“安全”含义,设定其他工程师遵循的标准,并直接在架构设计评审中代表云安全。

这是一个构建者角色——你将编写 Terraform、配置扫描器并亲自修复问题,为所触及的每个云领域带来深入的技术执行力。你将与信息安全团队紧密合作,制定企业架构和身份标准,并与网络安全运营团队合作进行检测调优和事件响应——为这些合作带来深厚的云原生专业知识。你还将直接与 GREYSTAR 的云平台团队工程师、数字和 AI 开发人员以及数据工程团队合作,确保安全被构建到每个设计中,而不是事后添加。

职位描述
你将负责:
云安全架构与标准

  • 在各个云平台上定义并负责云安全架构模式——IAM 保障措施、网络分割、加密标准和密钥管理——基础设施、交付和可靠性团队将据此进行构建。
  • 负责以代码形式编写的云策略,使用 Python、React、Kubernetes、Stripe 等工具。
查看英文原文

ABOUT GREYSTAR

Greystar is a leading, fully integrated global real estate platform offering expertise in property management, investment management, development, and construction services in institutional-quality rental housing. Headquartered in Charleston, South Carolina, Greystar manages and operates over $350 billion of real estate in more than 260 markets globally with offices throughout North America, Europe, South America, and the Asia-Pacific region. Greystar is the largest operator of apartments in the United States, managing over one million units/beds globally. Across its platforms, Greystar has nearly $79 billion of assets under management, including over $34 billion of development assets and over $36.5 billion of regulatory assets under management. Greystar was founded by Bob Faith in 1993 to become a provider of world-class service in the rental residential real estate business. To learn more, visit .
JOB DESCRIPTION SUMMARY
The Senior Cloud Security Engineer is Greystar's hands-on subject matter expert on cloud security with strategic direction driven from the Senior Director, Information Technology - the person other engineers, architects, and leaders turn to when a design decision needs an expert, defensible answer on cloud security. This is not a role that reviews security after the fact: you will define what "secure" means for Greystar's cloud environments, set the standards other engineers build against, and represent cloud security directly in architecture design reviews.

This is a builder's role - you'll be writing Terraform, configuring scanners, and fixing findings yourself, bringing deep technical execution to every part of the cloud estate you touch. You will partner closely with Information Security on enterprise architecture and identity standards, and with Cybersecurity Operations on detection tuning and incident response - bringing deep cloud-native expertise to those partnerships. You will also work directly with Greystar’s cloud Platform team engineers, Digital and AI developers, and Data Engineering team to make sure security is built into every design rather than bolted on afterward.JOB DESCRIPTION
What You Will Do:
Cloud Security Architecture & Standards

  • Define and own cloud security architecture patterns across cloud platforms - IAM guardrails, network segmentation, encryption standards, and secrets management - that the Infrastructure, Delivery, and Reliability tracks build against.
  • Own cloud Policy as code, including custom policy definitions, initiative assignments, and enforcement-mode governance across the cloud estate.
  • Establish secure-by-default reference patterns - landing zone security baseline, mandatory private endpoint use, default-deny network posture - in direct partnership with the Principal Cloud Engineer.
  • Partner with Information Security architecture so enterprise security policy translates correctly into cloud-native controls, acting as the translator of record between enterprise policy and cloud implementation.

Application, Pipeline & Supply-Chain Security

  • Build and configure security tooling directly into CI/CD pipelines - standing up IaC scanning, container image scanning, and SAST/DAST tools hands-on alongside the Delivery team.
  • Own supply-chain risk review for third-party CI/CD integrations (GitHub Actions, MCP servers, external connectors), partnering with the Senior DevOps Engineer on remediation.
  • Work hands-on with application development and AI/ML teams to harden new cloud-native and AI workloads before they ship - configuring network isolation, securing model endpoints and API keys, and directly fixing findings during the build.
  • Personally triage and remediate critical pipeline findings, working directly in the codebase or configuration with engineering teams to fix root causes.

Identity & Access Security (Cloud-Specific)

  • Define least-privilege RBAC and conditional access standards for cloud resources, partnering with Cloud Engineering on execution against established naming and group-based delegation conventions.
  • Own the just-in-time / privileged identity model for privileged cloud roles.
  • Own recurring access reviews and offboarding validation for service principals, managed identities, and human RBAC assignments across the cloud estate.

Detection, Response & Operations

  • Partner with Cybersecurity Operations to tune Defender for Cloud recommendations and Sentinel analytics rules for cloud-specific signal, reducing noise and closing detection gaps as new services and connectors come online.
  • Recommend and help prioritize which cloud workloads and connectors get phased into Sentinel next, based on risk and blast radius across the estate.
  • Contribute cloud-specific escalation criteria to the runbooks the Operations Command Center and Cybersecurity Operations execute against.
  • Deliver initial and ongoing training to Cybersecurity Operations on cloud-native anomalies - managed identity misuse, unusual resource provisioning, anomalous Entra ID sign-ins - so detection and tuning quality improve over time.

Governance, Risk & Compliance

  • Actively work down the CSPM and vulnerability backlog - rewriting Terraform to close a misconfiguration, migrating a plaintext secret to Key Vault, reconfiguring an identity - personally closing critical and high findings.
  • Map cloud infrastructure controls to relevant compliance frameworks (SOC 2, PCI, CIS Benchmarks) in partnership with enterprise Information Security, translating framework language into actual Azure/AWS configuration.

Architecture Review & Technical Authority

  • Serve as the primary cloud security voice in cloud architecture design reviews across Infrastructure, Application Development, and Data Engineering, providing the security assessment that informs whether a design moves forward.
  • Maintain security documentation, reference architectures, and runbooks specific to the cloud estate.

Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
  • 8+ years of experience in cloud security, security architecture, or cloud infrastructure engineering with a security focus, including demonstrated experience operating at a senior or principal level.
  • Deep, hands-on, expert-level experience securing Azure environments specifically - Azure Policy, Defender for Cloud, Sentinel, network security groups, and private endpoints - sufficient to set enterprise standards.
  • Solid working knowledge of AWS security services (IAM, Security Hub, GuardDuty, Config) sufficient to extend the same rigor as the estate expands beyond Azure.
  • Experience embedding security into Infrastructure as Code - reviewing and hardening Terraform, ARM, or Bicep - not only auditing after deployment.
  • Experience defining and enforcing CI/CD pipeline security gates: SAST/DAST, container image scanning, dependency scanning, and secrets detection.
  • Expert-level understanding of cloud identity security - Entra ID, RBAC and least-privilege design, just-in-time access, and workload identity federation - deep enough to author an identity architecture.
  • Experience identifying and triaging cloud-specific security signals - anomalous sign-ins, managed identity misuse, unusual resource provisioning - sufficient to train and hand off to an incident response team.
  • Proficiency in scripting and automation (PowerShell, Python, or Bash) for security tooling and remediation at scale.
  • Excellent executive communication skills, with the demonstrated ability to defend a security position persuasively to senior technical leadership and to explain risk and remediation priority to both engineers and non-technical stakeholders.

Preferred Qualifications:

  • Experience securing Databricks or data platform environments specifically, including Unity Catalog permissions models and data plane network isolation.
  • Experience with container and Kubernetes security (AKS), including image provenance and runtime security.
  • Familiarity with securing AI/ML and LLM-adjacent infrastructure - model serving endpoints, API key and secret exposure patterns, and agentic tool or third-party integration risk.
  • Direct experience mapping cloud controls to compliance frameworks (SOC 2, PCI DSS, CIS Benchmarks) in a real audit context.
  • Cloud security certifications (e.g., Microsoft Certified: Cybersecurity Architect Expert, AWS Certified Security - Specialty, CCSP) are a plus but not required.

The salary range for this position is $140,000 - $170,000 USD Annually.

Additional Compensation:

Many factors go into determining employee pay within the posted range including business requirements, prior experience, current skills and geographical location.

  • Corporate Positions: In addition to the base salary, this role may be eligible to participate in a quarterly or annual bonus program based on individual and company performance.
  • Onsite Property Positions: In addition to the base salary, this role may be eligible to participate in weekly, monthly, and/or quarterly bonus programs.

Robust Benefits Offered*:

  • Competitive Medical, Dental, Vision, and Disability & Life insurance benefits. Low (free basic) employee Medical costs for employee-only coverage; costs discounted after 3 and 5 years of service.
  • Generous Paid Time off. All new hires start with 15 days of vacation, 4 personal days, 10 sick days, and 11 paid holidays. Plus your birthday off after 1 year of service! Additional vacation accrued with tenure.
  • For onsite team members, onsite housing discount at Greystar-managed communities are available subject to discount and unit availability.
  • 6-Week Paid Sabbatical after 10 years of service (and every 5 years thereafter).
  • 401(k) with Company Match up to 6% of pay after 6 months of service.
  • Paid Parental Leave and lifetime Fertility Benefit reimbursement up to $10,000 (includes adoption or surrogacy).
  • Employee Assistance Program.
  • Critical Illness, Accident, Hospital Indemnity, Pet Insurance and Legal Plans.
  • Charitable giving program and benefits.

*Benefits offered for full-time employees. For Union and Prevailing Wage roles, compensation and benefits may vary from the listed information above due to Collective Bargaining Agreements and/or local governing authority.

Greystar will consider for employment qualified applicants with arrest and conviction records.

Greystar is an equal opportunity employer and does not discriminate in employment on the basis of race, color, religion, sex (including pregnancy, sexual orientation, and gender identity), national origin, age, disability, genetic information, military or veteran status, or any other characteristic protected by applicable law.

This position may be performed remotely anywhere within the United States except the state of Alaska.

Important Notice: Greystar will never request your banking details or other sensitive personal information during the interview process. Greystar does not conduct any interviews via text or messaging, and all communication will come from official Greystar email addresses (@greystar.com). If you receive suspicious requests, please report them immediately to .

ANTICIPATED CLOSING DATE
November 30, 2026This date may be subject to change due to evolving business needs.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级总监,资本项目

GreystarUnited States$105,000 - $135,000/年Full Time今天
开发工程限定地区(需当地身份)

项目经理

GreystarUnited States$78,000 - $98,000/年Full Time昨天
职能支持限定地区(需当地身份)

区域员工关系总监

GreystarUnited States$160,000 - $180,000/年Full Time昨天
职能支持限定地区(需当地身份)

← 返回全部职位