Opens cadence.wd1.myworkdayjobs.com in a new tab
What You'll Do
- Secure Architecture and Engineering Design and deploy secure reference architectures across multi-cloud environments.
- Integrate security into Infrastructure-as-Code (IaC) using tools like Terraform, CloudFormation, and ARM Templates.
- Implement cloud-native security controls: VPCs, WAFs, DDoS, and endpoint protections.
- Ensure data protection via encryption, KMS/HSM, and DLP policies. 2.
- Identity and Access Management (IAM) Design, implement, and audit IAM policies, roles, service accounts, and federation models using least-privilege principles.
- Configure MFA, SSO, and PAM solutions for secure cloud access. 3.
- Monitoring, Detection, and Response Configure and maintain cloud-native security tools (e.g., AWS Security Hub, Microsoft Defender for Cloud, Google Security Command Center).
- Integrate cloud logs with SIEM systems for threat detection.
- Lead incident response efforts for cloud-related security events.
- Continuously monitor cloud environments using CSPM, CNAPP, and cloud-native security tools to identify, prioritize, and remediate security misconfigurations and policy violations.
- Track and manage cloud security findings through remediation workflows.
- Partner with Cloud Platform, Infrastructure, and Application teams to coordinate remediation of identified security risks and vulnerabilities.
- Conduct root cause analysis of recurring cloud security issues and recommend preventive controls and automation improvements. 4.
- Cloud Data Loss Prevention (DLP) Management DLP Alert Triage and Investigation: Monitor, triage, and investigate all DLP alerts and events.
- Differentiate between policy violations, potential insider threats, and false positives, escalating confirmed incidents to the Incident Response team.
- Tool Optimization and Tuning: Serve as the subject matter expert (SME) for Cloud DLP tools (e.g., Microsoft Purview, Google DLP, dedicated CASB solutions).
- Continuously tune policies and rulesets to minimize alert fatigue while maintaining high fidelity.
- Reporting and Compliance: Generate regular reports on DLP effectiveness, policy violations, and risk trends for leadership and compliance/audit teams (e.g., SOC 2, HIPAA, GDPR).
- Data Classification Integration: Collaborate with Governance, Risk, and Compliance (GRC) teams to ensure DLP policies align with the corporate data classification framework. 5.
- Automation and DevSecOps Develop automation scripts (Python, PowerShell, Bash) and serverless functions (AWS Lambda, Azure Functions, Google Cloud Run). 6.
- Cloud Security Posture Management & Compliance Continuously assess AWS, Azure, and GCP environments using CSPM platforms to identify misconfigurations, excessive permissions, exposed resources, compliance gaps, and other security risks.
- Develop, maintain, and enforce cloud security baselines aligned with industry standards, regulatory requirements, and organizational security policies.
- Perform periodic cloud security assessments and audits using CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and internal security standards.
- Drive remediation of findings identified through CSPM monitoring, security assessments, audits, compliance reviews, and risk assessments.
- Support internal and external audits by providing cloud security evidence, compliance reporting, and remediation status updates. 7.
- Secure Access and Network Security Controls Enforce secure access patterns by eliminating unnecessary public exposure and implementing private endpoints, bastion hosts, AWS Systems Manager Session Manager, and least-privilege network segmentation.
- Enforce private connectivity architectures by leveraging: AWS PrivateLink Azure Private Endpoints Google Private Service Connect Eliminate unnecessary public exposure of cloud workloads, services, and management interfaces.
- Design and maintain least-privilege network segmentation and cloud-native firewall controls across multi-cloud environments. 8.
- Cloud Workload Security and Hardening Establish and maintain secure cloud operating system baselines using CIS Benchmarks and vendor-recommended hardening standards.
- Perform periodic reviews and validation of operating system, virtual machine, and container security configurations.
- Collaborate with Infrastructure and Platform teams to implement hardened images and golden image standards.
- Monitor and remediate deviations from approved OS hardening baselines.
- Job Qualifications: Technical Expertise Deep knowledge of at least one cloud platform (AWS, Azure, or GCP).
- Proficiency in scripting: Python (preferred), PowerShell, Unix shell scripting.
- Strong understanding of networking and cloud-native network security.
- Experience with CSPM/CNAPP platforms such as CloudGuard Dome9, Wiz, Prisma Cloud, Microsoft Defender for Cloud, or similar solutions.
- Strong knowledge of CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and industry cloud security best practices.
- Familiarity with securing OS and containerized environments (Docker, Kubernetes).
- Experience implementing secure cloud network architectures, private endpoints, bastion access patterns, and zero-trust security principles.
- Experience supporting cloud compliance, audit readiness, and regulatory assessments.
- Education & Certification Bachelor’s degree in computer science, Information Security, or related field (or equivalent experience).
- Preferred Certifications: AWS Certified Solutions Architect – Associate AWS Certified Security – Specialty Microsoft Certified: Azure Administrator Associate Microsoft Certified: Azure Security Engineer Associate Google Cloud: Associate Cloud Engineer Google Cloud: Professional Cloud Security Engineer (ISC)² Certified Cloud Security Professional (CCSP) (ISC)² Certified Information Systems Security Professional (CISSP) Soft Skills Strong analytical and problem-solving abilities.
- Excellent communication and collaboration skills, especially with DevOps and engineering teams.
- Cadence is committed to equal employment opportunity and employment equity throughout all levels of the organization.
- We strive to attract a qualified and diverse candidate pool and encourage diversity and inclusion in the workplace.
- Travel: N/A The hourly range for California is $57.21 to $106.25 per hour.
- You may also be eligible to receive incentive compensation: bonus, equity, and benefits.
- Please note that the hourly range is a guideline and compensation may vary based on factors such as qualifications, skill level, competencies and work location.
- Our benefits programs include: paid vacation and paid holidays, 401(k) plan with employer match, employee stock purchase plan, a variety of medical, dental and vision plan options, and more.
- We’re doing work that matters.
- Help us solve what others can’t.
Tools & Skills
Sourced directly from Cadence Design Systems’s career page
Your application goes straight to Cadence Design Systems.
Opens cadence.wd1.myworkdayjobs.com in a new tab
Specialisation
Open roles at Cadence Design Systems
593 positions
Job ID
/job/SAN-JOSE/Cloud-Security-Operations-Engineer_R55396
Get matched to roles like this
Upload your resume once. We’ll notify you when matching roles open up.
Join talent pool — freeSimilar Other roles
Samsung Semiconductor
Staff Engineer, Trace-Driven Simulator Development
San Jose, California, United States|Other
Micron Technology
Executive Admin - ID1
Boise, ID - Main Site|Other
Micron Technology
OCT CMP Mfg. Alignment (MA) Engineer/Sr Engineer
Taichung - Fab 16, Taiwan|Other
Micron Technology
MANAGER, SMART MFG & AI, DATA ENG (Taichung or Taoyuan)
2 Locations|Other