Cloud Engineer
Sourcebae
Job Description: Cloud Security Engineer
Reports to: Security Lead
Level: Mid (IC)
Mission
Own the identity, access, and network security control plane — CyberArk, Zscaler and Cloudflare — for a fast-scaling, AI-driven insurance infrastructure org. You'll take these tools from initial deployment handoff to steady, auditable, day-2 operations, and be the technical backbone the Security Lead relies on for privileged access and network security posture.
What you'll own
• CyberArk (PAM) — safe/policy design, privileged account lifecycle, credential rotation monitoring, access recertification
• Zscaler (SSE) — policy tuning, app onboarding, exception handling
• Cloudflare (WAF/CDN, and Zero Trust/Access if applicable) — rule tuning, DNS, edge security posture
Key responsibilities
• Take over day-2 administration of CyberArk from the implementation partner; ensure clean runbooks/SOPs exist and are maintained
• Run privileged access onboarding/offboarding and periodic access recertification, feeding evidence to the GRC Analyst for audit cycles
• Own Zscaler and Cloudflare policy baselines; manage exceptions without degrading security posture
• Partner with engineering teams as headcount scales to keep IAM and network controls usable, not just secure
• Support technical deep-dives requested by auditors or pen testers on identity/network architecture
• Identify opportunities to automate policy-drift detection and routine PAM/SSE administration, in line with the team's AI-driven, lean operating model
• Escalate control-design questions or audit findings on these tools to the Security Lead
What we're looking for
• 3–6+ years in security engineering, with hands-on ownership of at least one PAM platform (CyberArk strongly preferred) in production
• Working experience with a cloud SSE/ZTNA platform (Zscaler, Cloudflare Access, or similar) and a CDN/WAF
• Comfortable being the sole owner of high-scrutiny controls in an audited environment (SOC 2, ISO 27001, or similar)
• Strong scripting/automation ability (Python, Terraform, or similar) to keep a lean team's operational load sustainable
• Clear written communication — you'll produce evidence and explanations auditors and pen testers can follow
Nice to have
• Insurance, financial services, or other regulated-industry background
• Experience standing up or maturing a PAM program from a fresh implementation
• Exposure to NAIC Insurance Data Security Model Law or similar state insurance regulatory frameworks
How we'll know you're succeeding
• CyberArk, Zscaler, and Cloudflare pass audit control tests with minimal findings
• Privileged access recertification completed on schedule every cycle
• No unplanned production impact from policy changes across owned tools
• Routine administration increasingly automated rather than manual quarter over quarter