Cloud Security Specialist – Platform Engineering

Xona Space SystemsBurlingame, CA
$153,000 - $178,000

About The Position

Xona is seeking a Cloud Security Engineer to join their Platform Engineering team. This role involves embedding security into the core of their AWS infrastructure and deployment pipelines. The engineer will focus on designing, implementing, and automating security guardrails, building secure defaults, automated policy enforcement, and self-service security tools. The position requires close collaboration with architecture, DevOps, and enterprise security teams to deliver secure foundational services, automate compliance, and maintain high security standards across the engineering organization.

Requirements

  • 4+ years of experience in cloud security, DevOps, or platform engineering, with a strong emphasis on security operations and architecture.
  • Deep hands-on experience securing cloud environments (AWS, GCP, or Azure).
  • Strong understanding of containerization security best practices, and Kubernetes security controls (RBAC, network policies, runtime security).
  • Proficiency in languages such as Python, Go, etc. and experience with automation tools.
  • Familiarity with CI/CD security integrations, Software Bill of Materials (SBOM), Security Information and Event Management (SIEM), and cloud security posture management (CSPM) tools.

Nice To Haves

  • Certifications such as AWS Certified Security, CISSP, or CCSK are a plus.
  • Experience implementing Zero Trust architectures within a modern enterprise.
  • Familiarity with Policy-as-Code frameworks (e.g., Open Policy Agent).
  • Demonstrated passion for developer enablement and building "security as a product" rather than a roadblock.
  • Hands-on experience running offensive security scenarios or red-team exercises for distributed, highly available cloud environments.
  • For U.S. Roles: Applicant must be a U.S. citizen, lawful permanent resident of the United States (i.e. Green Card holder), or other protected individual as defined by 8 U.S.C. 1324b(a)(3).
  • For U.K. Roles: Role requires Baseline Personnel Security Standard (BPSS) checks, and successful candidates must be eligible to obtain UK Security Clearance (SC).
  • For Canada Roles: Successful candidates must obtain and hold a security clearance at the reliability status level, and pass security assessment for the Canadian Controlled Goods Program (CGP) and ITAR.

Responsibilities

  • Design and enforce secure cloud patterns, zero-trust network segmentation, and hardening standards across AWS multi-account architecture and container platforms (e.g., Kubernetes).
  • Architect secure authentication, authorization, secrets management, and zero-trust networking principles across all platform services.
  • Build automated security guardrails that empower developers to move fast safely, minimizing friction while maintaining strict compliance standards (e.g., CMMC, NIST 800-171).
  • Conduct regular security assessments and threat modeling.
  • Partner with SRE and operations teams to monitor security telemetry, triage cloud threats, and participate in incident response and root-cause analysis.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service