Senior Cloud Security Engineer

Alloy•New York City, NY
•Hybrid

About The Position

Alloy is where you belong! Alloy is the AI-powered identity and fraud prevention platform that accelerates onboarding, stops fraud, and scales compliance across the customer lifecycle so financial organizations can grow without limits. More than 900 of the world's leading financial institutions and fintechs trust Alloy for smarter risk management that drives growth. Through our values: Be Bold, Go Fast, Collaborate, and Celebrate Our Differences, we are creating a workplace where you can grow, thrive, and belong. See how we’ve been continuously recognized and named one of Inc. Magazine’s Best Workplaces , Forbes America’s Best Startup Employers , Best Fintech to Work for by American Banker , year after year. Check out our investors and read more about us here . About the team Product Security covers application security and cloud security at Alloy. Our customers are banks and fintechs, so the state of our security program is not an internal matter. It shows up in client due diligence, in what we can sell, and in whether deals close. The team is small and the program is still being matured, which means the person in this seat shapes how engineering across the company designs and ships infrastructure rather than inheriting someone else's finished playbook. Alloy operates in a hybrid-work environment. We look to foster collaboration and community by having our local employees onsite three days a week.

Requirements

  • 3+ years in cloud security, or in cloud infrastructure with a security focus, primarily in AWS.
  • Hands-on with AWS networking and security services: VPC design, security groups, NACLs, WAF, GuardDuty, Config, Inspector, KMS, and IAM.
  • Provisioning infrastructure as code with Terraform and working knowledge of Kubernetes or EKS.
  • Working experience with a SIEM and a CSPM, including tuning alerts and building detections that engineers act on.
  • Scripting or programming in Python or TypeScript, with an eye for where the code itself creates risk.
  • On-call incident response experience, and the ability to explain risk and remediation to engineers who do not work in security.

Nice To Haves

  • AWS Organizations and multi-account environments.
  • AWS Solutions Architect Associate or AWS Security Specialty.
  • Public key infrastructure and applied cryptography.

Responsibilities

  • Own the security of Alloy's AWS environment and the tooling that keeps it visible.
  • Work closest with the Infrastructure team, but your reach will extend to every engineering team.
  • Partner with the Infrastructure team to build security into new cloud infrastructure as it is designed, and act as the security point of contact for new builds.
  • Lead initiatives you scope yourself to reduce cloud infrastructure risk in ways that are repeatable and maintainable.
  • Build alerts, detections, and dashboards in our CSPM and SIEM, and write the runbooks that make them actionable for the people who get paged.
  • Own CSPM findings end to end, from triage through remediation, including the Terraform changes that fix the problem at its source.
  • Drive AWS permissions and network design toward least privilege, and debug both without widening the attack surface in the process.
  • Join the on-call rotation, investigate security incidents to root cause, and put controls in place so the same incident does not recur.

Benefits

  • Unlimited PTO and flexible work policy
  • Employee stock options
  • Medical, dental, vision plans with HSA (monthly employer contribution) and FSA options
  • 401k with 100% match up to 4% of annual employee compensation
  • Eligible new parents receive 16 weeks of paid parental leave
  • Home office stipend for new employees
  • Annual Learning & Development annual stipend
  • Well-being benefits include access to ClassPass, OneMedical, UrbanSitter, and Spring Health
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service