Security Engineer – Cloud Security (AWS)
Xcel Energy
- Location
- Denver, CO
- Employment
- Full Time
- Work model
- Hybrid
- Level
- Senior
- Posted
- Sep 21, 2026
Skills
About this role
Xcel Energy (NASDAQ: XEL) is a leading energy provider and Fortune 500 company, dedicated to serving millions of electricity and natural gas customers across eight states: Minnesota, Colorado, Wisconsin, Michigan, North Dakota, South Dakota, New Mexico and Texas. We make energy work better for our customers, helping them thrive every day. That means always raising the bar - delivering better service and providing more reliable, resilient, and sustainable energy. Xcel Energy is a place where you’ll have opportunities to grow, expand your skills, and help lead the clean energy transition. We offer meaningful rewards, recognition, and support to help you build your career and make an impact - both on the job and beyond. Most importantly, it means you’ll be joining a company that knows employees are the driving force behind its success and is committed to helping you be your best. Xcel Energy supports a hybrid work model to enable collaboration and flexibility. Many roles are expected to work onsite three days per week (Tuesday–Thursday); however, work location expectations vary based on role, team, and business needs.
Role
Summary The Security Engineer – Cloud Security (AWS) is responsible for building and running the AWS cloud security program with a focus on reducing risk through visibility, guardrails, and automation. This role identifies and analyzes cloud security risk, drives remediation through stakeholders, and implements preventative controls to reduce exposure over time. The role operates in an advisory capacity and does not perform direct operational changes. Initial focus is AWS across commercial and GovCloud environments, with planned expansion to Azure once the AWS program is mature. This position reports to the Manager, Vulnerability Management. It will be required to interview in person in Minneapolis, MN or Denver, CO. Primary Objectives Build and mature the AWS cloud security program with clear ownership, processes, and workflows. Identify, prioritize, and communicate cloud security risk across environments and stakeholders. Implement preventative controls and guardrails to reduce risk before deployment. Leverage automation and integration to reduce manual effort and improve consistency. Support remediation by driving findings to the appropriate owners and tracking outcomes.
Responsibilities
Serve as the primary cloud security engineer for AWS environments, including commercial, GovCloud, dev, and test accounts. Use AWS native security capabilities such as Inspector, Security Hub, and related services to identify and analyze risk. Maintain visibility across IAM, network configuration, logging, monitoring, and workload security posture. Identify issues such as overly permissive access, unused accounts, misconfigurations, and exposure risks. Develop and implement guardrails, policies, and controls to prevent insecure configurations and reduce attack surface. Promote the use of hardened images, containers, and standardized builds to reduce risk at deployment. Integrate cloud security findings into existing workflows and coordinate remediation with responsible teams. Work closely with Cloud Platform, SAP, Enterprise Architecture, and other teams to implement meaningful security improvements. Partner with Application Security teams to support DevSecOps practices, including CI/CD pipeline integration, gates, and automation. Support SAP cloud security needs and maintain awareness of SAP-specific risks within AWS environments. Use APIs, scripting, and integration to automate data collection, analysis, and workflow execution. Analyze cloud risk in context and communicate clear, actionable recommendations to stakeholders. Support logging and monitoring capabilities setup and integration while deferring operational ownership to SOC/IR teams.
Required Qualifications
Minimum 5 years of experience in information security. Strong hands-on