yoinka

Senior Security Engineer - Cloud Security

PagerDuty

AtlantaSeniorH-1B sponsor company
Sign in to applyVerified 1h ago
Location
Atlanta
Work model
On-Site
Level
Senior
H-1B history
1 approvals (FY2023)
Posted
2h ago

Skills

AWSAzureCybersecurityGenAIKubernetesLLMPythonRESTSalesforceTerraform

About this role

PagerDuty, Inc. (NYSE: PD) is the global leader in AI-first digital operations. By automatically detecting, diagnosing, and remediating issues, the PagerDuty Platform orchestrates AI agents and automated workflows with context from over 750 integrations. Trusted by approximately two-thirds of the Fortune 100 and nearly half of the Fortune 500, PagerDuty is the industry standard for organizations scaling resilient, autonomous operations. Notable customers include Chipotle, Cloudflare, Docusign, Fox, Nvidia, Salesforce, Spotify, Zoom and more. We are growing rapidly and hiring top talent with leading AI skills across engineering, sales, product, marketing, and beyond as we build the leading digital operations platform.

Senior Security Engineer — Cloud Security (Platform, Identity & Cryptography)

PagerDuty is seeking a Senior Security Engineer to join our Cloud Security team, part of Security Engineering within the CTO organization. This is a preventive, platform-focused role owning security posture across our multi-account AWS environment and the Kubernetes platforms running on it, with deep responsibility for identity & access management and cryptography (PKI and encryption). You'll partner with 30+ engineering teams, shipping controls as code that roll out without disrupting engineering — including across our FedRAMP footprint.

*This role will require 2 days per week in our Atlanta office...*

What you'll do

• Harden PagerDuty's AWS and Kubernetes environments against CIS Benchmarks, DISA STIGs, and FedRAMP Moderate baselines across a multi-account, multi-org footprint — proving results through evidence, config-remediation tooling, and KPIs that track posture, identity, and encryption/PKI health so we know where we stand and where the gaps are.

• Harden EKS clusters and the Istio service mesh against the CIS Kubernetes Benchmark, DISA Kubernetes STIG, and NSA/CISA hardening guidance.

• Design and enforce Kubernetes RBAC, least-privilege workload identity, and container supply-chain controls (image provenance, admission control, runtime policy).

• Own PKI and encryption standards across the environment — certificate lifecycle and management, KMS-backed key management and rotation, TLS/mTLS (including within the Istio mesh), and encryption-at-rest and in-transit requirements — and define the standards other teams build against.

• Design and roll out Service Control Policy (SCP) guardrails and least-privilege IAM/PAM across dozens of accounts and multiple orgs.

• Lean into AI to unlock efficiency and velocity — consume agentic tooling in day-to-day work and build lightweight agentic solutions that streamline repetitive security work: posture triage, threat modeling, risk assessment, incident enrichment and investigation, compliance-evidence generation, and detection tuning.

• Shape detection strategy for the domains you own — Kubernetes/Istio, identity, and cryptography — authoring and tuning detections in our SIEM stack, defining what "good" coverage looks like for these domains, and threat hunting for container escape, lateral movement, anomalous mesh traffic, and identity or credential abuse.

• Participate in the team's on-call rotation, triaging and dispositioning cloud and Kubernetes threat alerts and acting as Incident Lead during incidents — driving containment, blast-radius/exposure analysis, and post-incident review.

• Automate security controls as code using Terraform and Python — including Kubernetes policy-as-code and tool-to-tool integrations that reduce manual work.

• Partner closely with our AppSec and GRC teams — aligning platform controls with secure-development needs and translating hardening, identity, and encryption work into audit and compliance

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka