SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 150,000 - 251,900 / annual
PagerDuty is seeking a Senior Security Engineer to join the Cloud Security team within Security Engineering. This is a preventive, platform-focused role owning security posture across PagerDuty's multi-account AWS environment and Kubernetes platforms, with deep responsibility for identity & access management and cryptography (PKI and encryption). You will partner with 30+ engineering teams to ship security controls as code that roll out without disrupting engineering, including across the FedRAMP footprint. The role requires 2 days per week in the Atlanta office.
Key responsibilities include:
- Harden AWS and Kubernetes environments against CIS Benchmarks, DISA STIGs, and FedRAMP Moderate baselines across a multi-account, multi-org footprint, proving results through evidence, config-remediation tooling, and KPIs tracking posture, identity, and encryption/PKI health.
- Harden EKS clusters and Istio service mesh against CIS Kubernetes Benchmark, DISA Kubernetes STIG, and NSA/CISA hardening guidance.
- Design and enforce Kubernetes RBAC, least-privilege workload identity, and container supply-chain controls (image provenance, admission control, runtime policy).
- Own PKI and encryption standards across the environment—certificate lifecycle and management, KMS-backed key management and rotation, TLS/mTLS (including within Istio mesh), and encryption-at-rest and in-transit requirements.
- Design and roll out Service Control Policy (SCP) guardrails and least-privilege IAM/PAM across dozens of accounts and multiple orgs.
- Leverage AI to unlock efficiency and velocity—consume agentic tooling in day-to-day work and build lightweight agentic solutions that streamline repetitive security work: posture triage, threat modeling, risk assessment, incident enrichment and investigation, compliance-evidence generation, and detection tuning.
- Shape detection strategy for Kubernetes/Istio, identity, and cryptography domains—author and tune detections in the SIEM stack, define what "good" coverage looks like, and threat hunt for container escape, lateral movement, anomalous mesh traffic, and identity or credential abuse.
- Participate in the team's on-call rotation, triaging and dispositioning cloud and Kubernetes threat alerts and acting as Incident Lead during incidents.
- Automate security controls as code using Terraform and Python, including Kubernetes policy-as-code and tool-to-tool integrations.
- Partner closely with AppSec and GRC teams to align platform controls with secure-development needs and translate hardening, identity, and encryption work into audit and compliance evidence.
- Mentor and guide teammates on platform, identity, and cryptography security practices; contribute to roadmap and annual planning. At the senior end, help draft external- and auditor-facing communication and represent the team in cross-team planning.
Requirements:
- 5+ years as a Security Engineer in an AWS-native, microservice SaaS environment, with strong focus on cloud infrastructure, container, and identity security.
- Deep, hands-on expertise securing Kubernetes and containerized environments—EKS, RBAC, Kubernetes admission control, network policy, and workload identity.
- Container runtime and image security experience; familiarity with a service mesh such as Istio strongly preferred.
- Strong, hands-on expertise in PKI and cryptography—certificate lifecycle/management, TLS/mTLS, key management and rotation (AWS KMS or similar HSM/KMS), and encryption-at-rest/in-transit standards.
- Deep, hands-on expertise with AWS security services, including but not limited to: IAM family, Organizations/SCPs, Secrets Manager, KMS, GuardDuty, CloudTrail, and Config.
- Ability to inform and drive detection strategy within your domains—comfortable authoring and tuning detections in a modern SIEM and threat hunting for Kubernetes, identity, and cryptography-related threats.
- A builder's mindset toward AI—hands-on experience using agentic/AI coding tools and interest in developing lightweight automation and agents to accelerate security work.
- Experience with security incident response and on-call—triaging alerts and coordinating containment during incidents.
- Proficiency with Infrastructure as Code and at least one programming language (Terraform plus Python, or similar), and comfort automating controls, including Kubernetes policy-as-code.
- Proven ability to scope ambiguous projects, break complex work into actionable items, and drive them to completion with a high degree of ownership.
Preferred qualifications:
- Hands-on experience hardening cloud and Kubernetes environments to CIS Benchmarks and DISA STIGs, and operating within FedRAMP Moderate (or similar) authorization; familiarity with NIST CSF, SOC 2, or ISO 27001.
- Experience building agentic or AI-assisted security automation (e.g., agent frameworks, LLM-backed tooling, and translating playbooks into automated pipelines).
- Familiarity with securing AI/ML or agentic workloads running on cloud and Kubernetes infrastructure.
- Experience with cloud-native security tooling such as a CNAPP platform and an EDR/runtime-protection agent, including container and Kubernetes runtime protection.
- Experience partnering with AppSec and GRC teams to align controls and produce compliance evidence.
- Azure security exposure (Entra ID, Defender for Cloud) a plus, but not required.
- Demonstrated history of mentoring engineers and strong written and verbal communication skills.
- Working knowledge of PagerDuty's Incident Management and Process Automation products.