Cloud Security Engineer - AWS Focus

<p>Ledgebrook is a tech-enabled E&S MGA on a mission to modernize Specialty insurance. The industry is burdened with legacy technology and inefficient processes, preventing innovation at scale. We are changing that. Our goal is to become the best-in-class full-stack insurance and re/insurer, leveraging AI and data-driven insights to revolutionize underwriting, pricing, and risk selection.</p><p>We believe in talent density—fewer, better people working together as one. We win as a team, and our success is shared through generous equity packages for all employees.</p><p><br></p><p><br></p> <br><h3>About the Role</h3> <p>We are seeking a Cloud Security Engineer with deep expertise in securing cloud-native environments, with a strong emphasis on AWS services. The ideal candidate will have a solid understanding of cloud infrastructure, DevSecOps practices, and modern security frameworks. You will play a key role in designing and implementing secure architectures, tooling, and practices to protect our cloud infrastructure and workloads.</p><p><br></p><p><strong>Key Responsibilities:</strong></p><ul><li>Design, implement, and manage <strong>secure AWS cloud architectures</strong>, including networking, IAM, and service configurations.</li><li>Develop and enforce <strong>cloud security standards, policies, and guardrails</strong> across AWS environments.</li><li>Implement <strong>automated security controls</strong> using tools like <strong>Terraform, AWS Config, Security Hub, GuardDuty</strong>, and <strong>Inspector</strong>.</li><li>Collaborate with DevOps and engineering teams to integrate security into <strong>CI/CD pipelines</strong> (DevSecOps).</li><li>Monitor and respond to security events using <strong>SIEM</strong> and cloud-native logging tools (<strong>CloudWatch, CloudTrail, AWS Security Hub, etc.</strong>).</li><li>Conduct <strong>threat modeling</strong>, <strong>risk assessments</strong>, and <strong>security architecture reviews</strong> for AWS-based applications and services.</li><li>Maintain and optimize <strong>identity and access management</strong> across AWS accounts using <strong>IAM, SSO, SCPs</strong>, and <strong>Organizations</strong>.</li><li>Manage <strong>data protection strategies</strong>, including encryption (KMS), DLP, and secure key management.</li><li>Support compliance initiatives (e.g., <strong>SOC 2, HIPAA, ISO 27001, or FedRAMP</strong>) with evidence collection and policy implementation.</li></ul><p><br></p> <br><h3>About you</h3> <p>Here at Ledgebrook we are passionate about creating a team that is on a continuous learning journey and that shares our excitement about building a company from the ground up. Some of the characteristics we hold dear are:</p><ul><li>A passion to deliver a world-class customer service experience to both internal and external customers</li><li>Intellectual curiosity and a desire to innovate processes/procedures versus being satisfied with the status quo</li><li>A desire to continue learning whatever your career stage</li><li>Agile prioritization skills coupled with a keen sense of urgency that seeks to balance getting it right versus getting it done right now</li><li>A strong drive and desire to win together as a high-performing team</li><li>A moral compass to “do the right thing, period”, we have zero tolerance for toxic behaviors.</li></ul><p><br></p> <br><h3>Requirements</h3> <p><strong>Basic Qualifications:</strong></p><ul><li><strong>3+ years</strong> of experience in a Cloud Security, Security Engineering, or related role.</li><li>Strong knowledge of <strong>AWS security services</strong>, architectures, and best practices.</li><li>Experience with <strong>Infrastructure as Code (IaC)</strong> tools such as <strong>Terraform or CloudFormation</strong>.</li><li>Hands-on experience with <strong>cloud monitoring and logging</strong>, especially in an AWS context.</li><li>Proficiency in scripting or automation (e.g., <strong>Python, Bash, or PowerShell</strong>).</li><li>Solid understanding of <strong>network security</strong>, <strong>firewalls</strong>, <strong>VPC design</strong>, and <strong>zero-trust principles</strong>.</li><li>Familiarity with <strong>incident response processes</strong>, <strong>SIEM platforms</strong>, and <strong>forensics tools</strong>.</li><li>Comfortable working cross-functionally with engineering, IT, and compliance teams.</li><li>Self-starter with a proactive approach to risk identification and mitigation.</li><li>Willingness to participate in an on-call rotation or security incident escalations as needed.</li></ul><p><strong>Preferred Qualifications:</strong></p><ul><li><strong>AWS certifications</strong> such as AWS Certified Security – Specialty, Solutions Architect, or DevOps Engineer.</li><li>Experience with <strong>multi-account AWS environments</strong> and AWS Organizations.</li><li>Knowledge of <strong>container security</strong>, especially within <strong>Amazon ECS.</strong></li><li>Experience with <strong>third-party security tools</strong> such as <strong>Tenable, Prisma Cloud, Wiz, or Lacework</strong>.</li><li>Experience with <strong>compliance frameworks</strong> and translating them into technical controls.</li></ul><p>Background in <strong>penetration testing, red/blue teaming</strong>, or <strong>threat intelligence</strong> is a plus.</p><p>For those applying in the US:</p><p><em>Please note: This position is open only to candidates who are authorized to work in the United States without the need for current or future employer-sponsored work authorization. We are unable to offer visa sponsorship at this time</em></p><p><br></p> <br><h3>Benefits</h3> <p>US Benefits</p><ul><li>Competitive salary and meaningful equity ownership</li><li>Health Insurance 100% employer-paid option available (US only)</li><li>Additional benefits available include 401k plan, dental, vision & other options (US only)</li><li>Remote work, flexible hours</li><li>Unlimited time off policy</li><li>Ownership, autonomy, purpose</li></ul><p><br></p><p>Poland Benefits:</p><ul><li>Competitive salary and meaningful equity</li><li>Completely remote, flexible schedule, and monthly coworking gatherings</li><li>Unlimited paid time off</li><li>Clear ownership and impact from day one</li><li>Collaborative, transparent work culture</li></ul><p><br></p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...