← Back to results

Senior Security Engineer - Cloud Security

Join PagerDuty as a Senior Security Engineer focusing on cloud security, identity management, and cryptography in a hybrid work environment.

Location
Atlanta
Compensation
$150k–$251.9k/yr
Level
senior
Type
full time · Hybrid

Posted by employer 3 days ago

First seen on Joblaze 2 days ago

Last verified on the company career page 12 hours ago

What you'll build

  • Harden AWS and Kubernetes environments
  • Design and enforce Kubernetes RBAC
  • Own PKI and encryption standards
  • Automate security controls as code
  • Shape detection strategy for Kubernetes and identity

Must have

  • 5+ years as a Security Engineer in an AWS-native environment
  • Deep expertise securing Kubernetes and containerized environments
  • Strong expertise in PKI and cryptography
  • Hands-on expertise with AWS security services
  • Ability to inform and drive detection strategy

Nice to have

  • Experience hardening cloud and Kubernetes environments to CIS Benchmarks
  • Experience building agentic or AI-assisted security automation
  • Familiarity with securing AI/ML workloads
  • Experience with cloud-native security tooling
  • Azure security exposure

Practical constraints

  • This role will require 2 days per week in our Atlanta office

AI in the day-to-day

Lean into AI to unlock efficiency and velocity — consume agentic tooling in day-to-day work and build lightweight agentic solutions.

Requirements

Experience
5+ years

Not disclosed in this posting: visa sponsorship.

Benefits

Flexible work arrangements Comprehensive benefits package Paid Parental Leave Company equity Paid Volunteer Time Off Competitive salary

Joblaze summary

In the role of Senior Security Engineer for Cloud Security at PagerDuty, the individual will focus on enhancing the security posture of the company's AWS and Kubernetes environments, ensuring compliance with various security benchmarks. Key skills include expertise in Kubernetes security, identity management, and cryptography, along with proficiency in Terraform and Python for automating security controls. This position is suited for experienced security engineers with a strong background in cloud infrastructure and a proactive approach to threat detection and incident response. The role involves collaboration with multiple engineering teams and contributes to PagerDuty's commitment to maint

Joblaze insights

  • Listed 2 days ago — first seen on Joblaze September 19, 2026. Last confirmed on PagerDuty's careers page September 20, 2026.
  • Salary band is below the typical range for Security roles (median ~$170,000).
  • Starts above 26% of 98 comparable senior security roles in United States that list Python we track (median $170,000 across 40 companies). See Python salary trends
  • Python appears in 42.2% of 306 comparable senior security roles in United States; EKS appears in 0.7% of 306 comparable senior security roles in United States.

Quick facts

Is the Senior Security Engineer - Cloud Security role remote?
It's hybrid — PagerDuty expects some on-site time in Atlanta.
What's the salary range?
PagerDuty lists $150,000–$251,900 for this role.
How much experience is required?
At least 5 years of relevant experience for this Senior Security Engineer - Cloud Security role.
Where is the role based?
PagerDuty is hiring for this position in Atlanta.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Cryptography, EKS, IAM, Istio, Kubernetes.
What seniority level is this role?
PagerDuty targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Senior Security Engineer - Cloud Security role at PagerDuty.

From the original posting

PagerDuty, Inc. (NYSE: PD) is the global leader in AI-first digital operations. By automatically detecting, diagnosing, and remediating issues, the PagerDuty Platform orchestrates AI agents and automated workflows with context from over 750 integrations. Trusted by approximately two-thirds of the Fortune 100 and nearly half of the Fortune 500, PagerDuty is the industry standard for organizations scaling resilient, autonomous operations. Notable customers include Chipotle, Cloudflare, Docusign, Fox, Nvidia, Salesforce, Spotify, Zoom and more. We are growing rapidly and hiring top talent with leading AI skills across engineering, sales, product, marketing, and beyond as we build the leading digital operations platform.

.

Senior Security Engineer — Cloud Security (Platform, Identity & Cryptography)

PagerDuty is seeking a Senior Security Engineer to join our Cloud Security team, part of Security Engineering within the CTO organization. This is a preventive, platform-focused role owning security posture across our multi-account AWS environment and the Kubernetes platforms running on it, with deep responsibility for identity & access management and cryptography (PKI and encryption). You'll partner with 30+ engineering teams, shipping controls as code that roll out without disrupting engineering — including across our FedRAMP footprint.

*This role will require 2 days per week in our Atlanta office...*

What you'll do

  • Harden PagerDuty's AWS and Kubernetes environments against CIS Benchmarks, DISA STIGs, and FedRAMP Moderate baselines across a multi-account, multi-org footprint — proving results through evidence, config-remediation tooling, and KPIs that track posture, identity, and encryption/PKI health so we know where we stand and where the gaps are.
  • Harden EKS clusters and the Istio service mesh against the CIS Kubernetes Benchmark, DISA Kubernetes STIG, and NSA/CISA hardening guidance.
  • Design and enforce Kubernetes RBAC, least-privilege workload identity, and container supply-chain controls (image provenance, admission control, runtime policy).
  • Own PKI and encryption standards across the environment — certificate lifecycle and management, KMS-backed key management and rotation, TLS/mTLS (including within the Istio mesh), and encryption-at-rest and in-transit requirements — and define the standards other teams build against.
  • Design and roll out Service Control Policy (SCP) guardrails and least-privilege IAM/PAM across dozens of accounts and multiple orgs.
  • Lean into AI to unlock efficiency and velocity — consume agentic tooling in day-to-day work and build lightweight agentic solutions that streamline repetitive security work: posture triage, threat modeling, risk assessment, incident enrichment and investigation, compliance-evidence generation, and detection tuning.
  • Shape detection strategy for the domains you own — Kubernetes/Istio, identity, and cryptography — authoring and tuning detections in our SIEM stack, defining what "good" coverage looks like for these domains, and threat hunting for container escape, lateral movement, anomalous mesh traffic, and identity or credential abuse.
  • Participate in the team's on-call rotation, triaging and dispositioning cloud and Kubernetes threat alerts and acting as Incident Lead during incidents — driving containment, blast-radius/exposure analysis, and post-incident review.
  • Automate security controls as code using Terraform and Python — including Kubernetes policy-as-code and tool-to-tool integrations that reduce manual work.
  • Partner closely with our AppSec and GRC teams — aligning platform controls with secure-development needs and translating hardening, identity, and encryption work into audit and compliance evidence.

Additional responsibilities

  • Mentor and guide teammates on platform, identity, and cryptography security practices, and contribute to roadmap and annual planning. At the senior end of this role, you'll help draft external- and auditor-facing communication and represent the team in cross-team planning.

Basic qualifications

  • 5+ years as a Security Engineer in an AWS-native, microservice SaaS environment, with a strong focus on cloud infrastructure, container, and identity security.
  • Deep, hands-on expertise securing Kubernetes and containerized environments — EKS, RBAC, Kubernetes admission control, network policy, and workload identity.
  • Container runtime and image security experience; familiarity with a service mesh such as Istio strongly preferred.
  • Strong, hands-on expertise in PKI and cryptography — certificate lifecycle/management, TLS/mTLS, key management and rotation (AWS KMS or similar HSM/KMS), and encryption-at-rest/in-transit standards.
  • Deep, hands-on expertise with AWS security services, including but not limited to: IAM family, Organizations/SCPs, Secrets Manager, KMS, GuardDuty, CloudTrail, and Config.
  • Ability to inform and drive detection strategy within your domains — comfortable authoring and tuning detections in a modern SIEM and threat hunting for Kubernetes, identity, and cryptography-related threats.
  • A builder's mindset toward AI — hands-on experience using agentic/AI coding tools and an interest in developing lightweight automation and agents to accelerate security work.
  • Experience with security incident response and on-call — triaging alerts and coordinating containment during incidents.
  • Proficiency with Infrastructure as Code and at least one programming language (Terraform plus Python, or similar), and comfort automating controls, including Kubernetes policy-as-code.
  • Proven ability to scope ambiguous projects, break complex work into actionable items, and drive them to completion with a high degree of ownership.

Preferred qualifications

  • Hands-on experience hardening cloud and Kubernetes environments to CIS Benchmarks and DISA STIGs, and operating within FedRAMP Moderate (or similar) authorization; familiarity with NIST CSF, SOC 2, or ISO 27001.
  • Experience building agentic or AI-assisted security automation (e.g., agent frameworks, LLM-backed tooling, and translating playbooks into automated pipelines).
  • Familiarity with securing AI/ML or agentic workloads running on cloud and Kubernetes infrastructure.
  • Experience with cloud-native security tooling such as a CNAPP platform and an EDR/runtime-protection agent, including container and Kubernetes runtime protection.
  • Experience partnering with AppSec and GRC teams to align controls and produce compliance evidence.
  • Azure security exposure (Entra ID, Defender for Cloud) a plus, but not required.
  • Demonstrated history of mentoring engineers and strong written and verbal communication skills.
  • Working knowledge of PagerDuty's Incident Management and Process Automation products.

The base salary range for this position is 150,000 - 251,900 USD. This role may also be eligible for bonus, commission, equity, and/or benefits.

Hesitant to apply?

PagerDuty uses the E-Verify employment verification program.

Standard company text repeated across PagerDuty's postings is omitted here.

Similar positions

PagerDuty
Site Reliability Engineer I
PagerDuty · Atlanta; Toronto
PagerDuty
Site Reliability Engineer II
PagerDuty · Atlanta
PagerDuty
Senior Developer Advocate
PagerDuty · Atlanta
PagerDuty
Senior AI/ML Engineer
PagerDuty · Lisbon
PagerDuty
Senior Product Manager
PagerDuty · Atlanta; San Francisco