Senior Cloud Security Engineer

TP-LINK

Irvine, USonsite$150k-$180k/yrPosted Aug 21, 2026
Posting intelligenceActively listed

Skills

kubernetespythonprismaazurecicdaws

About the role

About Us:

Headquartered in the United States, TP-Link Systems Inc. is a global provider of reliable networking devices and smart home products, consistently ranked as the world’s top provider of Wi-Fi devices. The company is committed to delivering innovative products that enhance people’s lives through faster, more reliable connectivity. With a commitment to excellence, TP-Link Systems serves customers in over 170 countries and continues to grow its global footprint.

We believe technology changes the world for the better! At TP-Link Systems Inc, we are committed to crafting dependable, high-performance products to connect users worldwide with the wonders of technology.

Embracing professionalism, innovation, excellence, and simplicity, we aim to assist our clients in achieving remarkable global performance and enable consumers to enjoy a seamless, effortless lifestyle.

Overview:

The Senior Cloud Security Engineer reduces material risk across large-scale AWS, Azure, and multi-cluster Kubernetes environments. This engineer operates and continuously improves our CSPM/CNAPP platform, investigates complex exposure paths, strengthens cloud security guardrails, and works with Cloud Operations, SRE, and engineering teams to drive remediation through closure.

This is also a builder role. You will use Python, APIs, infrastructure as code, and modern AI-assisted engineering tools to develop secure dashboards, integrations, automation, and analytical workflows. Success requires strong cloud security judgment, practical engineering ability, and the persistence to drive findings through remediation rather than simply reporting them.

What You'll Do

Operate and improve cloud security controls across AWS, Azure, Kubernetes, and hybrid infrastructure.

Use CSPM/CNAPP telemetry to investigate vulnerabilities, misconfigurations, identity risks, exposure paths, and publicly accessible services.

Validate and prioritize findings based on real-world risk, then work with infrastructure owners to drive remediation through closure.

Develop secure dashboards, integrations, automation, and analytical workflows using APIs and modern AI-assisted engineering tools.

Secure Kubernetes environments and containerized workloads across the software development lifecycle.

Conduct security reviews of cloud architecture, infrastructure patterns, identities, network controls, and deployment pipelines.

Build automation, guardrails, reporting, and repeatable processes that improve cloud security visibility and execution.

Investigate cloud security incidents and support response, containment, and corrective action.

Requirements

What You Must Have

7+ years of professional experience in security engineering, cloud engineering, infrastructure engineering, or a closely related technical role.

3+ years of direct, hands-on responsibility for securing production cloud environments, with depth in AWS or Azure and practical experience with the other.

Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or another relevant technical field.

Hands-on experience operating an enterprise CSPM/CNAPP platform, such as Orca, Wiz, Prisma Cloud, or Microsoft Defender for Cloud, including tuning policy, investigating findings, prioritizing material risk, and driving remediation rather than simply consuming platform output.

Experience building and shipping production-quality security tooling, automations, integrations, or dashboards using Python and APIs, supported by infrastructure as code and modern CI/CD practices. Candidates should be prepared to walk through something they built and explain their individual contribution.

Strong command of cloud security fundamentals at scale in your primary cloud: IAM, network security, logging and detection, encryption and key management, and secure configuration.

Hands-on experience securing production Kubernetes environments, including workload identity, network controls, secrets management, admission policies, image security, and runtime visibility.

Demonstrated ability to use modern AI-assisted development tools to accelerate engineering work.

Current AWS or Azure security or architecture certification, such as AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate or Professional, Microsoft Certified: Azure Security Engineer Associate, or Microsoft Certified: Azure Solutions Architect Expert.

Experience working directly with Cloud Operations, SRE, or engineering teams to drive remediation of cloud security risk.

Preferred Qualifications

Experience securing large, globally distributed or multi-cloud environments.

Multiple cloud security or architecture certifications beyond the required minimum.

Advanced experience implementing policy as code, automated cloud guardrails, and security controls within CI/CD pipelines.

Benefits

Salary range: $150,000-$180,000

Fully paid medical, dental, and vision insurance (partial premium coverage for dependents)

Employer quarterly contributions to 401k funds

15 days accrued vacation

11 paid holidays

Bi-annual reviews, and annual pay increases

Health and wellness benefits, including free gym membership

Quarterly team-building event

At TP-Link Systems Inc., we are continually searching for ambitious individuals who are passionate about their work. We believe that diversity fuels innovation, collaboration, and drives our entrepreneurial spirit. As a global company, we highly value diverse perspectives and are committed to cultivating an environment where all voices are heard, respected, and valued. We are dedicated to providing equal employment opportunities to all employees and applicants, and we prohibit discrimination and harassment of any kind based on race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. Beyond compliance, we strive to create a supportive and growth-oriented workplace for everyone. If you share our passion and connection to this mission, we welcome you to apply and join us in building a vibrant and inclusive team at TP-Link Systems Inc.

Please, no third-party agency inquiries, and we are unable to offer visa sponsorships at this time.

Compensation

This Security Engineer role pays $150k-$180k/yr. Within typical range for security engineer roles in United States.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on TP-LINK's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Security Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United States medians across recent openings.

You never touch the form - the application is filled and submitted for you on TP-LINK's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.