Principal Security Engineer Cloud and Infrastructure Security
One Identity · India · 2026-10-07
About this role
Overview
Principal Security Engineer Cloud and Infrastructure Security
One Identity · Information Security, Attack Surface
Principal individual contributor · India · Reports to the Director of Information Security
Why this role exists
The architecture set in this role decides which certifications One Identity can hold and which markets we can sell into. That is unusual commercial weight for an engineering seat, and it comes with a mandate from leadership to build the program behind it.
We sell on-premises and hosted solutions. Some products run as hosted services we operate in Azure and AWS. Others ship as software customers deploy in their own datacenters. Infrastructure security here has two audiences: the environments we run, and the base images, container definitions, and deployment defaults we publish, which become part of every customer's environment. A hardening decision made once is inherited by everyone who deploys it.
We're separating from Quest Software and building an independent security function. The team is lean and globally distributed, and this role is its senior technical voice. Scope comes from what you design and automate, and from what engineering chooses to adopt.
What you'll do
Shape the architecture
• Own security architecture across Azure and AWS: tenant, subscription and account design, network segmentation and traffic control, private connectivity, egress policy, workload isolation. Where a regulated market or a certification constrains a design, you're expected to know before it's committed.
• Run our own products against real security requirements and tell us what you find. IT operates our privileged access controls on One Identity software, so you'll see how our products hold up under production pressure and take that back to the teams building them.
• Bring engineering into architectural decisions early. Designs teams help shape are the ones that hold up in production.
Raise the engineering bar
• Teams already build with infrastructure as code across both clouds. Raise the security ceiling inside that practice: hardened modules, secure-by-default landing zones and account baselines, and patterns teams reach for because they're better.
• Extend policy as code across the pipeline and the platform so teams get a signal at commit time.
• Own the hardened image pipeline for virtual machines and containers, covering the fleet we run and the images we publish: build, patch cadence, provenance, signing, and the automation that keeps both current.
• Secure the container orchestration layer, including the reference architecture and secure defaults customers inherit when they deploy our products on their own clusters.
• Set the security architecture for AI workloads: model and inference endpoint exposure, data boundaries and residency, identity for agents and service principals, secrets handling, and guardrails around AI tooling in the development lifecycle.
Reduce exposure and prove it
• Own infrastructure vulnerability and exposure management end to end: discovery, prioritization weighing exploitability and reachability alongside severity, ownership routing, remediation tracking, verification. Hosted services and customer-deployed software have different release paths and the practice accounts for both.
• Elevate cloud posture and workload protection into a single practice spanning Azure and AWS. You set the platform direction, the coverage standard both clouds are held to, and the path findings take to the teams that own them.
• Drive the decisions on where agentic workflows belong in security engineering: where automation acts and where it recommends, how its output gets verified, and what has to hold true before teams trust it. Where a person still has to act, the finding arrives with owner, fix path, and rationale. Where we can act ourselves, it arrives as a pull request against the module, image definition, or policy that produced it. PRs, not tickets.
• Build so control evidence can be produced by query. Cloud, configuration, and network controls are assessed under ISO 27001 and SOC 2 today, with IRAP, ACN and PCI self-assessment ahead. A portfolio that keeps growing makes hand-assembled evidence unsustainable.
What we're looking for
Required
Ten or more years in security engineering or infrastructure engineering, with substantial time in cloud architecture. Equivalent depth counts.
• Deep cloud security architecture experience across Azure and AWS. Real depth in one, working command of the other.
• Hands-on work securing AI workloads or AI-enabled tooling within the last six months. This area moves fast enough that older experience doesn't carry, and we'll ask specifically what you built and when.
• Something you built that engineering teams adopted and kept using.
The three above are the bar. Everything below is depth we'd like and can build. If you meet the requirements and bring most of the rest, apply. We'd rather assess the gap ourselves than have you decide it for us.
Also matters: enough seniority in infrastructure as code to improve on what strong teams already do; network security fundamentals applied to cloud, covering segmentation, private connectivity, egress control, and east-west traffic; container and Kubernetes security, image hardening, supply chain integrity, and secrets management; policy-as-code frameworks and a view on where enforcement belongs in the lifecycle; controls you designed that held up under an audit you were personally accountable for; judgment about which risks to carry and which to escalate.
Helpful: shipping software customers deploy themselves, FedRAMP or IRAP, a carve-out or large-scale cloud migration.
What you should know going in
This is a builder's seat with leadership behind it. You'll set the infrastructure security architecture for a newly independent company, with the backing to build a program rather than the job of holding one together. The work enables engineering directly and opens new…
Skills asked for
- azure
- aws
- rest
- kubernetes
Similar jobs
- Principal Cyber Security EngineerVertex Inc.
- Principal Security Field EngineerDatabricks
- Senior Principal Software Developer (AI Cybersecurity)Huntington National Bank
- Principal Security ArchitectMenlosecurity · Canada - Distributed
- Principal Linux Security EngineerCiq · Remote
- Principal Consulting Architect - Observability/Security - ANZElastic · Australia
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.