Senior Cloud Security Engineer
Greystar · Remote
📍 Remote, United Statesvia workdayFirst listed here 2026-09-16
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Greystar.
ABOUT GREYSTAR
Greystar is a leading, fully integrated global real estate platform offering expertise in property management, investment management, development, and construction services in institutional-quality rental housing. Headquartered in Charleston, South Carolina, Greystar manages and operates over $350 billion of real estate in more than 260 markets globally with offices throughout North America, Europe, South America, and the Asia-Pacific region. Greystar is the largest operator of apartments in the United States, managing over one million units/beds globally. Across its platforms, Greystar has nearly $79 billion of assets under management, including over $34 billion of development assets and over $36.5 billion of regulatory assets under management. Greystar was founded by Bob Faith in 1993 to become a provider of world-class service in the rental residential real estate business. To learn more, visit www.greystar.com .
JOB DESCRIPTION SUMMARY
The Senior Cloud Security Engineer is Greystar's hands-on subject matter expert on cloud security with strategic direction driven from the Senior Director, Information Technology - the person other engineers, architects, and leaders turn to when a design decision needs an expert, defensible answer on cloud security. This is not a role that reviews security after the fact: you will define what "secure" means for Greystar's cloud environments, set the standards other engineers build against, and represent cloud security directly in architecture design reviews.
This is a builder's role - you'll be writing Terraform, configuring scanners, and fixing findings yourself, bringing deep technical execution to every part of the cloud estate you touch. You will partner closely with Information Security on enterprise architecture and identity standards, and with Cybersecurity Operations on detection tuning and incident response - bringing deep cloud-native expertise to those partnerships. You will also work directly with Greystar’s cloud Platform team engineers, Digital and AI developers, and Data Engineering team to make sure security is built into every design rather than bolted on afterward.
JOB DESCRIPTION
What You Will Do: Cloud Security Architecture & Standards
Define and own cloud security architecture patterns across c loud platforms - IAM guardrails, network segmentation, encryption standards, and secrets management - that the Infrastructure, Delivery, and Reliability tracks build against.
Own c loud Policy as code, including custom policy definitions, initiative assignments, and enforcement-mode governance across the c loud estate.
Establish secure-by-default reference patterns - landing zone security baseline, mandatory private endpoint use, default-deny network posture - in direct partnership with the Principal Cloud Engineer .
Partner with Information Security architecture so enterprise security policy translates correctly into cloud-native controls, acting as the translator of record between enterprise policy and cloud implementation.
Application, Pipeline & Supply-Chain Security
Build and configure security tooling directly into CI/CD pipelines - standing up IaC scanning, container image scanning, and SAST/DAST tools hands-on alongside the Delivery team .
Own supply-chain risk review for third-party CI/CD integrations (GitHub Actions, MCP servers, external connectors), partnering with the Senior DevOps Engineer on remediation.
Work hands-on with application development and AI/ML teams to harden new cloud-native and AI workloads before they ship - configuring network isolation, securing model endpoints and API keys, and directly fixing findings during the build.
Personally triage and remediate critical pipeline findings, working directly in the codebase or configuration with engineering teams to fix root causes.
Identity & Access Security (Cloud-Specific)
Define least-privilege RBAC and conditional access standards for cloud resources, partnering with Cloud Engineering on execution against established naming and group-based delegation conventions.
Own the just-in-time / privileged identity model for privileged cloud roles.
Own recurring access reviews and offboarding validation for service principals, managed identities, and human RBAC assignments across the cloud estate.
Detection, Response & Operations
Partner with Cybersecurity Operations to tune Defender for Cloud recommendations and Sentinel analytics rules for cloud-specific signal , reducing noise and closing detection gaps as new services and connectors come online.
Recommend and help prioritize which cloud workloads and connectors get phased into Sentinel next, based on risk and blast radius across the estate.
Contribute cloud-specific escalation criteria to the runbooks the Operations Command Center and Cybersecurity Operations execute against.
Deliver initial and ongoing training to Cybersecurity Operations on cloud-native anomalies - managed identity misuse, unusual resource provisioning, anomalous Entra ID sign-ins - so detection and tuning quality improve over time.
Governance, Risk & Compliance
Actively work down the CSPM and vulnerability backlog - rewriting Terraform to close a misconfiguration, migrating a plaintext secret to Key Vault, reconfiguring an identity - personally closing critical and high findings.
Map cloud infrastructure controls to relevant compliance frameworks (SOC 2, PCI, CIS Benchmarks) in partnership with enterprise Information Security, translating framework language into actual Azure/AWS configuration.
Architecture Review & Technical Authority
Serve as the primary cloud security voice in cloud architecture design reviews across Infrastructure, Application Development, and Data Engineering, providing the security assessment that informs whether a design moves forward.
Maintain security documentation, reference architecture
More Remote jobs
Remote jobs · Browse all locations