S

Staff Cloud Security Engineer

Scribd, Inc.

Vancouver, British Columbia, Canada · Full Time

Be the first to apply

Experience
10+ yrs
Salary
CAD 189,000 – CAD 225,000 / year
Openings
1
Posted
2 days ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Scribd, Inc.

Scribd, Inc. is dedicated to advancing human comprehension through its products—Scribd®, Slideshare®, Everand™, and Fable—which collectively assist billions globally to move from access to insight and expertise.

Culture

We foster an environment encouraging authenticity and boldness, where discussions and commitments embrace change, and employees are empowered to act with the customer as the priority. Our flexible work model, Scribd Flex, allows team members to select work styles and locations optimal for their performance, while maintaining essential in-person collaboration to strengthen community and culture. All employees occasionally attend on-site meetings regardless of their location.

Our Values – GRIT

We value "GRIT," representing passion and perseverance towards long-term goals. This mindset guides our work, focusing on setting and achieving objectives, delivering results, innovating solutions, and collaborating positively to strengthen our team.

Team and Role

The Security Engineering team safeguards Scribd's applications and cloud infrastructure by embedding security proactively throughout the software development lifecycle. Collaborating closely with software, infrastructure, and product teams, the group identifies and mitigates security risks, builds controls, and assists engineering teams in secure operations.

As a Staff Cloud Security Engineer, you will guide the technical direction of cloud security, spearhead major architectural projects across AWS and GCP platforms, enhance identity models, establish secure default practices, and safeguard application workloads.

This position requires hands-on technical leadership involving initiative ownership, capability development, and influencing engineering teams to implement security practices balancing architectural refinement and urgent security priorities.

Key Responsibilities

  • Develop and refine cloud security architecture and guardrails for AWS and GCP, covering account/project configurations, network defenses, and infrastructure standards.
  • Enhance identity and access management with policies enforcing least privilege, just-in-time access, ephemeral workload credentials, and secure cross-account methods.
  • Define and improve standards for secrets management, data security, and encryption ensuring robust and verifiable controls.
  • Architect security solutions for cloud workloads, including Kubernetes, container security, runtime defense, and isolation strategies to reduce impact risks.
  • Collaborate with infrastructure teams to ensure secure cloud deployment, workload identities, registries, and CI/CD environment protections.
  • Create reusable secure infrastructure capabilities such as Terraform modules and policy-as-code guardrails to enforce compliance pre-deployment.
  • Specify cloud telemetry and enhance threat detection in cooperation with Detection & Response teams.
  • Validate security controls through threat hunting and incident involvement, converting insights into lasting system enhancements.
  • Lead cloud security roadmap development with managers and engineers, prioritizing risks based on threat models and incidents.
  • Champion security standards across engineering teams, provide technical mentorship, and communicate security risks and progress.

Required Qualifications

  • Over 10 years in cloud or infrastructure security engineering or a blend of software and security engineering experience securing large-scale cloud environments.
  • Expertise in AWS or GCP security with strong familiarity in the alternate provider.
  • Proven experience shaping security architecture and leading cross-team initiatives, influencing security adoption without formal authority.
  • Extensive hands-on knowledge of identity and access management, including least-privilege strategies, cross-account access, short-lived credentials (e.g., IRSA, OIDC), and service-to-service authentication (e.g., mTLS, SPIFFE). Experience minimizing long-lived credentials.
  • Experience securing Kubernetes and containerized cloud workloads with runtime protection and workload isolation.
  • Familiarity with cloud security posture management, CNAPP, CSPM tools, evaluating findings, attack path analysis, and addressing prioritized vulnerabilities.
  • Design and implementation experience of cloud security guardrails at scale, including security baselines, policy-as-code like AWS SCPs or OPA, infrastructure provisioning, and landing zone automation.
  • Strong Infrastructure-as-Code skills with tools such as Terraform and proficiency in programming languages such as Python or Go.
  • Knowledge of cloud-native security monitoring tools like GuardDuty, Security Command Center, CloudTrail, Cloud Audit Logs, SIEM integration, and how to translate incident insights into preventative improvements.
  • Demonstrated success delivering impactful security improvements balancing depth, architectural judgment, and practical execution.

Compensation

Salary is determined regionally and based on various factors such as experience and skills. In Canada, the salary range is from 189000 CAD to 225000 CAD annually. This role also offers equity ownership and a comprehensive benefit package.

Work Location Requirements

Employees must reside in or near designated cities in the United States, Canada, or Mexico, including Vancouver, BC, Canada.

Employee Benefits

  • Flexible work model supporting balance and collaboration
  • Health, dental, and vision insurance
  • Mental health and disability support
  • Generous paid time off including vacations, holidays, and sabbaticals
  • Parental leave and family support
  • Retirement matching and employee equity
  • Opportunities for learning and career development
  • Wellness and home office stipends
  • Free access to the Scribd suite of products and enterprise AI tools

Equal Opportunity and Inclusivity

Scribd promotes equal employment opportunities regardless of race, color, religion, national origin, gender, sexual orientation, age, marital status, veteran status, disability, or any other protected characteristic. We actively encourage diverse applicants and foster a respectful and inclusive work environment.

Candidate Support

Applicants who require accommodation during the hiring process can request adjustments at any stage by contacting the company for support.

How they work

Communication Teamwork & Collaboration Problem Solving Leadership Creativity

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer