S

Staff Cloud Security Engineer

Scribd, Inc.

Toronto, Ontario, Canada · Full Time

Be the first to apply

Experience
10+ yrs
Salary
CAD 189,000 – CAD 225,000 / year
Openings
1
Posted
1 day ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Scribd, Inc.

Scribd, Inc. is dedicated to advancing global understanding through its suite of products including Scribd®, Slideshare®, Everand™, and Fable, impacting billions worldwide by transforming access into insight and expertise.

Culture at Scribd, Inc.

We foster a workplace where authenticity and bold ideas thrive. Our employees engage in thoughtful debates and embrace challenges while prioritizing customer centricity. Scribd Flex promotes a balance between flexible workstyles and meaningful face-to-face collaboration. Although we support flexibility, occasional in-person attendance is required of all employees.

We seek candidates who embody “GRIT”—a blend of passion and perseverance manifesting as setting clear goals, delivering results, contributing innovative solutions, and strengthening team dynamics.

Team and Role Overview

The Security Engineering team is responsible for protecting our cloud infrastructure and applications, integrating security early in the software development lifecycle. The Staff Cloud Security Engineer will lead strategic architectural initiatives to enhance security across AWS and GCP environments, focusing on identity, secure defaults, and workload protection. This role requires hands-on technical leadership, balancing architectural innovation with urgent security challenges.

Key Responsibilities

  • Enhance security architecture and guardrails across AWS and GCP, including account/project configurations, network and infrastructure standards.
  • Advance identity and access management with principles of least privilege, just-in-time access, short-lived credentials, and secure cross-account access.
  • Establish standards for secrets management, data encryption, and data protection, ensuring effectiveness and measurable coverage of controls.
  • Secure cloud workloads and deployment paths, focusing on Kubernetes, secure base images, runtime protection, and isolation of untrusted content services.
  • Collaborate with Infrastructure teams to secure deployment pipelines, workload identities, registries, and CI/CD infrastructure.
  • Develop reusable security capabilities such as Terraform modules and policy-as-code guardrails to enforce secure-by-default infrastructure deployments.
  • Improve cloud telemetry and detection coverage of cloud-native threats in collaboration with the Detection & Response team.
  • Conduct threat hunting, attack-path analyses, incident technical support, and transform learnings into security improvements.
  • Co-lead the Cloud Security strategy and roadmap, prioritize risks based on threat models and incidents, and balance security needs with engineering agility.
  • Guide and mentor technical teams, evaluate security tools, and communicate risks and progress to stakeholders.

Qualifications

  • Over 10 years of experience in cloud or infrastructure security engineering or a related blend of software and security engineering with hands-on work securing production cloud environments at scale.
  • Expertise primarily in AWS or GCP with sufficient knowledge in the other cloud platform to identify security risks.
  • Proven experience in shaping security architecture and influencing cross-team adoption of security standards without direct authority.
  • Deep knowledge in identity and access management, including least-privilege access, cross-account patterns, short-lived workload credentials (e.g., IRSA, OIDC federation), and service-to-service identity (e.g., mTLS, SPIFFE/SPIRE, service mesh).
  • Hands-on experience securing Kubernetes workloads, container security, runtime protections, and workload isolation.
  • Familiarity with cloud security posture management tools and workload protection (CSPM/CNAPP), translating security findings into prioritized improvements.
  • Experience designing cloud security guardrails, policy as code (e.g., AWS SCPs or OPA), secure infrastructure provisioning, and landing zone automation.
  • Strong Infrastructure-as-Code skills with tools like Terraform and programming languages such as Python or Go.
  • Proficiency with cloud security monitoring and response using tools like GuardDuty, Security Command Center, CloudTrail, or Cloud Audit Logs and integrating with SIEM platforms.
  • Proven track record of delivering tangible security improvements balancing technical depth and practical implementation.

Additional Information

This position offers a competitive base salary along with equity ownership and an extensive benefits package tailored to the candidate’s experience, skills, and specific location within North America.

Eligible primary residence locations for employment include specified cities in the United States, Canada, and Mexico, emphasizing proximity to major metro areas.

Benefits

  • Flexible work model via Scribd Flex
  • Comprehensive health, dental, and vision coverage
  • Mental health and disability support
  • Generous paid time off and parental leave policies
  • Retirement matching and equity participation
  • Learning and professional growth opportunities
  • Wellness and home office stipends
  • Free access to Scribd’s suite of products and enterprise AI tools

Commitment to Inclusion and Accessibility

Scribd is committed to equal employment opportunities and encourages candidates from diverse backgrounds to apply. Accommodations for accessibility needs during the interview process are available upon request. Personal information collected during the hiring process is managed according to Scribd’s Employee and Applicant Privacy Policy.

Tools & software

Amazon Web Services AWS required Terraform · 10+ years required

How they work

Teamwork & Collaboration Problem Solving Leadership Strategic Thinking

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer