11 days ago

Logo of Arctic Wolf

Principal Cloud Security Developer

Arctic Wolf

RemoteUSCanada

At Arctic Wolf, were not just navigating the cybersecurity landscape - were redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: weve earned recognition on the Forbes Cloud 100, CNBC Disruptor 50, Fortune Future 50, and Fortune Cyber 60 lists, and we recently took home the 2024 CRN Products of the Year award. We’re proud to be named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services and earning a Customers Choice distinction from Gartner Peer Insights. Our Aurora Platform also received CRN’s Products of the Year award in the inaugural Security Operations Platform category. Join a company that’s not only leading, but also shaping, the future of security operations.

Our mission is simple: End Cyber Risk. We’re looking for a Principal Cloud Security Developer​ be part of making this/that happen.  

The Principal Cloud Security Developer will contribute to our Product Security Engineering department by leading initiatives that enhance the protection and detection capabilities of Arctic Wolf’s cloud infrastructure, with a strong focus on automation, scalability, and operational excellence across AWS (and soon Azure and GCP).

As a Principal Cloud Security Developer, you will be the brains and backbone of the Cloud Security team, strongly focused on ensuring the security of the Arctic Wolf infrastructure via all available means and channels. This is a hands-on position with a strong focus on raising the bar for Cloud Security throughout the organization. You will work largely within an “everything-as-code Amazon Web Services based environment with a small but growing footprint in Azure.
 

The focus of this role is on helping identify, champion, and ensure improvements to our ability to Protect and Detect across our infrastructure and product - defining, deploying, managing and improving the use and usability of both cloud-based and other infrastructure security tooling
 

In addition, you will lead the effort to continuously improve and simplify access control throughout our Cloud environments, with work largely focused on AWS IAM and CloudTrail Lake, along with custom tooling to enable least-privilege and just-in-time access. You will frequently work collaboratively with other organizations - representing the team, driving our security requirements, and advocating for our strategic/tactical goals. You will act as a leader as well as a Subject Matter Expert and be extensively involved in our strategy and planning.

Finally, you will help get to the root of security risks and events at Arctic Wolf - acting as the key contributor for high impact incidents, engaging with teams to support design improvements, pushing vendors to implement tooling improvements, and always looking at how we can automate away toil.

In your first six months, you might:

  • Get comfortable in our AWS environment and help us branch out to include Azure and GCP, as well as move forward our security posture in other platforms like Kubernetes.

  • Identify a gap, then define, deploy and operationalize a new Amazon Web Services security service or feature using Infrastructure as Code

  • Research and enable new features, operationalize, and grow usage of new and existing security tooling

  • Act as a Subject Matter Expert in response to infrastructure security events and incidents, follow up with Root Cause Analysis and help stop repeats

  • Automate reporting and remediation of security findings through tools like EventBridge, Lambda, Jira, Slack, Security Hub, and Defender for Cloud

  • Improve automation, data collection, reporting, usability, or add features around Access Control

  • Lead technical aspects of certifications. For example, FedRAMP, CMMC, PCI, or SOC2

  • Lead the improvement of security in a problem domain (host based, containers, Identity Access Management, Lambda, APIs, etc.)

  • Drive understanding and remediation of risks throughout our cloud infrastructure

  • Define and lead improvements to CI/CD to improve guardrails and gates to production

Your responsibilities:

  • Take ownership of strategic problems, work with internal security teams, engineering staff, and product functions to deliver actionable solutions that will lower risk

  • Stay current on the cloud security landscape, advocate for useful advances, and help set and implement security direction

  • Define and maintain our security toolset, ensuring that it is scalable and automated

  • Drive improved security monitoring for platforms, infrastructure, and code

  • Support remediation of infrastructure security problems across our range of products

  • Build significant automation to remove the operational toil for the Cloud Security and other teams

  • Help set the direction for cloud security initiatives by improving business intelligence tools and driving a reduction in risk throughout the organization

Technical Skills:

  • Extensive experience with major projects in AWS, particularly using AWS security services such as GuardDuty, CloudTrail, IAM Access Analyzer, IAM, Security Hub

  • Extensive experience with major projects in Azure, particularly using Azure security services such as Azure Monitor, Entra ID, and Defender for Cloud

  • Experience with multiple projects focused on using IaC (CloudFormation, Resource Manager, Terraform) to manage and deploy services

  • Significant experience with programming languages (Python, Go) and libraries (boto3, troposphere)

  • Comfortable working with AWS Lambda - writing, deployment, operations

  • Comfort with CI/CD systems, particularly automating security checks and integrations with other tools

What sets you apart:

  • Passion for automation and removing operational overhead

  • Self-driven and collaborative, able to work across teams and levels

  • Strong communicator and clear documentation advocate

  • Strategic thinker comfortable in ambiguity, able to drive vision to execution

  • Experienced in production-grade services and cloud security operations

Bonus if you have:

  • Multi-region/multi-cloud battle scars

  • Cloud certifications (AWS, Azure, GCP)

  • Big Data or pipeline experience

  • Networking/security protocol knowledge (e.g., DNS)

Tech Stack You’ll Touch:
AWS (Security Hub, GuardDuty, Lambda, EKS, Terraform), Kubernetes, Docker, Kafka, Prometheus, Go, Python, GitHub Actions, Harness, Azure, GCP.

About Arctic Wolf

At Arctic Wolf, we foster a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture. This is reflected in our multiple awards, including Top Workplace USA (2021-2024), Best Places to Work – USA (2021-2024), Great Place to Work – Canada (2021-2024), Great Place to Work – UK (2024), and Kununu Top Company – Germany (2024). Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction, with over 7,000 customers worldwide and more than 2,000 channel partners globally. As we continue to expand globally and enhance our technology, Arctic Wolf remains the most trusted name in the industry. 

 

Our Values 

Arctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day. We believe in diversity and inclusion, and truly value the unique qualities and unique perspectives all employees bring to the organization. And we appreciate that—by protecting people’s and organizations’ sensitive data and seeking to end cyber risk— we get to work in an industry that is fundamental to the greater good. 

 

We celebrate unique perspectives by creating a platform for all voices to be heard through our Pack Unity program. We encourage all employees to join or create a new alliance. See more about our Pack Unity here.  

 

We also believe and practice corporate responsibility, and have recently joined the Pledge 1% Movement, ensuring that we continue to give back to our community. We know that through our mission to End Cyber Risk we will continue to engage and give back to our communities. 

 

All wolves receive compelling compensation and benefits packages, including: 

  • Equity for all employees 

  • Flexible time off and paid volunteer days 

  • RRSP and 401k match 

  • Training and career development programs 

  • Comprehensive private benefits plan including medical, mental health, dental, disability, life and AD&D, and value-added services 

  • Robust Employee Assistance Program (EAP) with mental health services 

  • Fertility support and paid parental leave 

Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, provincial, or local law. Arctic Wolf is committed to fostering a welcoming, accessible, respectful, and inclusive environment ensuring equal access and participation for people with disabilities. As such, we strive to make our entire employee experience as accessible as possible and provide accommodations as required for candidates and employees with disabilities and/or other specific needs where possible. Please let us know if you require any accommodations by emailing recruiting@arcticwolf.com. 

 

Security Requirements 

  • Conducts duties and responsibilities in accordance with AWN’s Information Security policies, standards, processes and controls to protect the confidentiality, integrity and availability of AWN business information (in accordance with our employee handbook and corporate policies). 

  • Background checks are required for this position. 

  • This position may require access to information protected under U.S. export control laws and regulations, including the Export Administration Regulations (“EAR”).  Please note that, if applicable, an offer for employment will be conditioned on authorization to receive software or technology controlled under these U.S. export control laws and regulations.