hirq
← All jobs

Scribd, Inc.

Staff Cloud Security Engineer

San Francisco · On-site · FullTime · Engineering

Apply well, not just fast

Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.

About the role

Cloud SecurityAWSGCPKubernetesTerraformIAMCADPythonGoCI/CDSIEMMentoring
Scribd, Inc. is on a mission to advance human understanding. Our four products — Scribd®, Slideshare®, Everand™, and Fable — help billions of people across the globe move beyond access and into insight, application, and expertise. CULTURE AT SCRIBD, INC. We support a culture where our employees can be real and be bold; where we debate and commit as we embrace plot twists; and where every employee is empowered to take action as we prioritize the customer. We believe the best work happens when individual flexibility is balanced with meaningful community connection. Scribd Flex empowers employees to choose the workstyle and location that support their best performance, while committing to intentional in-person moments that strengthen collaboration and culture. Occasional in-person attendance is required for all Scribd, Inc. employees, regardless of location. So what are we looking for in new team members? At Scribd, Inc., we hire for “GRIT.” Traditionally defined as the intersection of passion and perseverance toward long-term goals, GRIT reflects the mindset we expect from every employee. For us, it also serves as a practical framework for how we work: setting and achieving Goals, delivering Results within your role, contributing Innovative ideas and solutions, and strengthening the broader Team through collaboration and attitude. This posting reflects an approved, open position within the organization. ABOUT THE TEAM AND ROLE Our Security Engineering team protects Scribd's applications and cloud infrastructure. We take a proactive, shift-left approach, integrating security throughout the software development lifecycle, from development through production. We work closely with software engineers, infrastructure and platform teams, and product teams to identify and address security risks, build effective security controls, and enable engineering teams to move securely. As a Staff Cloud Security Engineer, you'll help shape the technical direction of Cloud Security and drive complex architectural investments across our AWS and GCP environments. You'll work closely with engineers already building our cloud security capabilities to strengthen our identity model, establish secure-by-default guardrails, and protect the workloads our applications run on. This is a hands-on technical leadership role. You'll lead significant initiatives, build security capabilities, and influence engineering teams to adopt them, balancing long-term architectural improvements with the most pressing security risks. WHAT YOU'LL DO Set the Cloud Security architecture - Strengthen and evolve security architecture and guardrails across our AWS and GCP environments, including account and project configuration, network security, and infrastructure standards. - Strengthen identity and access management across our cloud environments, driving least privilege, just-in-time access, short-lived workload credentials, and secure cross-account access. - Define and improve secrets management, data protection, and encryption standards, ensuring security controls are effective and their coverage can be demonstrated. Secure cloud workloads and delivery paths - Drive security architecture and guardrails for cloud workloads, including Kubernetes, secure base images, workload identity, runtime protection, and isolation of services processing untrusted content, with an emphasis on limiting the impact of compromise. - Partner with our Infrastructure teams to secure cloud deployment paths, workload identities, registries, and the infrastructure supporting CI/CD. - Build reusable security capabilities and paved paths, including Terraform modules and policy-as-code guardrails, that make secure configurations the default and prevent noncompliant infrastructure changes before deployment. Strengthen cloud visibility and resilience - Define cloud telemetry requirements and improve detection coverage for cloud-native threats in partnership with Detection & Response. - Validate cloud security controls through threat hunting and attack-path analysis, contribute technical expertise during incidents, and partner with infrastructure teams on containment and recovery architecture, translating incident learnings into durable improvements. Drive Cloud Security strategy and technical direction - Shape and drive the Cloud Security technical roadmap alongside the Security Engineering manager and engineers in the domain, using threat models, incidents, and control effectiveness to prioritize systemic risks while balancing security outcomes with engineering friction. - Lead complex technical initiatives, establish and evolve security standards, and influence their adoption across engineering teams. - Provide technical guidance and mentorship, contribute to tooling evaluations, and proactively communicate Cloud Security risks, progress, and direction to stakeholders. WE'RE LOOKING FOR SOMEONE WHO HAS - 10+ years of experience with significant depth in cloud or infrastructure security engineering, or an equivalent blend of software and security engineering, with hands-on experience securing production cloud environments at scale. Deep expertise in at least one of AWS or GCP, with sufficient fluency in the other to reason about security risks. - Experience shaping security architecture and leading initiatives across team boundaries, including influencing engineering teams to adopt security standards and controls without formal authority. - Deep hands-on identity and access management expertise, including least-privilege access, cross-account access patterns, short-lived workload credentials (e.g., IRSA, OIDC federation), and service-to-service identity and authorization (e.g., mTLS, SPIFFE/SPIRE, or service mesh identity models), with experience reducing standing access and long-lived credentials. - Experience securing cloud workloads, including Kubernetes, container security, runtime protection, and workload isolation. - Experience with cloud security posture management and workload protection, including CSPM/CNAPP platforms, evaluating security findings, identifying attack paths, and translating them into prioritized improvements. - Experience designing and implementing cloud security guardrails at scale, including account or project security baselines, policy-as-code (e.g., AWS SCPs or OPA), secure infrastructure provisioning, and landing zone automation. - Strong Infrastructure-as-Code and automation skills, including Terraform or equivalent tooling and proficiency in a programming language such as Python or Go. - Experience with cloud security visibility and response, including cloud-native security tooling (e.g., GuardDuty, Security Command Center, CloudTrail, or Cloud Audit Logs), detection capabilities, SIEM integration, and applying incident learnings to improve preventive and detective controls. - A track record of delivering measurable security improvements, balancing technical depth, architectural judgment, and hands-on execution. ---------------------------------------------------------------------------------- At Scribd, Inc., your base pay is one part of your total compensation package and is determined within a range. Our pay ranges are based on the local cost of labor benchmarks for each specific role, level, and geographic location. San Francisco is our highest geographic market in the United States.   In the state of California, the reasonably expected salary range is between $179,000 [minimum salary in our lowest geographic market within California] to $255,000 [maximum salary in our highest geographic market within California].   In the United States, outside of California, the reasonably expected salary range is between $147,000 [minimum salary in our lowest US geographic market outside of California] to $242,000 [maximum salary in our highest US geographic market outside of California].   In Canada, the reasonably expected salary range is between $189,000 CAD[minimum salary in our lowest geographic market] to $225,000 CAD[maximum salary in our highest geographic market].   We carefully consider a wide range of factors when determining compensation, including but not limited to experience; job-related skill sets; relevant education or training; and other business and organizational needs. The salary range listed is for the level at which this job has been scoped. In the event that you are considered for a different level, a higher or lower pay range would apply. This position is also eligible for a competitive equity ownership, and a comprehensive and generous benefits package. WORKING AT SCRIBD, INC. Are you currently based in a location where Scribd, Inc. can employ you? Employees must have their primary residence in or near one of the following cities. This includes surrounding metro areas or locations within a typical commuting distance: United States: Atlanta | Austin | Boston | Dallas | Denver | Chicago | Houston | Jacksonville | Los Angeles | Miami | New York City | Phoenix | Portland | Sacramento | Salt Lake City | San Diego | San Francisco | Seattle | Washington D.C. Canada: Ottawa | Toronto | Vancouver Mexico: Mexico City Benefits at Scribd, Inc. - Scribd Flex (flexible work model) - Comprehensive health, dental, and vision coverage - Mental health support and disability coverage - Generous paid time off, including vacation, sick time, holidays, winter break, volunteer time, and sabbaticals - Paid parental leave and family support benefits - Retirement matching and employee equity - Learning and development programs and professional growth opportunities - Wellness and home office stipends - Complimentary access to the Scribd, Inc. suite of products - Enterprise access to leading AI tools Get to Know Scribd, Inc. About Scribd, Inc. https://www.scribdinc.com/about Life at Scribd, Inc. https://bit.ly/ScribdonLinkedin We want our interview process to be accessible to everyone. You can inform us of any reasonable adjustments we can make to better accommodate your needs by emailing [email protected] about the need for adjustments at any point in the interview process. If you apply for a job with Scribd, Inc. or otherwise engage with us in connection with employment (including as an employee, contractor, or other personnel), the personal information we process in that context is subject to our Employee and Applicant Privacy Policy, which is available here https://support.scribd.com/hc/en-us/articles/49754646187284-Employee-and-Applicant-Privacy-Policy-and-Notice-at-Collection. Scribd, Inc. is committed to equal employment opportunity regardless of race, color, religion, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or any other characteristic protected by law. We encourage people of all backgrounds to apply, and believe that a diversity of perspectives and experiences create a foundation for the best ideas. Come join us in building something meaningful.