Staff Cloud Security Engineer
San Jose, CA - USA
Job Summary
At Bloom Energy our vision for a world powered by clean reliable and affordable energy is more than just a dreamweremaking it reality.
For over two decadeswevebeen at the forefront of the global energy transition pioneering solutions that empower critical industries to thrive in a rapidly digitizing energy-intensive world. From revolutionizing power for AI-driven data centers to ensuring resilience for hospitals electric grids manufacturing facilities and utilities our solid oxide fuel cell (SOFC) and solid oxideelectrolyzer(SOEC) technologies are redefiningwhatspossible by delivering energy abundance for all. With more than 30000 fuel cell modules deployed worldwide we are the trusted partner for Fortune 100 companies and innovators alike. Ourcutting-edgesolutions enable unparalleled time-to-power capabilities reliability and sustainability ensuring our customersremainahead in a world where soaring energy demand and intensifying energy scarcity are rapidly becoming the new norm.
At Bloom we thrive on collaboration bold thinking and relentless innovation. We believe that together we can create a brighter more sustainable future while tackling the most pressing challenges of the 21st century.
We are looking for a Staff Cloud Security Engineerto join our team in one of todays most exciting role willreporttoSenior Manager Cloud Engineering and based inSan Jose CA.This is a fully on-site in officerole5 days a week.
CloudSecurityEngineering
Design implement automate and maintainsecurityarchitectures controls and processes across AWS and Microsoft Azure environments
Develop and maintaincloudsecurityreference architectures patterns and guardrails aligned with industry best practices and Bloom Energysecuritystandards
Build and operationalizesecuritybaseline controls integrated into CI/CD pipelines and Infrastructure-as-Code deployments
Implement policy-as-code and automated compliance validation acrosscloudenvironments
Review and approvesecurity-sensitive infrastructure and application changes including IAM policies networksecuritycontrols secrets management andcloud-native services
Serve as thecloudsecuritysubject matter expert supporting enterprisecloudtransformation initiatives across IaaS PaaS and SaaS platforms
AI & Machine LearningSecurity
Define and implementsecurityframeworks for AI/ML systems across the full model lifecycle including data ingestion model training deployment and monitoring
Assess and mitigate emerging AIsecurityrisks such as adversarial attacks prompt injection model theft model inversion and data poisoning
Secure AI/ML platforms and services including Amazon SageMaker Bedrock Azure Machine Learning OpenAI APIs and other enterprise AI tooling
Collaborate with AI engineering and data science teams to integratesecuritycontrols into MLOps pipelines and AI governance processes
Monitor evolving AI regulations standards and frameworks including NIST AI RMF and global AI governance initiatives translating them into actionable controls and engineering practices
DataSecurity
Implement and manage DataSecurityPosture Management (DSPM) capabilities to identify and reduce sensitive data exposure acrosscloudenvironments
Design and enforce controls for structured and unstructured data platforms including databases data lakes warehouses object storage and analytics platforms such as AWS S3.
Drive adoption of data-centricsecuritycontrols including encryption tokenization data classification retention and access governance
Partner with application and analytics teams to embed secure data handling practices into engineering workflows
SecurityArchitecture & Leadership
Provide deep technical expertise acrosscloud AI infrastructure identity and applicationsecuritydomains
Leadsecurityassessments and threat modeling exercises forcloudservices AI/ML platforms enterprise applications and emerging technologies
Enable secure innovation by partnering with engineering teams early in the design and development lifecycle
Support incident response investigation and remediation activities related tocloud AI and datasecurityevents
Collaborate closely with Information and OTSecurity Infrastructure Product Engineering and Enterprise Architecture teams to drive secure technology adoption across the organization
Contribute to the development ofsecuritystandards policies and operational procedures aligned with business and regulatory requirements
What You Bring
Mindset
Self-starter with strong ownership mentality and ability to manage multiple priorities in a dynamic environment
Passion for DevSecOps automation and engineering scalablesecuritysolutions
Strong curiosity and practical understanding of the evolving AI threat landscape and moderncloud-native technologies
Collaborative mindset with ability to work effectively across engineering infrastructure AI data andsecurityteams
Strong communication skills with the ability to influence technical and business stakeholders
Desire to continuously improvesecuritymaturity while enabling business agility and innovation
Qualifications
Required
Bachelors degree in computer science Engineering Information Technology Cybersecurity or related field
10 years of experience insecurityengineeringcloudsecurityarchitecture or cybersecurityoperations
Strong hands-on expertise with AWS and/or Microsoft Azuresecurityservices andcloud-native architectures
Experience implementingsecurityautomation within CI/CD and Infrastructure-as-Code environments
Deep understanding of IAM networksecurity encryption secrets management logging monitoring and threat detection
Experience securing enterprise data platforms and moderncloud-native applications
Strong knowledge ofsecurityframeworks and best practices including NIST CIS Zero Trust and secure SDLC principles
Preferred
Experience securing AI/ML platforms GenAI services or MLOps pipelines
Familiarity with AI governance AIsecurityrisks and emerging regulatory frameworks
Experience with DSPM CSPM CNAPP SIEM SOAR and moderncloudsecuritytooling
Securitycertifications such as CISSP CCSP CCSK AWS CertifiedSecuritySpecialty or Microsoft Certified: AzureSecurityEngineer Associate
Preferred additional certifications or training in AIsecurityor data privacy/securitydomains (e.g. CDPSE CIPP AIsecuritycertifications)
Bloom Energy is an equal opportunity employer and makes employment decisions on the basis of merit. We are committed to compliance with all applicable laws providing equal employment opportunities. All qualified applicants will receive consideration for employment without regard to race sex color religion national origin protected veteran status or on the basis of disability. Bloom Energy makes reasonable accommodations consistent with applicable laws for the known physical or mental limitations of an otherwise qualified applicant or employee with a disability who can perform the essential job functions unless undue hardship would result.
At Bloom Energy we are committed to supporting the well-being of our employees and their families. Our comprehensive benefits package for eligible employees includes competitive Medical Dental and Vision plans with a large employer contribution a 401(k) Retirement Plan with companymatch generousMental Health Support services Legal services virtual Physical Therapy access and Fertility & Family Forming benefits.
Bloom Energy is committed to fair andequitablecompensation practices.
FULL TIME ROLE ONLY:The total compensation for this position includes standard company benefits and is based onvarious factorsincluding but not limited to relevant skills and experience.
#LI-NP
Required Experience:
Staff IC
About Company
Bloom Energy’s leading solid-oxide platform for the distributed generation of electricity and hydrogen production is changing the future of energy.