About this role.
LastPass seeks a principal-level cloud security engineer to define and scale cloud security architecture, standards, and controls across its product and infrastructure environment. The role partners closely with DevOps, CI/CD, platform, architecture, and trust and security teams to embed secure-by-design and shift-left practices. Core technical requirements include AWS security services, infrastructure as code, GitLab CI, Kubernetes/EKS, containers, admission controls, and software supply-chain security. This UK-remote position combines hands-on security engineering with strategic technical leadership and risk trade-off decisions. The successful candidate will continuously improve cloud and Kubernetes posture management while supporting compliance and audit requirements.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
5/5Pace & Pressure
4/5Autonomy Level
5/5Communication Load
5/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would establish a layered baseline covering identity, network segmentation, encryption, logging, configuration monitoring, and incident response. I would codify guardrails through infrastructure as code, AWS Organizations policies, IAM patterns, Config rules, and automated remediation, while providing reusable secure modules that make the compliant path the easiest path for teams.
I would prioritize automated, actionable checks at the earliest useful point: IaC scanning, secret detection, dependency and container scanning, policy-as-code, and signed-artifact verification. Findings should be risk-ranked with clear remediation guidance, initially using visibility and developer education before enforcing carefully selected blocking controls for critical risks.
I would use least-privilege IAM roles for service accounts, restrictive network policies, hardened pod security standards, image provenance and scanning, admission policies, encrypted secrets, and centralized audit logging. I would also continuously assess cluster posture, keep versions patched, and integrate runtime detection to identify suspicious workload behavior.
I would clarify the data sensitivity, threat scenarios, exposure duration, and compensating controls, then quantify the residual risk in language the stakeholders can use. If immediate delivery is necessary, I would document a time-bound exception with accountable ownership, monitoring, mitigations, and a committed remediation date rather than accepting an open-ended risk.
I would inventory identities, roles, policies, trust relationships, and actual permission usage using CloudTrail and access-analysis data. I would identify high-risk privileges and unused permissions, replace broad policies with role-specific least-privilege policies, enforce stronger guardrails, and roll out changes incrementally with testing and stakeholder coordination to avoid production disruption.
About LastPass
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, LastPass blends strong security with everyday simplicity. From discovering unapproved AI and applications to reducing login friction and securing credentials across the business, LastPass delivers on its mission to give everyone seamless access to everything they need to work, move fast, and stay protected as their environments evolve.
Curious about our products? Visit our website and try it free!
We welcome new ideas, support your growth, and recognize your value, if this aligns with what you are looking for in your next career move, Join Us!
LastPass is looking for a Principal Cloud Security Engineer:
As a Principal Cloud Security Engineer at LastPass, you will partner with DevOps and CI/CD engineers and our Architects team to ensure security best practices are embedded across our cloud infrastructure. We are looking for an experienced security engineering leader with an ability to scale security and make the right trade-off decisions that enable us to offer secure, innovative solutions to customers.
About the team:
The Cloud Security team at LastPass is a collaborative group of talented cloud security engineers working in close partnership with our engineering, platform, and trust & security teams. We are on a mission to safeguard the privacy and security of our company and users’ data, embedded directly in the heart of our product development.
If you are passionate about complex problem solving and motivated by scale, then this is the role for you!
Who will you work with?
You will work closely with DevOps and CI/CD engineers, Cloud Architects, and cross-functional engineering teams across LastPass. You will also collaborate with our Trust & Security and Platform teams, acting as a key embedded security partner throughout the product and infrastructure development process to drive secure-by-design outcomes at every stage.
What are some of the exciting challenges you will be working on?
- Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization
- Use your knowledge of security architecture to help engineers build and securely operate products and services from the ground up
- Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements
- Perform proactive research to identify new threats and attack vectors
- Partner with engineering teams to embed shift-left security practices throughout the software development lifecycle
- Implement and manage cloud and Kubernetes security posture management tooling to continuously monitor and reduce risk across containerized workloads
What does it take to work at LastPass?
- Proven experience working with AWS and AWS security services in a secure production environment, including IAM, Config, KMS, Secrets Manager, CloudWatch, CloudTrail, and GuardDuty
- Proven experience working closely with engineering teams and supporting them on their path to shifting security left
- Background with infrastructure as code (AWS CDK, CloudFormation, or Terraform), version control and CI tools such as GitLab and GitLab CI
- Hands-on experience with Kubernetes (AWS EKS), containers (Docker, AWS ECS), K8s admission controllers and Supply Chain Security
- Solid understanding of internet and computer network protocols, including TCP/IP, TLS, and VPN
- Good written and verbal communication skills in English
- Collaborative team player with a hands-on, can-do approach to problem solving
It’s great, but not required:
- AWS Certified Security – Specialty certification or similar.
- General familiarity with AI tools and large language models (e.g., Claude by Anthropic, AWS Bedrock)
Why LastPass?
- The leader in secure access
- High-growth, collaborative environment with inclusive teams
- Remote-first culture
- Competitive compensation
- Flexible Paid Time Off policies, including but not limited to: Quarterly Self-Care Days (4 extra paid days off annually) and Volunteer Days
- Parental leave
- Comprehensive health coverage, including dependents
- Home office setup support
- LastPass Families free account for up to 5 members
- Continuous learning and development opportunities, including an annual learning stipend to invest in your growth
- Peer-to-peer recognition through Motivosity
- Employee Assistance Program for well-being support
- Remote work stipend to support your home office needs
- Short-Term or Remote-Centric Work Arrangements for added flexibility
Unlock your potential with us – your skills, experience, and unique perspective matter more than just checking the boxes. Apply today, and let’s build the future together!
We’re building an inclusive community that reflects the people of all races, genders, sexual orientations, national origins, backgrounds, and perspectives who share our world.
For more information about how we process your personal data and your rights, please refer to our Candidate Privacy Notice.
Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.






