[All remote jobs](https://jobicy.com/jobs.md)Open role[![LastPass logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13842160-221.png)](https://jobicy.com/company/lastpass.md)Remote opportunity at[LastPass](https://jobicy.com/company/lastpass.md)

# Principal Cloud Security Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/lastpass.md)Share27 Aug 2026Published32Listing views1Application actions26 Sep 2026Apply before  Opportunity details

## About this role.

AI SummaryLastPass seeks a principal-level cloud security engineer to define and scale cloud security architecture, standards, and controls across its product and infrastructure environment. The role partners closely with DevOps, CI/CD, platform, architecture, and trust and security teams to embed secure-by-design and shift-left practices. Core technical requirements include AWS security services, infrastructure as code, GitLab CI, Kubernetes/EKS, containers, admission controls, and software supply-chain security. This UK-remote position combines hands-on security engineering with strategic technical leadership and risk trade-off decisions. The successful candidate will continuously improve cloud and Kubernetes posture management while supporting compliance and audit requirements.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a principal-level role requiring deep, practical AWS and Kubernetes security expertise alongside the ability to establish organization-wide architectures and influence multiple engineering teams. The engineer must make high-impact risk trade-offs while translating security requirements into scalable developer-friendly controls.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$195,000US market range$165k–$230k0$253k

AI insightNo actual salary range is disclosed; "competitive compensation" is not a quantifiable salary statement. The figures shown are estimated US-market annual base-salary benchmarks in USD for a principal cloud security engineer, recognizing that the listed role is UK remote and actual UK compensation may differ materially by employer, location, bonus, and equity.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[AWS security](https://jobicy.com/jobs?search_keywords=AWS%20security.md)[Cloud security architecture](https://jobicy.com/jobs?search_keywords=Cloud%20security%20architecture.md)[Kubernetes security](https://jobicy.com/jobs?search_keywords=Kubernetes%20security.md)[Amazon EKS](https://jobicy.com/jobs?search_keywords=Amazon%20EKS.md)[Infrastructure as code](https://jobicy.com/jobs?search_keywords=Infrastructure%20as%20code.md)[Terraform](https://jobicy.com/jobs?search_keywords=Terraform.md)[CI/CD security](https://jobicy.com/jobs?search_keywords=CICD%20security.md)[GitLab CI](https://jobicy.com/jobs?search_keywords=GitLab%20CI.md)[Container security](https://jobicy.com/jobs?search_keywords=Container%20security.md)[Software supply-chain security](https://jobicy.com/jobs?search_keywords=Software%20supply-chain%20security.md)

Sample interview questionsHow would you design a cloud security baseline for AWS accounts used by multiple product engineering teams?I would establish a layered baseline covering identity, network segmentation, encryption, logging, configuration monitoring, and incident response. I would codify guardrails through infrastructure as code, AWS Organizations policies, IAM patterns, Config rules, and automated remediation, while providing reusable secure modules that make the compliant path the easiest path for teams.

How do you embed shift-left security in a CI/CD workflow without creating excessive delivery friction?

I would prioritize automated, actionable checks at the earliest useful point: IaC scanning, secret detection, dependency and container scanning, policy-as-code, and signed-artifact verification. Findings should be risk-ranked with clear remediation guidance, initially using visibility and developer education before enforcing carefully selected blocking controls for critical risks.

What controls would you implement to secure Kubernetes workloads on EKS?

I would use least-privilege IAM roles for service accounts, restrictive network policies, hardened pod security standards, image provenance and scanning, admission policies, encrypted secrets, and centralized audit logging. I would also continuously assess cluster posture, keep versions patched, and integrate runtime detection to identify suspicious workload behavior.

Describe how you would evaluate a security trade-off when a product team needs to launch quickly.

I would clarify the data sensitivity, threat scenarios, exposure duration, and compensating controls, then quantify the residual risk in language the stakeholders can use. If immediate delivery is necessary, I would document a time-bound exception with accountable ownership, monitoring, mitigations, and a committed remediation date rather than accepting an open-ended risk.

How would you investigate and improve an overly permissive IAM environment?

I would inventory identities, roles, policies, trust relationships, and actual permission usage using CloudTrail and access-analysis data. I would identify high-risk privileges and unused permissions, replace broad policies with role-specific least-privilege policies, enforce stronger guardrails, and roll out changes incrementally with testing and stakeholder coordination to avoid production disruption.

About LastPass
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, LastPass blends strong security with everyday simplicity. From discovering unapproved AI and applications to reducing login friction and securing credentials across the business, LastPass delivers on its mission to give everyone seamless access to everything they need to work, move fast, and stay protected as their environments evolve.

Curious about our products? Visit our website and [try it free!](https://www.lastpass.com/products/personal?utm_campaign=glb-b2c-mkr-jbap&utm_medium=referral&utm_source=greenhouse)

We welcome new ideas, support your growth, and recognize your value, if this aligns with what you are looking for in your next career move, Join Us!

LastPass is looking for a Principal Cloud Security Engineer:

As a Principal Cloud Security Engineer at LastPass, you will partner with DevOps and CI/CD engineers and our Architects team to ensure security best practices are embedded across our cloud infrastructure. We are looking for an experienced security engineering leader with an ability to scale security and make the right trade-off decisions that enable us to offer secure, innovative solutions to customers.

About the team:

The Cloud Security team at LastPass is a collaborative group of talented cloud security engineers working in close partnership with our engineering, platform, and trust & security teams. We are on a mission to safeguard the privacy and security of our company and users’ data, embedded directly in the heart of our product development.

If you are passionate about complex problem solving and motivated by scale, then this is the role for you!

Who will you work with?

You will work closely with DevOps and CI/CD engineers, Cloud Architects, and cross-functional engineering teams across LastPass. You will also collaborate with our Trust & Security and Platform teams, acting as a key embedded security partner throughout the product and infrastructure development process to drive secure-by-design outcomes at every stage.

What are some of the exciting challenges you will be working on?

* Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization
* Use your knowledge of security architecture to help engineers build and securely operate products and services from the ground up
* Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements
* Perform proactive research to identify new threats and attack vectors
* Partner with engineering teams to embed shift-left security practices throughout the software development lifecycle
* Implement and manage cloud and Kubernetes security posture management tooling to continuously monitor and reduce risk across containerized workloads

What does it take to work at LastPass?

* Proven experience working with AWS and AWS security services in a secure production environment, including IAM, Config, KMS, Secrets Manager, CloudWatch, CloudTrail, and GuardDuty
* Proven experience working closely with engineering teams and supporting them on their path to shifting security left
* Background with infrastructure as code (AWS CDK, CloudFormation, or Terraform), version control and CI tools such as GitLab and GitLab CI
* Hands-on experience with Kubernetes (AWS EKS), containers (Docker, AWS ECS), K8s admission controllers and Supply Chain Security
* Solid understanding of internet and computer network protocols, including TCP/IP, TLS, and VPN
* Good written and verbal communication skills in English
* Collaborative team player with a hands-on, can-do approach to problem solving

It’s great, but not required:

* AWS Certified Security – Specialty certification or similar.
* General familiarity with AI tools and large language models (e.g., Claude by Anthropic, AWS Bedrock)

Why LastPass?

* The leader in secure access
* High-growth, collaborative environment with inclusive teams
* Remote-first culture
* Competitive compensation
* Flexible Paid Time Off policies, including but not limited to: Quarterly Self-Care Days (4 extra paid days off annually) and Volunteer Days
* Parental leave
* Comprehensive health coverage, including dependents
* Home office setup support
* LastPass Families free account for up to 5 members
* Continuous learning and development opportunities, including an annual learning stipend to invest in your growth
* Peer-to-peer recognition through Motivosity
* Employee Assistance Program for well-being support
* Remote work stipend to support your home office needs
* Short-Term or Remote-Centric Work Arrangements for added flexibility

Unlock your potential with us – your skills, experience, and unique perspective matter more than just checking the boxes. Apply today, and let’s build the future together!

We’re building an inclusive community that reflects the people of all races, genders, sexual orientations, national origins, backgrounds, and perspectives who share our world.

For more information about how we process your personal data and your rights, please refer to our [Candidate Privacy Notice](https://www.lastpass.com/-/media/925ED6EB59CF457EBA0CDE6C9CADDA50.pdf).

Show more

[Apply now >](https://jobicy.com/jobs/151831-principal-cloud-security-engineer.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Pleo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b27fbed2-221.jpg)
Pleo  Aug 27

### [Lead Security Operations Engineer](https://jobicy.com/jobs/151792-lead-security-operations-engineer.md)

About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we’re changing that. We build spend solutions…

*
![Ada logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/666ef11e-221.png)
Ada  Aug 27

### [Compliance and Security Lead](https://jobicy.com/jobs/151791-compliance-and-security-lead.md)

About Us Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service…

*
![Pleo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b27fbed2-221.jpg)
Pleo  Aug 27

### [Senior Application Security Manager](https://jobicy.com/jobs/151788-senior-application-security-manager.md)

About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we’re changing that. We build spend solutions…

*
![GitLab logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/12/WRILS-201207055737-109952.jpg)
GitLab  Aug 27

### [Senior Security Engineer, Security Incident Response Team (SIRT) – EMEA](https://jobicy.com/jobs/149309-senior-security-engineer-security-incident-response-team-sirt-emea.md)

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50…

*
![Vercel logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/a6aded72-221.png)
Vercel  Aug 27

### [Security Software Engineer, IAM](https://jobicy.com/jobs/147750-security-software-engineer-iam.md)

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built….

*
![Bloomreach logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/60790cd5-221.png)
Bloomreach  Aug 26

### [Director, AI Enablement & Security](https://jobicy.com/jobs/151780-director-ai-enablement-security.md)

Bloomreach is building the world’s premier agentic platform for personalization.We’re revolutionizing how businesses connect with their customers, building and deploying AI agents to personalize the entire customer journey. We’re taking…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Aug 26

### [Security Engineer, Infrastructure Security](https://jobicy.com/jobs/151778-security-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Aug 26

### [Security Engineer, Agent Security](https://jobicy.com/jobs/151775-security-engineer-agent-security.md)

About the TeamThe team’s mission is to accelerate the secure evolution of agentic AI systems at OpenAI. To achieve this, the team designs, implements, and continuously refines security policies, frameworks,…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Aug 26

### [Security Engineer, Detection and Response](https://jobicy.com/jobs/151765-security-engineer-detection-and-response.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Aug 26

### [Technical Threat Investigator, Threat Intel Engineering](https://jobicy.com/jobs/151752-technical-threat-investigator-threat-intel-engineering.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Threat Intelligence team protects OpenAI’s technology, people, research,…