Cloud Security Engineer

Other Jobs To Apply

<p style="text-align:left"><span class="emphasis"><b><b><i>Together we fight for everyone’s opportunity for a better financial future.</i></b></b></span></p><p style="text-align:inherit"></p><p style="text-align:left">We will do this together — with customers, partners and colleagues. We will fight for others, not against: We will stand up for and champion everyone’s access to opportunities. The status quo is not good enough … we believe every individual and every community deserves access to financial opportunities. We are determined to support both individuals and communities in reaching a better financial future.  We know that reaching this future depends on our actions today.</p><p style="text-align:inherit"></p><p style="text-align:left">Like our Purpose Statement, Voya believes in being bold and committed to action.  We are committed to a work environment where the differences that we are born with — and those we acquire throughout our lives — are understood, valued and intentionally pursued. We believe that our employees own our culture and have a responsibility to foster an environment where we all feel comfortable bringing our whole selves to work. Purposefully bringing our differences together to positively influence our culture, serve our clients and enrich our communities is essential to our vision.</p><p style="text-align:inherit"></p><p style="text-align:left"><b><b><span class="emphasis">Are you ready to join a company with a strong purpose and a winning culture? Start your Voyage –</span> </b></b><span class="emphasis-2"><b><b>Apply Now</b></b></span></p><p style="text-align:inherit"></p><div><div><div><b>***This role is remote with the expectation that candidates are based near one of the following Voya office locations: Windsor, CT; Boston, MA; or Atlanta, GA.***</b></div><div></div><p></p><div></div><p><span><span>Voya is seeking a<span> </span></span></span><b><span>Senior IT Security Specialist</span></b><span> </span><span><span><span> </span><span> </span>to strengthen our<span> </span></span>SaaS Security Posture Management (SSPM)<span>,<span> </span></span>Cloud Security Posture Management (CSPM)<span>, and<span> </span></span>container security<span><span> </span>capabilities across a rapidly evolving hybrid cloud and SaaS ecosystem.</span> </span></p><p></p></div><div><p><span><span>This role will partner closely with Cloud,<span> </span>DevSecOps</span><span>, Application Security, and Platform Engineering teams to<span> </span></span>identify, assess, and remediate security risks<span><span> </span>across SaaS platforms, public cloud infrastructure, and containerized workloads. The ideal candidate brings strong hands-on experience with<span> </span></span>cloud-native security controls, automation, <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Infrastructure-as-Code</span> (IaC), Policy-as-Code (PaC)<span>, and modern security tooling.</span> </span></p><p></p></div><div><p><span><span>Experience with<span> </span></span><b>CrowdStrike Falcon Shield<span>,<span> </span></span>Palo Alto<span> </span>Prisma, Cortex</b><span><span> </span>or similar platforms is highly desirable. Familiarity with<span> </span></span>AI Security Posture Management (AI-SPM)<span><span> </span>and<span> </span></span>MLOps<span> </span>security<span><span> </span>is a strong plus as Voya continues to expand its AI-enabled capabilities.</span> </span><span> </span><span> </span></p></div><div><p><span> </span></p></div><div><p><b><span>Key Responsibilities</span></b><span> </span></p></div><div><p><b><span>SaaS & Cloud Security Posture Management</span></b><span> </span></p></div><div><ul><li><p><span><span>S</span><span>upport<span> </span></span></span><b><span>SaaS Security Posture Management (SSPM)</span></b><span><span><span> </span>initiatives across enterprise SaaS platforms.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Configure,<span> </span></span><span>operate</span><span>, and tune SSPM/CSPM tools to<span> </span></span><span>identify</span><span><span> </span>misconfigurations, excessive permissions, and risky integrations.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Support and mature CSPM capabilities across<span> </span></span></span><b><span>AWS and Azure</span></b><span><span>, including continuous monitoring and risk prioritization.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Partner with application owners to drive remediation of SaaS and cloud security findings.</span></span><span> </span></p></li></ul><p></p></div></div><div><div><p><b><span>Cloud & Container Security</span></b><span> </span></p></div><div><ul><li><p><span><span>Secure cloud-native workloads across AWS and Azure using native and third-party security controls.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Support<span> </span></span></span><b><span>container and Kubernetes security</span></b><span><span>, including image scanning, runtime protections, and policy enforcement.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Collaborate with<span> </span></span><span>DevSecOps</span><span><span> </span>teams to embed security controls into CI/CD pipelines.</span></span><span> </span></p></li></ul><p></p></div><div><p><b><span>Automation,<span> </span></span><span>IaC</span><span><span> </span>&<span> </span></span><span>PaC</span></b><span> </span></p></div><div><ul><li><p><span><span>Develop and<span> </span></span><span>maintain</span><span><span> </span></span></span><b><span>security automation</span></b><span><span><span> </span>using scripting languages (Python, PowerShell, Bash).</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Implement and review<span> </span></span></span><b><span><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Infrastructure-as-Code</span> (Terraform, ARM, CloudFormation)</span></b><span><span><span> </span>with a security-first mindset.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Design and enforce<span> </span></span></span><b><span>Policy-as-Code (OPA, Sentinel, native cloud policies)</span></b><span><span><span> </span>to prevent insecure deployments.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Enable shift-left security by integrating controls early in the<span> </span></span><span>development</span><span><span> </span>lifecycle.</span></span><span> </span></p></li></ul><p></p></div><div><p><b><span>AI / ML Security (Plus)</span></b><span> </span></p></div><div><ul><li><p><span><span>Contribute to emerging<span> </span></span></span><b><span>AI Security Posture Management (AI-SPM)</span></b><span><span><span> </span>efforts.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Partner with platform and data teams to assess and secure<span> </span></span></span><b><span>MLOps</span><span><span> </span>pipelines</span></b><span><span>, models, and supporting infrastructure.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Help define guardrails for AI usage, data access, and model governance.</span></span><span> </span></p></li></ul><p></p></div><div><p><b><span>Risk, Governance & Collaboration</span></b><span> </span></p></div><div><ul><li><p><span><span>Translate technical findings into actionable risk insights for<span> </span></span><span>remediation</span><span>.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Support audits, risk assessments, and regulatory inquiries related to cloud and SaaS security.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Stay current on emerging threats, SaaS attack patterns, cloud security trends, and AI security risks.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Mentor junior team members and influence secure-by-design practices across the organization.</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Required Qualifications</span></b><span> </span></p></div></div><div><div><ul><li><p><span><span>5</span><span>+ years of experience in<span> </span></span></span><b><span>information security</span></b><span><span>, with<span> </span></span><span>strong</span><span><span> </span>focus on<span> </span></span></span><b><span>cloud and SaaS security</span></b><span><span>.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Hands-on experience with<span> </span></span></span><b><span>Cloud Security Posture Management (CSPM)</span></b><span><span><span> </span>in AWS and/or Azure.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Experience with<span> </span></span></span><b><span>SaaS Security Posture Management (SSPM)</span></b><span><span><span> </span>tools such as: </span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>CrowdStrike Falcon Shield</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Palo Alto (SaaS / Prisma-related capabilities)</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>or similar platforms</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Strong understanding of<span> </span></span></span><b><span>container security</span></b><span><span><span> </span>and Kubernetes environments.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Proficiency</span><span><span> </span>in<span> </span></span></span><b><span>scripting and automation</span></b><span><span><span> </span>(Python, PowerShell, Bash).</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Practical experience with<span> </span></span></span><b><span><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">Infrastructure-as-Code</span> (</span><span>IaC</span><span>)</span></b><span><span><span> </span>and<span> </span></span></span><b><span>Policy-as-Code (</span><span>PaC</span><span>)</span></b><span><span>.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Solid understanding of IAM, identity federation, least-privilege access, and SaaS permissions models.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Ability to work cross-functionally with cloud, DevOps, AppSec, and platform teams.</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>Preferred / Nice-to-Have Qualifications</span></b><span> </span></p></div><div><ul><li><p><span><span>Experience securing<span> </span></span></span><b><span>MLOps</span><span><span> </span>pipelines</span></b><span><span><span> </span>and AI-enabled platforms.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Familiarity with<span> </span></span></span><b><span>AI Security Posture Management (AI-SPM)</span></b><span><span><span> </span>concepts and tooling.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Experience integrating security into CI/CD pipelines.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Knowledge of cloud-native security services (AWS Security Hub,<span> </span></span><span>GuardDuty</span><span>, Azure Defender, etc.).</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Security certifications such as CISSP, CCSP, AWS/Azure Security certifications.</span></span><span> </span></p></li></ul></div><div><p><span> </span></p></div><div><p><b><span>What Success Looks Like</span></b><span> </span></p></div></div><div><div><ul><li><p><span><span>Improved visibility and risk reduction across Voya’s SaaS and cloud environments.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Measurable reduction in high-risk misconfigurations and over-privileged access.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Increased automation and policy-driven enforcement of security controls.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Strong partnership with engineering teams, enabling security without slowing delivery.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Forward-looking contributions to AI and<span> </span></span><span>MLOps</span><span><span> </span>security strategy.</span></span><span> </span></p></li></ul></div></div><p style="text-align:inherit"></p><p style="text-align:left"><span class="emphasis"><b><b>Compensation Pay Disclosure: </b></b></span></p><p style="text-align:inherit"></p><p style="text-align:left"><span>Voya is committed to pay that’s fair and equitable, which means comparable pay for comparable roles and responsibilities.</span></p><p style="text-align:inherit"></p><p style="text-align:left"><span>The below annual base salary range reflects the expected hiring range(s) for this position in the location(s) listed. In addition to base salary, Voya offers incentive opportunities (i.e., annual cash incentives, sales incentives, and/or long-term incentives) based on the role to reward the achievement of annual performance objectives. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Voya Financial is willing to pay at the time of this posting.</span></p><p style="text-align:inherit"></p><p style="text-align:left"><span>Actual compensation offered may vary from the posted salary range based upon the candidate’s geographic location, work experience, education, licensure requirements and/or skill level and will be finalized at the time of offer. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.</span><span> </span></p><p style="text-align:inherit"></p>$114,480 - $130,000<p></p><p><span class="emphasis"><b><b>Be Well. Stay Well.</b></b></span></p><p>Voya provides the resources that can make a difference in your lives. To us, this means thriving physically, financially, socially and emotionally. Voya benefits are designed to help you do just that. That’s why we offer an array of plans, programs, tools and resources with one goal in mind: To help you and your family be well and stay well.</p><p></p><p><span class="emphasis"><b><b>What We Offer</b></b></span></p><ul><li>Health, dental, vision and life insurance plans</li><li>401(k) Savings plan – with generous company matching contributions (up to 6%)</li><li>Voya Retirement Plan – employer paid cash balance retirement plan (4%)</li><li>Tuition reimbursement up to $5,250/year</li><li>Paid time off – including 20 days paid time off, nine paid company holidays and a flexible Diversity Celebration Day.</li><li>Paid volunteer time — 40 hours per calendar year</li></ul><p></p><p><i><span>Learn more about </span></i><a href="https://assets.voya.com/m/65c932d9fbfe4634/original/Voya_Benefits_Highlights.pdf" target="_blank" rel="noopener noreferrer">Voya benefits (download PDF)</a></p><p></p><p><span class="emphasis"><b><b>Critical Skills</b></b></span></p><p><span>At Voya, we have identified the following critical skills which are key to success in our culture: </span></p><ul><li><span class="emphasis-2"><b><b>Customer Focused</b>:</b></span><span> Passionate drive to delight our customers and offer unique solutions that deliver on their expectations.</span></li><li><span class="emphasis-2"><b><b>Critical Thinking</b>:</b> </span>Thoughtful process of analyzing data and problem solving data to reach a well-reasoned solution.</li><li><span class="emphasis-2"><b><b>Team Mentality</b>:</b></span><span> Partnering effectively to drive our culture and execute on our common goals. </span></li><li><span class="emphasis-2"><b><b>Business Acumen</b>:</b></span><span class="emphasis-3"> </span>Appreciation and understanding of the financial services industry in order to make sound business decisions.</li><li><span class="emphasis-2"><b><b>Learning Agility</b>:</b></span><span> Openness to new ways of thinking and acquiring new skills to retain a competitive advantage.</span></li></ul><p></p><p><i><span>Learn more about<b><span> </span></b><a href="https://corporate.voya.com/careers/working-voya-financial/critical-skills" target="_blank" rel="noopener noreferrer">Critical Skills</a></span></i></p><p></p><p><span class="emphasis"><b><b>Equal Employment Opportunity</b></b></span></p><p><i><span>Voya Financial is an equal-opportunity employer. Voya Financial provides equal opportunity to qualified individuals regardless of race, color, sex, national origin, citizenship status, religion, age, disability, veteran status, creed, marital status, sexual orientation, gender identity, genetic information, or any other status protected by state or local law.</span></i></p><p></p><div><div><div><div><div><div><div><div><div><div><div><div><div><p><span class="emphasis"><b><b>Reasonable Accommodations</b></b></span></p><p><i><span>Voya is committed to the inclusion of all qualified individuals. As part of this commitment, Voya will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, </span> <span>please</span> reference</i> <i><a href="https://www.voya.com/page/applicants-disabilities" target="_blank" rel="noopener noreferrer">resources for applicants with disabilities</a>.</i></p><p></p><p><a href="https://www.voya.com/articles/other-helpful-information#employment" target="_blank" rel="noopener noreferrer">Misuse of Voya's name in fraud schemes</a></p><p></p></div></div></div></div></div></div></div></div></div></div></div></div></div>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...