Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely. We are currently seeking a Senior Infrastructure Security Engineer to join our rapidly growing Security team, where you will build proactive security solutions and implement detection capabilities in a cloud-first environment.
Responsibilities:
- Implement and maintain security controls across AWS/Azure, focusing on EKS/AKS cluster security, EC2 hardening, and cloud-native protection
- Partner with the cloud security manager to plan and develop the team’s road map
- Develop and tune rules for cloud-specific threats, manage GuardDuty/Defender integration, and build automated response workflows
- Investigate potential security incidents and serve as initial incident responder
- Provide architectural guidance for securing our user environments and maintaining a good security posture
- Secure Kubernetes workloads, implement pod security standards, and integrate security scanning into CI/CD pipelines
- Stay up-to-date with current methods of cloud compromise, tools, tactics, and procedures
- Work in a small team where you can make a big impact
Requirements:
- Cloud Security expertise with 3+ years in securing AWS environments
- Hands-on expertise with Kubernetes and/or EKS, including autoscaling, CI/CD, and automation
- Adept at using IaC technologies like Terraform, Puppet, CloudFormation, or Ansible
- Skilled in securing cloud infrastructure such as AWS, GCP/GSuite, GitHub, and IdP
- Familiarity in a cloud-first organization, including experience with AWS and/or GCP
- Ability to program in a dynamic programming language: Python, Ruby
- Strong understanding of threat vectors, indicators of compromise, malicious behaviour identification, and emerging threat analysis
- Strong Linux experience
- Demonstrate a keen interest in improving your craft by using AI
- Strong Azure and/or GCP security experience to go with your AWS Experience
- Any security certifications such as AWS Security Specialist, OSCP, CKS, GCPN, CISSP or others
- Experience with Ruby on Rails, Puppet, Terraform, ELK (Elastic/OpenSearch, Logstash and Kibana)
- Infrastructure security (firewalls, ACLs, authentication, device hardening)
- Container Security Tools familiarity with Falco, OPA/Gatekeeper, container image scanning, and runtime protection