Req 26-03267 · Onsite · Contract
Engineering | Level 3 (USD)
Onsite contract role in Alpharetta, GA. Compensation is discussed at interview. An ApTask vertical recruiter manages your submission on this live client requisition.
- Requisition
- 26-03267
- Location
- Alpharetta, GA
- Type
- Onsite · Contract
- Compensation
- Compensation discussed at interview
- Posted
- Today (as of Oct 2, 2026, 2:06 PM EDT)
Your résumé routes to the vertical recruiter who owns this requisition. Identity-verified profile, never resold or syndicated.
About the role
Position Title: Senior Cloud Controls Engineer Company Profile: *** is a leading global financial services firm providing a wide range of investment banking, securities, wealth management and investment management services. With offices in more than 42 countries, the Firm's employees serve clients worldwide including corporations, governments, institutions, and individuals. For further information about ***, please visit www.Brokerage.com.
Cyber Data Risk & Resilience: The mission of Cyber Data Risk & Resilience (CDRR) is to deliver first-line defences to manage risks to Firm technology, information and cyber threats through risk identification, control management and assurance. This allows the business to operate and grow in a secure and legally compliant manner. Our vision is to deliver Programs that protect and enable the business, ensure secure delivery of services to our clients, adjust to address the risks presented by an evolving threat landscape, meet regulatory expectations, and offer highly attractive career opportunities. Profile Description: The Cloud Security Engineering team enables the firm to securely adopt and scale cloud-native technologies across the enterprise. You will work alongside highly skilled professionals in an environment that values intellectual rigor, technical depth, and collaboration. This role offers the opportunity to contribute to enterprise-scale cloud security while supporting standards, engineering practices and risk governance. We design, implement and operationalize security controls that govern the use of cloud services at scale across Microsoft Azure, AWS, and GCP. We are seeking a Senior Cloud Controls Engineer to contribute to cloud security research and control engineering in a fast-paced, highly technical environment. This role partners with engineering, architecture, risk and business stakeholders to ensure secure, scalable, and compliant cloud adoption. What you ll do in the role: Design and implement deploy-time security controls for cloud services across Azure, AWS, and GCP, using OPA (Rego) and Regula Translate firm-wide configuration baseline requirements into enforceable policy-as-code controls integrated directly into Terraform workflows and CI/CD pipelines Contribute across the control implementation lifecycle: requirement interpretation, policy authoring, testing, optimization, and deployment within engineering pipelines. Establish and maintain reusable policy libraries and modules to ensure consistency and scalability of controls across services and environments. Provide deep technical expertise in Terraform, infrastructure-as-code patterns, and pipeline orchestration, ensuring secure and efficient deployments. Define and implement testing strategies for policy validation, including unit and integration testing. Identify gaps where requirements cannot be enforced at deploy-time and propose compensating controls or alternative enforcement points. Contribute to the evolution of a unified control framework, enabling consistent control logic across deploy-time and runtime evaluation points Contribute to cloud security strategy and standards. Technical Expertise & Collaboration Serve as a senior technical contributor for deploy-time control implementation, helping shape technical approaches and support high-quality delivery. Provide hands-on technical guidance and peer support in OPA/Rego, Regula, Terraform, and secure pipeline design. Participate in code reviews, design discussions, and knowledge sharing to strengthen engineering quality and consistency across the team. Partner with platform engineering, security architecture, and application teams to improve implementation clarity and reduce delivery friction. Communicate complex technical concepts clearly to engineering teams, stakeholders, and senior leadership. Contribute to engineering best practices for infrastructure-as-code, policy development, testing, and review processes. What you ll bring to the role: Bachelor s degree in Computer Science, Information Security, or a related field, or equivalent experience. 7+ years of hands-on experience in cloud security engineering, with a strong focus on infrastructure-as-code and deployment pipelines. Proven experience designing and implementing policy-as-code controls using OPA/Rego and/or Regula in production environments. Deep hands-on expertise with Terraform, including module design, state management, and secure configuration patterns. Strong experience integrating security controls into CI/CD pipelines, including gating and enforcement mechanisms. Demonstrated ability to translate security requirements into automated, testable, and enforceable deploy-time controls. Solid understanding of cloud security architectures across AWS, Azure, and/or GCP, including IAM, networking, and data protection controls. Experience implementing control validation and testing strategies, including policy unit testing, pipeline validation, and drift detection. Familiarity with CSPM platforms and the ability to align deploy-time controls with runtime detection and compliance models. Strong understanding of modern threat models, attack paths, and misconfiguration risks in cloud environments, and how to mitigate them through preventive controls. Experience building and maintaining reusable policy libraries and shared control frameworks at enterprise scale. Experience working as a senior engineer on complex technical initiatives, including task prioritization, delivery planning, and contribution to technical direction. Demonstrated ability to mentor peers and share expertise, particularly in policy-as-code, Terraform, and secure pipeline practices. What you can expect from *** We are committed to maintaining the first-class service and high standard of excellence that have defined *** for over 85 years. At our foundation are five core values putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back that guide our more than 80,000 employees in 1,200 offices across 42 countries. At ***, you will find trusted colleagues, committed mentors and a culture that values diverse perspectives, individual intellect, and cross-collaboration. Our Firm is differentiated by the caliber of our diverse team, while our company culture and commitment to inclusion define our legacy and shape our future, helping to strengthen our business and bring value to clients around the world. Learn more about how we put this commitment to action: Brokerage.com/diversity. We are proud to support our employees and their families at every point along their work-life journey, offering some of the most attractive and comprehensive employee benefits in the industry. *** is an equal opportunities employer. We work to provide a supportive and inclusive environment where all individuals can maximise their full potential. Our skilled and creative workforce is comprised of individuals drawn from a broad cross section of the global communities in which we operate and who reflect a variety of backgrounds, talents, perspectives, and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing, and advancing individuals based on their skills and talents.
About operations at ApTask
Operations roles at ApTask cover program management, PMO, business analysis, transformation, and change-management positions across enterprise clients. We place operators who translate strategy into delivery — PMPs, Scrum Masters, agile coaches, Six Sigma black belts, and change-management practitioners certified in Prosci or the client's preferred framework. Candidates are validated against the specific enterprise tooling the client runs (ServiceNow, Jira Portfolio, Clarity, Planview) and their prior track record in comparable-scale programs, not generic delivery experience.
What happens after you apply.
1. Verified profile
Submit your résumé and complete the ApTask identity + skills verification. We check right-to-work, background, and technical calibration once — never resell or re-verify — so future roles surface faster.
2. Recruiter calibration call
Within one business day, the recruiter who owns this requisition reviews your profile against the client's specific stack, arrangement, and start-date requirements. You'll hear back either way — no ghosting.
3. Client interview
If your profile is a fit, we present you to the hiring team. Most clients run 2-3 interview stages: hiring-manager screen, technical panel, and final. We prep you with the exact scorecard criteria before each round.
4. Offer + onboarding
On acceptance, you onboard W-2 with ApTask. Benefits, payroll, and timesheets run through us. Your recruiter stays your point of contact for the length of the engagement.
Ready to apply? Two minutes, one profile.
Your résumé routes to the recruiter who owns this requisition. Identity-verified once, matched against every future ApTask role that fits your stack.
Own a staffing company that places roles like these.
ApTask Franchise: build your own book of business on our back office, payroll funding and recruiting bench.