Skip to main content

Staff Cloud Security Engineer

Xometry · Xometry is an online marketplace that allows customers to access a network of machine shops and custom manufacturers.

Lexington, KY1001-5000 employeesPosted 6 days ago
Post-IPO Equity · $225Mraised 5 months agoled by Bosch Ventures, Siemens, BMW i Ventures

This board only lists companies whose most recent round closed in the last 180 days.

Apply on Xometry’s site
<div class="content-intro"><p><span style="font-size: 10pt; font-family: arial, helvetica, sans-serif;">Xometry (NASDAQ: XMTR) powers the industries of today and tomorrow by connecting the people with big ideas to the manufacturers who can bring them to life. Xometry’s digital marketplace gives manufacturers the critical resources they need to grow their business while also making it easy for buyers at Fortune 1000 companies to tap into global manufacturing capacity.</span></p></div><p>&nbsp;</p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Xometry is looking for a Staff Cloud Security Engineer to own our cloud security posture and runtime detection capabilities. This is a high-impact, individual contributor role focused on ensuring our live cloud environments and containerized workloads are hardened, continuously monitored, and generating the right signals for our security operations function.&nbsp; This role is about detection architecture, posture management, and runtime visibility.</span></p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">You will be the primary owner of our CrowdStrike platform, working closely with our MDR providers to ensure alert fidelity, tuning, and appropriate escalation. You will also evaluate migration to a new SIEM.</span></p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">This isn’t a role where you watch dashboards and write tickets. You’ll be the person who defines how we detect threats, decides how we respond to them, and has the autonomy to fix what you find.&nbsp; If you’re tired of maintaining legacy tooling, navigating slow change management processes, or writing findings that disappear into a backlog, this is the opposite of that. We’re a SaaS-first company running a modern, cloud-native stack. We ship fixes, not tickets.</span></p> <h2><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><strong>What You'll Contribute </strong></span></h2> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Own CrowdStrike Falcon configuration, ensuring policies are appropriately scoped, tuned, and generating actionable alerts.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Partner with MDR to define alert routing, triage thresholds, and escalation logic, ensuring the right signals reach the right team.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Monitor cloud environments (primarily AWS) for security posture drift: misconfigured IAM roles, overly permissive security groups, exposed storage, and non-compliant resource configurations.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Secure Kubernetes clusters and containerized workloads: manage Network Policies, RBAC, Admission Controllers, and runtime detection for anomalous container behavior.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Develop and enforce cloud security policies and standards for AWS infrastructure, ensuring secure and scalable deployments align with organizational risk posture.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Evaluate and lead the implementation of additional detection tooling, including cloud SIEM platforms, designing detection rules and alerting pipelines.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Manage infrastructure as code (IaC) security using Terraform or OpenTofu — ensuring IaC definitions meet security standards before deployment.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Automate security posture checks and detection workflows using Python and shell scripting.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Stay current with the evolving cloud threat landscape and translate emerging threats into detection coverage or posture improvements.</span></li> </ul> <h2><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><strong>What You Bring</strong></span></h2> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Minimum 8 years of experience in cloud security, security engineering, or a related infrastructure security discipline.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Hands-on experience with a cloud security posture management (CSPM) platform — CrowdStrike, Wiz, Prisma Cloud, Orca, or equivalent. Prior CrowdStrike experience is a plus but not required.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Deep familiarity with AWS security architecture: IAM/SCP policy design, VPC networking, security groups, CloudTrail, and cloud-native security controls. GCP or Azure experience considered in lieu of AWS for strong candidates willing to expand into AWS.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Proficiency with infrastructure as code (IaC) tools such as Terraform, OpenTofu, or CloudFormation, with an understanding of how to enforce security standards within IaC workflows.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Strong Python and shell scripting skills for security automation, detection rule development, and tooling integration.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Must be a US Citizen or legal permanent resident (Xometry handles ITAR-controlled data).</span></li> </ul> <h2><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><strong>Preferred&nbsp;</strong></span></h2> <ul> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">AWS GovCloud experience.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Hands-on Kubernetes security experience: securing and managing production clusters, including Network Policies, RBAC, and Admission Controllers.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Experience with cloud-native SIEM solutions, including writing detection rules in Python or SQL.</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Experience securing microservices architectures, including service mesh security (Istio or Linkerd).</span></li> <li style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">Bachelor’s degree in Computer Science, Information Security, or a related field</span></li> </ul> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">We also offer a competitive benefits package, including 401(k) match, medical, dental and vision insurance; life and disability insurance; generous paid time off including vacation, sick leave, floating and fixed holidays, maternity and bonding leave; EAP, other wellbeing resources; and much more.</span></p> <p>&nbsp;</p> <p><span style="font-size: 10pt; font-family: arial, helvetica, sans-serif;">#LI-Hybrid</span></p><div class="content-conclusion"><p><span style="font-size: 10pt; font-family: arial, helvetica, sans-serif;">Xometry is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, or disability status.</span></p> <p><span style="font-family: arial, helvetica, sans-serif; font-size: 10pt;">For US based roles: Xometry participates in E-Verify and after a job offer is accepted, will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S.</span></p></div>
Apply on Xometry’s site

Applications go straight to the employer. VCBacked does not sit between you and the company.

930 more roles posted in the last 48 hours

You are seeing the board after its 48-hour member window. Job Seeker opens that window and sends an alert the moment a role hits — applicants in the first 24 hours land 90 percent of interviews.

Back to all roles at freshly funded companies