Cloud Security Engineer

19 hours ago

Makati, Metro Manila, Philippines Workstreet Remote Full-time ₱1 - ₱2 Contract

About Workstreet

At Workstreet , we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

The Opportunity

We are seeking an experienced Cloud Security Engineer with deep, hands‑on Oracle Cloud Infrastructure (OCI) expertise to help clients design, implement, and maintain secure OCI environments that meet stringent security and compliance requirements.

The ideal candidate has extensive experience securing OCI services, including Compute, Networking, Storage, Identity and Access Management (IAM), Security Zones, Cloud Guard, Vault, Logging, and related OCI security services. Experience with AWS, Azure, or GCP is considered beneficial but is secondary to demonstrated OCI expertise.

You will work closely with clients and internal engineering teams to strengthen cloud security, implement security automation, and ensure compliance across enterprise cloud environments, with OCI serving as the primary cloud platform.

This is an OCI-first role. Candidates must have strong, real‑world experience designing, securing, and operating Oracle Cloud Infrastructure (OCI). Experience with OCI is a strict, non‑negotiable requirement. Applicants without substantial OCI experience will not be considered.

What You'll Do

  • Design and Implement Cloud Security Controls : Design, implement, and maintain security controls and best practices across Oracle Cloud Infrastructure (OCI), AWS, Google Cloud Platform (GCP), and Microsoft Azure, ensuring secure configurations, compliance with regulatory requirements, and alignment with industry security standards and best practices.
  • Assess Cloud Environments : Assess Oracle Cloud Infrastructure (OCI) and multi‑cloud environments (AWS, Google Cloud Platform (GCP), and Microsoft Azure) to identify security risks, misconfigurations, excessive permissions, network exposure, vulnerabilities, and compliance gaps, delivering actionable remediation recommendations to strengthen cloud security posture.
  • Deploy and Manage Security Tools : Configure and maintain SIEM, IDS/IPS, vulnerability management, and identity solutions to strengthen cloud security posture.
  • Support Compliance Initiatives : Support compliance initiatives across Oracle Cloud Infrastructure (OCI), AWS, Google Cloud Platform (GCP), and Microsoft Azure by implementing, validating, and testing security controls, and coordinating evidence collection to meet SOC 2, ISO 27001, HIPAA, and other regulatory and compliance requirements, with a primary focus on OCI environments.
  • Automate Security Operations : Automate cloud security operations across Oracle Cloud Infrastructure (OCI), AWS, Google Cloud Platform (GCP), and Microsoft Azure by developing and managing Infrastructure‑as‑Code (IaC) solutions using Terraform and scripting languages to standardize secure deployments, enforce security policies, and strengthen cloud governance, with a primary focus on OCI environments.
  • Conduct Cloud Security Reviews : Perform architecture assessments and configuration reviews to ensure secure design and adherence to best practices.
  • Collaborate with Engineering Teams : Integrate security practices into CI/CD pipelines and development workflows to prevent vulnerabilities early in the lifecycle.
  • Assist in Incident Response : Investigate and remediate cloud‑related security incidents to minimize exposure and restore integrity.
  • Communicate with Clients : Engage directly with clients via multiple channels to address security inquiries and deliver actionable guidance.

Client Relationship Management (Primary Focus)

  • Own the Client Experience: Act as the primary point of contact for a portfolio of cloud security clients, building strong, trust‑based relationships and ensuring consistent, high‑quality engagement throughout all phases of service delivery.
  • Guide Clients Through Cloud Security Initiatives: Lead clients through security improvement efforts — from initial assessments to implementation and ongoing optimization — with clear communication, defined milestones, and proactive support.
  • Collaborate Closely with Client Teams: Partner with engineering, DevOps, and IT stakeholders to understand their cloud environments, address security gaps, and implement scalable, compliant solutions tailored to their infrastructure.
  • Translate Security into Business Value: Communicate techn