Staff Security Engineer, Cloud
ridealso
Job Score
80 ptsAbout ALSO.
We’re ALSO, an electric mobility company originally conceived as a part of Rivian. We’re a passionate team of builders, dreamers, doers and innovators, focused on creating entirely new (not to mention, innovative and delightful) vertically integrated, small EVs designed to meet the global mobility challenges of today and tomorrow. Our mission is to inspire everyone to ride ALSO—replacing many local car, truck and SUV miles with ones on vehicles that are more affordable, more enjoyable and 10-50x more efficient.
At ALSO, we are looking for a Staff Security Engineer for Cloud who wants to own security end to end — not advise on it, build it — for a connected, software-defined EV platform where nearly everything of value runs through the cloud: telemetry streaming in from vehicles in the field, remote diagnostics and updates, fleet intelligence, and the product APIs customers touch every day.
You'd set the security architecture and then build it yourself, in Go, alongside the backend team — equally comfortable writing a threat model, reviewing a Kubernetes admission policy, and shipping the service that enforces it. You'd be the person the company turns to for every question that starts with "is this secure," with the autonomy to actually answer it properly rather than just flag the risk and move on.
What You'll Do
Own cloud security end to end — strategy, architecture, implementation, and operations across AWS, Kubernetes, and our microservices platform — including threat modeling new systems in architecture reviews before the code exists
Design and implement identity and access at scale: workload identity, org-wide IAM, least privilege by default, secrets management, and certificate/key lifecycle, including mutual TLS between services and between cloud and vehicle
Harden containers and orchestration: image provenance, admission control, runtime and network policy, service mesh configuration, and clean isolation across microservices
Secure the software supply chain: SBOM generation, dependency and image scanning, signed artifacts, and CI/CD pipelines that fail closed on what matters and stay quiet on what doesn't
Build the controls in Go — authorization services, policy enforcement, provisioning and rotation tooling — and serve as the DevSecOps function, writing guardrails and policy as code so other engineers move fast without routing every decision through security
Run detection and response: security logging and telemetry, meaningful alerting, runbooks, on-call for security incidents, and blameless postmortems that produce real fixes
Secure the vehicle-to-cloud boundary: device identity and provisioning, fleet-wide certificate rotation, secure OTA update paths, and anomaly and tamper detection at scale
Contribute to core backend work alongside the team, and own assurance — penetration tests, vulnerability management, evidence collection, and proportionate standards work that strengthens the product instead of slowing it down
What You'll Bring
10+ years in backend and infrastructure engineering, with a substantial portion spent owning security in production
Expert, hands-on AWS: IAM, VPC and network design, KMS, Secrets Manager, GuardDuty, Security Hub, CloudTrail, Config, and org-level guardrails (SCPs), alongside core compute and data services (EKS, ECS, ECR, Lambda, DynamoDB, S3)
Deep Kubernetes and container security — RBAC, admission controllers, pod security standards, network policy, secrets handling, runtime detection, and image hardening — with real experience operating clusters, not just reading about them
Fast, fluent Go: you design, review, and ship production Go code today, not several years ago
Microservices and distributed systems security: service-to-service authentication and authorization, API gateway patterns, rate limiting, tenant isolation, and event-driven pipeline security
Identity protocols and applied cryptography in practice: OAuth2, OIDC, JWT, SAML, mutual TLS, and PKI with certificate lifecycle management at scale
Infrastructure and policy as code, with security gating built into CI/CD
Threat modeling and secure architecture review as routine practice, with specific examples of designs you've changed, plus incident response you've personally led from detection through postmortem
Demonstrated 0 to 1 ownership: you've stood up a security function or program where none existed, without a large team behind you
The salary for this position ranges from $205,000 - $240,000 per year, depending on experience, qualifications, and location.
Perks & Benefits
Robust health coverage — excellent health, dental and vision insurance covered up to 100% by ALSO with FSA & HSA options
One Medical membership and dedicated insurance advocates
Rich fertility and family building benefits with Progyny
Flexible time off
401(k) match
Why ALSO.
We’re passionate about helping the world find a better way to get there—wherever it is you’re headed.
We’re located in the heart of Silicon Valley and have brought together a world-class team from some of the biggest brands in the technology, automotive, cycling, outdoor recreation and retail spaces.
Together we’re working hands-on to imagine, design and build an entirely new solution to a global set of transportation challenges.
About Information Security
The Information Security area is one of the most strategic and in-demand fields in the technology market. With the rise of cyberattacks, data breaches, and regulations like LGPD and GDPR, companies of all sizes invest heavily in professionals who can protect their digital assets.
Key specializations include Network Security, Cloud Security (AWS, Azure, GCP), Offensive Security (Penetration Testing, Red Team), Defensive Security (SOC, Blue Team), AppSec, and Security Governance. Tools like SIEM (Splunk, QRadar), firewalls, EDR, and Vulnerability Management platforms are essential.
Certifications like CISSP, CEH, OSCP, CompTIA Security+, and AWS Security Specialty are important differentiators. Information security professionals are among the highest-paid in the sector, with growing demand especially in fintechs, healthtechs, and large enterprises.
Discover Other Areas
Understand the scope of work, key skills, and tools used in different career areas.
About SEO Analyst
The SEO Analyst is the professional responsible for optimizing websites for search engines, increasing organic visibility and qualified traffic. With the growing importance of digital marketing, SEO professionals are fundamental to any online presence strategy.
Key skills include on-page and off-page SEO, technical SEO, keyword research, SEO audits, link building, optimized content creation, and metrics analysis. Tools like Google Search Console, Google Analytics, Ahrefs, Semrush, Moz, and Screaming Frog are essential for daily work.
SEO analysts in technology companies are highly valued, especially those who master technical SEO, Core Web Vitals, and data-driven content strategies. The field offers opportunities from junior analyst to head of SEO, with a focus on organic growth, domain authority, and return on investment.
About Ecommerce Manager
The Ecommerce Manager is the professional responsible for the entire strategic and operational management of online stores and marketplaces. They lead teams, define pricing, promotion, and catalog strategies, and monitor online sales performance across multiple platforms.
Key skills include catalog management, dynamic pricing, seasonal campaigns (Black Friday, Cyber Monday), marketplace management (Amazon, Mercado Livre, Shopee, Magalu), paid traffic, CRO, and team management. Knowledge of Shopify, VTEX, WooCommerce, Google Ads, Meta Ads, and performance metrics is a differentiator.
Ecommerce Managers in technology companies are highly valued, especially those who master multi-marketplace management, checkout optimization, and mobile commerce strategies. The field offers opportunities from ecommerce manager to head of ecommerce, with a focus on revenue, customer experience, and growth.
About Customer Service
The Customer Service / Client Relations area is essential for ensuring customer satisfaction, retention, and a good relationship. Professionals in this field are the primary interface for communication, handling inquiries, requests, feedback, and ensuring a high-quality day-to-day experience. Skills in communication, problem-solving, empathy, and patience are indispensable.
About Graphic Designer
The Graphic Designer is the professional responsible for creating visual pieces for print and digital communication, from visual identity and logos to marketing materials and packaging. They combine creativity with technique to convey messages visually and impactfully.
Key skills include Adobe Photoshop, Illustrator, and InDesign, CorelDRAW, visual identity design, typography, color theory, packaging design, and motion graphics. Knowledge of vector illustration, offset/digital printing, and print production is a differentiator.
Graphic Designers in technology companies are highly valued, especially those who master social media design, infographics, and can create materials that strengthen brand visual identity. The field offers opportunities from junior graphic designer to art director and design director.
About Systems Analyst
The Systems Analyst is the professional responsible for analyzing, designing, and implementing technology solutions that meet business needs. They act as a bridge between business areas and the development team, ensuring that systems deliver real value to the organization.
Key skills include requirements gathering and analysis, process modeling (BPMN), data modeling, technical and functional documentation, system integration (APIs, microservices), and knowledge of ERPs and CRMs. Tools like Jira, Confluence, Visio, and project management platforms are essential.
Systems Analysts in technology companies are highly valued, especially those who master agile requirements analysis (user stories, backlog), system integration, and solution architecture. The field offers opportunities from junior analyst to solution architect, with a focus on efficiency, quality, and technological innovation.
Comments 0