Cloud Security Engineer - Customer Trust & Assurance
Location: Remote, US only
Employment Type: Contractor
Targeted start date: Immediate
Rate: $70 - $85/hr W2 hourly // $80 - $100/hr C2C. Compensation will be determined based on relevant experience, skills, and overall qualifications.
Requirements: must be authorized to work legally in the US without sponsorship, now or in the future.
About Us
Concord isn't your typical consulting firm; we are an execution company with a passion for making things happen. Our mission is to help clients enhance customer experiences, optimize operations, and revolutionize their product offerings through seamless integration, optimization, and activation of technology and data.
We are purpose-built, merging the industry’s top specialty companies to amplify our Innovation Capabilities in analytics & AI, data management & engineering, UX and digital experience, and technical platform integration, automation & security engineering.
About the Role
We are seeking a highly skilled cybersecurity professional to join our client’s Customer Trust and Assurance team within a dynamic and growing cybersecurity program. In this role, you will represent the security of a modern SaaS platform by delivering accurate, engineering‑informed responses to security questionnaires, RFIs, and due‑diligence requests. You will work closely with internal engineers to understand how the platform is architected, validate the security design, and translate complex technical information into clear, customer‑ready explanations.
As a security architect, you will develop deep familiarity with the product’s cloud architecture, application security controls, and threat mitigation strategies. You will articulate how the platform is built and secured to both technical and non‑technical audiences, earning trust through clarity, confidence, and technical credibility. Operating at the intersection of product security, cloud security, and customer assurance, you will help transform detailed engineering knowledge into strong customer confidence in the platform's security posture.
What You Will Be Doing
- Respond to customer RFIs, security questionnaires, and due‑diligence inquiries related to security, privacy, and compliance.
- Collaborate closely with internal teams to gather, validate, and align accurate technical responses.
- Interpret and translate technical security concepts into clear, customer‑ready explanations.
- Support customer trust initiatives, including audits, certifications, and process improvements.
- Ensure timely, high‑quality delivery of all responses and maintain excellent communication throughout the customer lifecycle.
- Develop a deep understanding of the platform’s architecture, including cloud infrastructure, application components, identity flows, and data protection mechanisms.
- Articulate security design decisions, architectural patterns, and threat mitigation strategies in a way that builds high customer confidence.
- Partner with engineering teams to ensure externally communicated security details accurately reflect system design and controls.
- Enhance and maintain technical security documentation, architectural diagrams, and reusable content for customer assurance.
- Identify opportunities to improve clarity, consistency, and technical depth across customer‑facing security materials.
Qualifications
*Technical:*
- 8–12+ years of hands-on experience in cybersecurity, cloud security, application security, or software engineering — with demonstrable depth in security architecture, not just compliance or advisory work.
- Proven ability to design, validate, and articulate security controls at the engineering level — including IAM models, encryption strategies, secrets management, network segmentation, and logging/observability pipelines.
- Strong working knowledge of cloud-native architectures (AWS, Azure, or GCP) from a security design perspective — able to discuss tradeoffs, attack surfaces, and control decisions with engineering teams.
- Experience with threat modeling methodologies (e.g., STRIDE, MITRE ATT&CK) and applying them to real SaaS platform components such as identity flows, APIs, and data pipelines.
- Hands-on experience collaborating with engineering teams on system design reviews, security controls implementation, and architecture validation — not just documentation or sign-off.
*Candidates should expect to be evaluated on foundational security and cloud architecture concepts during the interview process, including the ability to discuss security design decisions at an engineering level.*
*Compliance & Customer Assurance:*
- Familiarity with security and compliance frameworks such as HITRUST CSF, SOC 2, ISO 27001, or CSA STAR — with the ability to ground compliance requirements in technical implementation, not just policy.
- Experience responding to customer security questionnaires, RFIs, and due-diligence requests, with responses anchored in engineering detail rather than templated answers.
- Experience creating or maintaining architectural diagrams, threat models, and technical security documentation.
*Communication & Collaboration:*
- Exceptional written and verbal communication skills — able to translate engineering-level security decisions into clear, accurate, customer-ready explanations for both technical and non-technical audiences.
- Confident representing the platform's security posture directly to customers and able to handle follow-up technical questions without escalation.
- Able to work cross-functionally across engineering, product, and compliance teams in a distributed environment.
*Certifications:*
- Relevant certifications strongly preferred: CISSP, CCSP, CISM, or cloud security certifications (AWS Security Specialty, Google Professional Cloud Security Engineer, etc.).
What We Offer (W2 Employment)
- Health, Dental, and Vision Insurance: Comprehensive coverage to support your well-being.
- Employer Contributions to Health Savings Accounts (HSA): Helping you save for medical expenses.
- Flexible Spending Accounts (FSA): Options for healthcare and dependent care expenses, plus a $200 Lifestyle Spending Account (LSA).
- Disability Insurance: Short- and long-term coverage, fully paid by the employer.
- Life and AD&D Insurance: Employer-provided coverage, with options for additional voluntary coverage.
- Employee Assistance Program (EAP): Access to personal and professional support resources.
- Career Growth Opportunities: Pathways for advancement and skill development.
- Team Engagement Activities: Regular team-building events and company-sponsored activities to foster collaboration and connection.