Cloud Security Engineer
About Marvell
Marvell’s semiconductor solutions are the essential building blocks of the data infrastructure that connects our world. Across enterprise, cloud and AI, and carrier architectures, our innovative technology is enabling new possibilities.
At Marvell, you can affect the arc of individual lives, lift the trajectory of entire industries, and fuel the transformative potential of tomorrow. For those looking to make their mark on purposeful and enduring innovation, above and beyond fleeting trends, Marvell is a place to thrive, learn, and lead.
Your Team, Your Impact
At Marvell, we are looking for a Cloud Security Professional who will be instrumental in protecting the company’s digital assets. The individual shall come with proven strong technical competence and leadership capability to contribute towards the success to secure our multi cloud environment across AWS, Azure, GCP, and OCI. You will design and implement security controls, drive posture management through CNAPP platforms, and work with engineering, DevOps, and compliance teams to embed security across the cloud lifecycle, from code to runtime.What You Can Expect
- Design, implement, and maintain security controls across AWS, Azure, GCP, and OCI, including IAM, network segmentation, encryption, key management, and logging.
- Own the deployment, tuning, and day-to-day operation of CNAPP platforms (such as Palo Alto Cortex Cloud, Wiz and/or Orca)
- Assessment, development & implementation, operationalization and
documentation of a comprehensive and broad set of security, data protection, cryptography, key management, identity and access management (IAM), network security) within IaaS and PaaS, and other cloud environments. - Manage CSPM, CWPP, CIEM, DSPM, vulnerability management, and container/Kubernetes security capabilities.
- Triage and prioritize findings by risk and attack path; drive remediation with application and platform teams, and track SLAs and risk reduction metrics.
- Build custom policies, detection rules, and automated remediation workflows.
- Integrate security into CI/CD pipelines: IaC scanning (Terraform, CloudFormation, ARM), SAST/SCA, secrets detection, and container image scanning.
- Integrate cloud-native telemetry with the SIEM/SOAR platform.
- Map cloud controls to frameworks and standards such as CIS Benchmarks, NIST, ISO 27001/27017 and other applicable regulations
- Support audits and produce evidence, and maintain security documentation, standards, and runbooks.
- Report on security posture, risk trends, and KPIs
- Partner with cloud platform, DevOps, SRE, and application teams as a trusted security advisor.
What We're Looking For
- 5+ years of experience in cloud security.
- Hands-on experience in at least one cloud - AWS, Azure, GCP, and OCI, with knowledge of the others.
- Experience with at least of the leading CNAPP tools - Cortex Cloud, Wiz, Prisma Cloud or Orca to safeguard the cloud environment
- Strong understanding of cloud IAM, network security, encryption/KMS, secrets management, and logging/monitoring.
- Experience with Infrastructure as Code (Terraform preferred) and security scanning of IaC.
- Scripting/automation skills in Python, Bash, or PowerShell; familiarity with APIs and event-driven automation.
- Familiarity with security frameworks and benchmarks (CIS, NIST CSF, ISO 27001, MITRE ATT&CK for Cloud).
- Strong communication skills, with the ability to explain risks to both technical and non-technical stakeholders.
- Strong interpersonal and communication skills; ability to work in a team environment.
- Ability to work independently with minimal direction; self-starter/self-motivated
Preferred Qualifications
- Certifications such as AWS Certified Security – Specialty, AZ-500, Google Professional Cloud Security Engineer, OCI Security Professional, CCSP and/or CISSP.
- Strong expertise in GCP services (i.e. Cloud Services Platform, Google Kubernetes Engine, Compute Engine, Cloud Interconnect)
- Experience with SIEM/SOAR tools (XSOAR, Splunk, Sentinel, Chronicle).
- Exposure to containers and Kubernetes security.
- Exposure to Zero Trust, data security/DSPM, and API security.
Additional Compensation and Benefit Elements
With competitive compensation and great benefits, you will enjoy our workstyle within an environment of shared collaboration, transparency, and inclusivity. We’re dedicated to giving our people the tools and resources they need to succeed in doing work that matters, and to grow and develop with us. For additional information on what it’s like to work at Marvell, visit our Careers page.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.
Interview Integrity
To support fair and authentic hiring practices, candidates are not permitted to use AI tools (such as transcription apps, real-time answer generators like ChatGPT or Copilot, or automated note-taking bots) during interviews.
These tools must not be used to record, assist with, or enhance responses in any way. Our interviews are designed to evaluate your individual experience, thought process, and communication skills in real time. Use of AI tools without prior instruction from the interviewer will result in disqualification from the hiring process.
This position may require access to technology and/or software subject to U.S. export control laws and regulations, including the Export Administration Regulations (EAR). As such, applicants must be eligible to access export-controlled information as defined under applicable law. Marvell may be required to obtain export licensing approval from the U.S. Department of Commerce and/or the U.S. Department of State. Except for U.S. citizens, lawful permanent residents, or protected individuals as defined by 8 U.S.C. 1324b(a)(3), all applicants may be subject to an export license review process prior to employment.
#LI-MN1
