We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results

Staff Cloud Security Engineer (Breakthrough)

U.S. Venture
remote work
United States, Wisconsin, Green Bay
1175 Lombardi Avenue (Show on map)
Jun 11, 2025
POSITION SUMMARYAbout Breakthrough

At Breakthrough, we empower our clients with data, technology, and market knowledge to reduce costs, create efficient networks, and decarbonize transportation. As a strategic partner to our clients, we challenge legacy practices in the $700 billion transportation industry, delivering sustainable fuel and freight products that foster fair partnerships and environmental responsibility.

As a digital product company, our culture thrives on curiosity, autonomy, and purpose-driven innovation. Here, you're not just executing tasks; you're collaborating with a team dedicated to transforming transportation and making a tangible impact on the global economy and the planet.

The Role

As a Staff Cloud Security Engineer, you'll play a pivotal role in developing and enhancing digital products that enable shippers to optimize the way freight moves around the globe.

The Staff Cloud Security Engineer is a key position to strengthen the security of our GCP-native SaaS platform, FELIX. This is a senior, hands-on role responsible for building and automating the security capabilities that protect our infrastructure, APIs, and client data. You will lead the technical security function within Breakthrough's product organization, while collaborating with our CTO and Corporate InfoSec team to shape and align strategy. This role will drive cloud security, threat detection, infrastructure-as-code (IaC) policy enforcement, and DevSecOps enablement with a focus on automation, scalability, and practical risk reduction. It's ideal for someone who enjoys solving problems with code, thrives in a high-ownership environment, and values balancing product development agility with sound security fundamentals.

We're seeking individuals who excel in collaborative environments, are driven by the "why" behind their work and the core problems they're trying to solve, and are eager to develop innovative solutions while influencing the evolution of our systems, teams, and culture.

"At Breakthrough, we're figuring out things for the first time; things that no
one else has ever done before" - Engineering leader, Breakthrough JOB RESPONSIBILITIES

What You'll Do

Technical Leadership

  • Provide technical guidance and security expertise across engineering teams.

  • Lead the implementation of security best practices and advocate for secure design, development, and deployment processes.

  • Collaborate with Engineering Directors, Principal Engineers, and Corporate InfoSec to align security strategy with product and platform goals.

  • Serve as the primary security point of contact within the Engineering organization.

Development & Automation

  • Design and implement security tooling and automation to support DevSecOps practices.

  • Write scripts and lightweight tools (e.g., in Python, Bash) to automate detection, remediation, and compliance workflows.

  • Contribute to infrastructure and CI/CD security by embedding secure guardrails in Terraform, Bitbucket pipelines, and deployment pipelines.

Architectural Design

  • Lead threat modeling and secure architecture reviews across our GCP-native SaaS platform.

  • Partner with Cloud Engineering to integrate security into infrastructure provisioning and platform components.

  • Translate compliance and security frameworks (e.g., SOC 2, NIST 800-53, FedRAMP, CIS Controls) into actionable, scalable policies and controls in infrastructure and code.

  • Evaluate and recommend security technologies with input from CTO and Corporate InfoSec - including GCP-native tools, CrowdStrike, and modern SIEM/SOAR platforms.

Technical Excellence

  • Drive the evaluation and adoption of cloud-native and modern security tools (e.g., Google SCC, Chronicle, Panther, CrowdStrike).

  • Build and tune threat detection capabilities to identify and respond to cloud misuse, API abuse, and potential data exfiltration.

  • Maintain incident response playbooks and lead security incident investigations in collaboration with Corporate InfoSec.

Innovation and Research

  • Stay current with cloud security trends, threat actor TTPs (tactics, techniques, and procedures), and evolving best practices.

  • Proactively identify opportunities to reduce risk and increase automation across the SDLC and cloud environment.

Collaboration

  • Partner with engineering teams to foster a culture of secure coding and continuous improvement in security posture.

  • Collaborate with Breakthrough's GRC Lead and Sr. Director of Technology Operations on audits and client due diligence.

  • Participate in periodic reviews with Corporate InfoSec to ensure alignment and maintain a strong security posture.

  • Mentor engineers in secure development practices and support team learning on threat modeling, authentication, and data protection.

This Role Might Be a Great Fit If...

  • You're enthusiastic about tackling complex challenges and can distill them into actionable solutions.

  • Understanding the underlying purpose of your work motivates you, beyond merely delivering features.

  • You thrive in collaborative settings, engaging with engineers, product owners, and designers to achieve common goals.

  • You're committed to advancing sustainability in transportation and reducing environmental impact through technological innovation.

This Role Might Not Be the Best Fit If...

  • You prefer working in isolation or solely on predefined tasks without broader context.

  • Adaptability to shifting priorities in a dynamic environment is challenging for you.

  • Collaborating with non-engineering disciplines, such as product and design, doesn't align with your working style.

  • You seek a rigid hierarchical structure to guide all decision-making processes.

  • Mentoring others and contributing to team growth aren't areas of interest for you.

How We Work

  • Hybrid-Friendly: While many team members are based in Green Bay, we embrace remote work and prioritize impact over location.

  • Cross-Functional Teams: You'll be part of an agile team comprised of product owners, designers, QA specialists, and fellow engineers, fostering a holistic approach to product development.

  • Continuous Improvement: We regularly conduct retrospectives, refine our processes, and invest in addressing technical debt to enhance our workflows.

  • Empowered Engineers: Beyond task execution, you're encouraged to influence both what we build and how we build it, ensuring alignment with our strategic objectives.

QUALIFICATIONS

What You Bring

  • Bachelor's degree in Computer Science or a related technical field involving coding (e.g., physics or mathematics), or equivalent technical experience.

  • 10+ years of experience in security engineering, cloud security, DevSecOps, or related technical domains, ideally within a SaaS or product-focused organization.

  • In-depth experience designing and implementing scalable, cloud-native security solutions, with a strong understanding of Google Cloud Platform (GCP) services such as IAM, VPC, Security Command Center, Workload Identity, and GKE.

  • Strong proficiency in multiple programming or scripting languages, specifically Python, Go, and Bash, with an emphasis on automation and tool development.

  • Demonstrated experience with infrastructure as code (IaC) and policy as code, including tools such as Terraform, CI/CD pipelines, and frameworks like OPA or Sentinel.

  • Hands-on experience with modern SIEM/SOAR platforms (e.g., Chronicle, Panther) and the ability to develop high-fidelity detection logic.

  • Expertise in secure development practices, application security, threat modeling, and advising on secure architecture.

  • Familiarity with compliance frameworks such as SOC 2, NIST 800-53, CIS Controls, and translating them into technical controls and processes.

  • Experience with Agile software development methodologies including Kanban and Scrum.

  • Excellent problem-solving skills and the ability to navigate complex technical and security challenges.

  • Strong communication skills, with the ability to articulate complex security concepts to both technical and non-technical stakeholders.

Preferred:

  • Relevant certifications such as Google Professional Cloud Security Engineer, Certified Information Systems Security Professional (CISSP), or Certified Cloud Security Professional (CCSP).

  • Familiarity with DevOps and platform engineering practices and tools.

  • Prior experience working in a cross-functional product engineering team.

  • Demonstrated leadership experience in guiding teams or influencing security strategy across an organization.

Tech We Use

  • Backend: Python, Postgres

  • Frontend: Node, React, TypeScript, graphQL

  • Cloud & Infrastructure: Google Cloud Platform (GCP), Terraform, Docker

  • Data & Analytics: BigQuery, dbt

  • Monitoring & Observability: GCP Monitoring

While expertise in every technology isn't required, familiarity with our stack is beneficial. We're keen to work with individuals who bring relevant experience and a willingness to learn.

Why Breakthrough

  • Mission-Driven Work: Engage in projects that have a tangible impact on the economy and the environment.Hear more about our innovation in this video.

  • Supportive Culture: Experience a workplace that values autonomy, growth, and meaningful contributions.

  • Leadership Opportunities: Take on roles that allow you to mentor, guide, and shape the future of our products and technological direction.

  • Established Backing: As a U.S. Venture company, we benefit from a legacy of innovation and a commitment to sustainable practices.

Apply Now

If you're driven to be part of developing smarter, cleaner transportation solutions and want to be part of a team that's making a difference, we'd love to hear from you!

DIVISION:

Breakthrough

U.S. Venture requires that a team member have and maintain authorization to work in the country in which the role is based. In general, U.S. Venture does not sponsor candidates for nonimmigrant visas or permanent residencyunless based on business need.

U.S. Venture will not accept unsolicited resumes from recruiters or employment agencies. In the absence of an executed recruitment Master Service Agreement, there will be no obligation to any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without an agreement, U.S. Venture shall reserve the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of U.S. Venture.

U.S. Venture, Inc. is an equal opportunity employer that is committed to inclusion and diversity. We ensure equal opportunity for all applicants without regard to race, color, religion, sex, sexual orientation, gender, gender identity or expression, marital status, age, national origin, disability, veteran status, genetic information, or other protected characteristic. If you need assistance or an accommodation due to a disability, you may call Human Resources at (920) 739-6101.

Applied = 0

(web-696f97f645-4mdcj)