Talent.com
Sr IT Engineer Cloud Security
Sr IT Engineer Cloud SecurityUlta Beauty • Bolingbrook, IL, United States
Sr IT Engineer Cloud Security

Sr IT Engineer Cloud Security

Ulta Beauty • Bolingbrook, IL, United States
13 days ago
Job type
  • Full-time
  • Part-time
Job description

OVERVIEW

Live the experience . From professional empowerment to continual learning opportunities. From ongoing investment in new and emerging technologies to a career of self-determination. At Ulta Beauty, our tech team is critical to our scalability-and is recognized that way. We've been defined as a "mature start-up." A place where interdepartmental exposure, open doors, and genuine collaboration is ubiquitous. Where challenges come fast and furious, requiring agility, mental dexterity, and creativity. Where our passion for better solutions drives us and is core to who we are.

We're engineering for the future of retail, and it's no-holds-barred. But for those motivated by continual change and ambiguity, by superior leadership, by whip smart colleagues who will press you daily for your very best, you'll find that virtually nothing's impossible at Ulta Beauty.

THE IMPACT YOU CAN HAVE :

You'll be a key contributor in automating and enforcing cloud security across Ulta Beauty's GCP ecosystem - building guardrails, securing workloads, and integrating real-time detection and remediation capabilities to keep our cloud environments safe and compliant at scale. Ulta Beauty is seeking a Senior Cloud Security Engineer with deep, hands-on experience in securing and automating workloads within Google Cloud Platform (GCP). This role is responsible for implementing and maintaining scalable security controls, integrating security into CI / CD pipelines, and automating monitoring and remediation processes to protect data, identities, and workloads across cloud environments.

The ideal candidate has strong technical depth in GCP IAM, network security, and workload protection , with a focus on execution and automation , not architecture or solution design.

YOU'LL ACCOMPLISH THESE GOALS BY :

Cloud Security Implementation

  • Configure, deploy, and maintain data and infrastructure security controls across GCP and Azure environments (projects, folders, and org-level).
  • Design and enforce Identity and Access Management (IAM) configurations - roles, service accounts, and permissions - following least-privilege and zero-trust principles .
  • Implement network security measures such as firewall rules, VPC Service Controls, Private Service Connect, and secure interconnects to safeguard data in motion.
  • Secure GCP and Azure services including Cloud Storage, GKE, Cloud SQL, Pub / Sub, Cloud Functions, and Dataflow with a focus on data confidentiality and workload isolation .
  • Implement data encryption and key management strategies using Cloud KMS, CMEK, and HSM integrations .
  • Automate configuration baselines, guardrails, and policy enforcement using Terraform, Cloud Build, or Deployment Manager .
  • Integrate cloud-native security tools (Security Command Center, Cloud Logging, Cloud Monitoring) for visibility, compliance, and anomaly detection .
  • Develop automation scripts and tooling (Python, PowerShell, Go) to detect, notify, and remediate misconfigurations or security drift.
  • Build and maintain CI / CD integrations for vulnerability scanning, policy validation, and data protection controls.
  • Use APIs and SDKs to connect cloud security data to central logging, SIEM, or analytics platforms (Chronicle, Splunk, Elastic).
  • Implement automated workflows for security posture management, access reviews, and incident response .

Monitoring & Incident Response

  • Configure and tune alerts from CSPM tools (e.g., Prisma Cloud, Wiz) and GCP-native monitoring solutions for network and IAM anomalies.
  • Respond to cloud-related security incidents , including unauthorized access, network exposure, or data exfiltration attempts, by isolating resources and applying remediation.
  • Develop and maintain detection logic and dashboards to visualize network flows, IAM changes, and workload health.
  • Participate in post-incident reviews to strengthen controls for IAM, encryption, and workload security.
  • Compliance & Risk Management

  • Execute security assessments on cloud workloads, data storage, network segmentation, and CI / CD processes.
  • Enforce compliance baselines (CIS, NIST 800-53, Google Blueprint standards) through automated policy checks and reporting .
  • Document security controls, policies, and exceptions with clear technical evidence and audit readiness.
  • Evaluate and report on data security risks , IAM misconfigurations, and network exposure across cloud environments.
  • Collaboration & Support

  • Partner with DevOps, Infrastructure, and Application teams to embed security into pipelines, networks, and workloads.
  • Provide technical guidance on secure networking, identity federation, workload segmentation, and encryption .
  • Support operational troubleshooting for GCP IAM, firewall rules, policy enforcement, and resource access issues .
  • Participate in on-call rotations or off-hours support for security incidents, vulnerability patching, and data protection reviews .
  • ESSENTIALS FOR SUCCESS :

  • 5+ years of experience in cloud security engineering, cloud operations, or DevSecOps (GCP preferred)
  • Hands-on GCP expertise with strong understanding of IAM, networking, KMS, audit logging, and policy enforcement.
  • Strong scripting proficiency in Python , PowerShell , or similar languages.
  • Experience automating with Terraform , Cloud SDK , or GCP API integrations.
  • Familiarity with CI / CD tools (Jenkins, GitLab, Cloud Build) and integrating security scanning (e.g., Snyk, Trivy).
  • Experience with CSPM solutions (Prisma Cloud, Wiz, Orca) and log analysis tools (Chronicle, Splunk, or Elastic).
  • Working knowledge of federated identity , SAML , and Google Cloud Directory Sync (GCDS) .
  • Strong understanding of cloud security frameworks (CIS GCP, NIST CSF, ISO 27001).
  • Preferred Certifications

  • Google Cloud Certified - Professional Security Engineer
  • ISC² CISSP or CCSP
  • ISACA CISM, CISA, or equivalent
  • Experience with container security (GKE, Artifact Registry, or Cloud Run)
  • Soft Skills

  • Strong troubleshooting and analytical mindset with attention to detail.
  • Comfortable working in fast-moving cloud environments with minimal supervision.
  • Excellent communication skills with both technical and non-technical teams.
  • Highly accountable and proactive - able to identify risks before failures occur.
  • #LI - HYBRID

    #LI - ML1

    The pay range for this position is $102,900.00 - $145,000.00 / Year with the opportunity for eligible associates to earn additional compensation pursuant to the Company's bonus plan. Exact pay will be based on factors including, but not limited to relevant education, qualifications, certifications, experience, level, shift, geographic location, and business and organizational needs. Full-time positions are eligible for paid time off, health, dental, vision, life and disability benefits. Part-time positions are eligible for dental, vision, life, and disability benefits. For additional information concerning our benefits, visit our Benefits and Career Development page :

    ABOUT

    At Ulta Beauty (NASDAQ : ULTA), the possibilities are beautiful . Ulta Beauty is the largest North American beauty retailer and the premier beauty destination for cosmetics, fragrance, skin care products, hair care products and salon services. We bring possibilities to life through the power of beauty each and every day in our stores and online with more than 25,000 products from approximately 500 well-established and emerging beauty brands across all categories and price points, including Ulta Beauty's own private label. Ulta Beauty also offers a full-service salon in every store featuring-hair, skin, brow, and make-up services.

    We will consider for employment all qualified applicants, including those with arrest records, conviction records, or other criminal histories, in a manner consistent with the requirements of any applicable state and local laws, including the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York City Fair Chance Act.

    Create a job alert for this search

    Cloud Security Engineer • Bolingbrook, IL, United States

    Related jobs
    Lead IT Engineer - Cybersecurity

    Lead IT Engineer - Cybersecurity

    Kellanova Co. • Naperville, IL, United States
    Part-time +1
    Join Kellanova as a Lead IT Engineer - Cybersecurity! Bring your expertise in cloud and application security to a dynamic, fast-paced environment where innovation meets impact.You'll collaborate wi...Show more
    Last updated: 17 days ago • Promoted
    Sr. Specialist, Security Engineer

    Sr. Specialist, Security Engineer

    Primient • Schaumburg, IL, United States
    Full-time
    Specialist, Security Engineer | Primient.Primient is a century old company with an entrepreneurial spirit.We are a leading producer of food and industrial ingredients made from plant-based, renewab...Show more
    Last updated: 17 days ago • Promoted
    Air Interdiction Agent

    Air Interdiction Agent

    U.S. Customs and Border Protection • Wilmington, IL, US
    Full-time
    Pilot CBP Air Interdiction Agent.Air and Marine Operations (AMO), a component of U.Customs and Border Protection (CBP), offers skilled Pilots interested in law enforcement an opportunity to work wi...Show more
    Last updated: 30+ days ago • Promoted
    Cloud Security Architect - Temp to Hire

    Cloud Security Architect - Temp to Hire

    Gallagher • Rolling Meadows, IL, United States
    Full-time
    Welcome to Gallagher - a global leader in insurance, risk management, and consulting services.With a growing team of more than 52,000 professionals worldwide, we empower businesses, communities, an...Show more
    Last updated: 13 days ago • Promoted
    Security Engineer

    Security Engineer

    SEKO Logistics • Schaumburg, IL, United States
    Full-time
    SEKO started out in business in 1976, operating out of a single Chicago office.Since then, we have built a solid reputation throughout the world as an innovative and flexible provider of first-clas...Show more
    Last updated: 17 days ago • Promoted
    Lead IT Engineer - Cybersecurity

    Lead IT Engineer - Cybersecurity

    Kellanova • Naperville, IL, United States
    Part-time +1
    Join Kellanova as a Lead IT Engineer - Cybersecurity! Bring your expertise in cloud and application security to a dynamic, fast-paced environment where innovation meets impact.You'll collaborate wi...Show more
    Last updated: 17 days ago • Promoted
    Sr IT Director, Agency Management Systems (Remote)

    Sr IT Director, Agency Management Systems (Remote)

    Arthur J Gallagher & Co • Rolling Meadows, IL, US
    Remote
    Full-time
    Senior IT Director, Agency Management Systems.Welcome to Gallagher - a global community of people who bring bold ideas, deep expertise, and a shared commitment to doing what's right.We help clients...Show more
    Last updated: 27 days ago • Promoted
    Security Engineer - Ping Authorize

    Security Engineer - Ping Authorize

    Diverse Lynx • Naperville, IL, United States
    Full-time
    Expert knowledge around Ping Authorize focusing on installation, configuration, policy editing, tuning, logging, monitoring and alerting. Construct fine-grained access rules based on identity attrib...Show more
    Last updated: 30+ days ago • Promoted
    Infrastructure and Platform Architect (AWS Cloud Management)

    Infrastructure and Platform Architect (AWS Cloud Management)

    Diverse Lynx • Naperville, IL, United States
    Full-time
    Job Title : Infrastructure and Platform Architect.Mandatory Skills : AWS Cloud Management.Seeking a highly skilled and proactive Infrastructure Architect to lead incident management and technical pro...Show more
    Last updated: 30+ days ago • Promoted
    Engineer, Site Risk Management - Midwest

    Engineer, Site Risk Management - Midwest

    Constellation Energy • Lockport, IL, US
    Full-time
    As the nation's largest producer of clean, carbon-free energy, Constellation is focused on our purpose : accelerating the transition to a carbon-free future. We have been the leader in clean ener...Show more
    Last updated: 24 days ago • Promoted
    Senior Director of IT Operations

    Senior Director of IT Operations

    The Judge Group • Addison, IL, United States
    Full-time +1
    Senior Director of IT Operations.Addison, IL (hybrid 3 days per week).We are looking for a strategic and visionary Senior Director of IT Operations to lead our client’s Infrastructure and Cloud str...Show more
    Last updated: 7 days ago • Promoted
    SIEM Engineer

    SIEM Engineer

    eTeam • Elk Grove Village, IL, United States
    Full-time
    The SIEM Engineer is responsible for the design, implementation, and management of Security Information and Event Management (SIEM) systems. This role involves monitoring security events, analyzing ...Show more
    Last updated: 14 days ago • Promoted
    Senior IT Security Analyst

    Senior IT Security Analyst

    Busey Bank • Joliet, IL, United States
    Full-time
    The Senior IT Security Analyst is responsible for managing activities relating to monitoring and responding to security events. The analyst is responsible for monitoring application, host, and netwo...Show more
    Last updated: 30+ days ago • Promoted
    Senior IT Security Analyst

    Senior IT Security Analyst

    Yusen Logistics • Elk Grove Village, IL, United States
    Full-time
    Salary Range : $105,628-$177,513.IT Security Analyst is responsible for assessing information risk and facilitates remediation of identified vulnerabilities for IT security and IT risk across the en...Show more
    Last updated: 3 days ago • Promoted
    Cloud Architect

    Cloud Architect

    Navtech • Downers Grove, IL, United States
    Full-time
    Role : Cloud Solutions Architect.Location : Downer Grove, IL - Hybrid 3 days Onsite / Week.Responsibilities & Accountabilities : . Participate in architecture and design discussions that produce requireme...Show more
    Last updated: 3 days ago • Promoted
    Sr IT Security Engineer

    Sr IT Security Engineer

    Dexter Magnetic Technologies • Elk Grove Village, IL, United States
    Full-time
    Permag is a leading provider of engineered magnetic solutions through its portfolio of specialized brands—Dexter Magnetic Technologies, Electron Energy Corporation (EEC), and Magnetic Component Eng...Show more
    Last updated: 17 days ago • Promoted
    Security Engineer

    Security Engineer

    Tree Top Staffing LLC • Wheeling, IL, United States
    Full-time
    The Security Engineer is expected to perform a combination of cyber security functions such as deployment, maintenance, testing, and investigation of cyber security products, to ensure secure inter...Show more
    Last updated: 30+ days ago • Promoted
    Information Systems Security Manager

    Information Systems Security Manager

    Kranze Technology Solutions • Des Plaines, IL, United States
    Full-time
    The Information System Security Manager (ISSM) is responsible for applying and documenting Information System (IS) security principles, practices, and procedures under the Risk Management Framework...Show more
    Last updated: 30+ days ago • Promoted