View All Jobs 160381

Sr IT Engineer Cloud Security

Automate cloud security controls and incident response processes at scale
Bolingbrook, Illinois, United States
Senior
yesterday

Experience At Ulta Beauty

Live the experience. From professional empowerment to continual learning opportunities. From ongoing investment in new and emerging technologies to a career of self-determination. At Ulta Beauty, our tech team is critical to our scalability—and is recognized that way. We’ve been defined as a “mature start-up.” A place where interdepartmental exposure, open doors, and genuine collaboration is ubiquitous. Where challenges come fast and furious, requiring agility, mental dexterity, and creativity. Where our passion for better solutions drives us and is core to who we are.

We’re engineering for the future of retail, and it’s no-holds-barred. But for those motivated by continual change and ambiguity, by superior leadership, by whip smart colleagues who will press you daily for your very best, you’ll find that virtually nothing’s impossible at Ulta Beauty.

The Impact You Can Have

You’ll be a key contributor in automating and enforcing cloud security across Ulta Beauty’s GCP ecosystem — building guardrails, securing workloads, and integrating real-time detection and remediation capabilities to keep our cloud environments safe and compliant at scale. Ulta Beauty is seeking a Senior Cloud Security Engineer with deep, hands-on experience in securing and automating workloads within Google Cloud Platform (GCP). This role is responsible for implementing and maintaining scalable security controls, integrating security into CI/CD pipelines, and automating monitoring and remediation processes to protect data, identities, and workloads across cloud environments.

The ideal candidate has strong technical depth in GCP IAM, network security, and workload protection, with a focus on execution and automation, not architecture or solution design.

You'll Accomplish These Goals By:

  • Configure, deploy, and maintain data and infrastructure security controls across GCP and Azure environments.
  • Design and enforce Identity and Access Management (IAM) configurations.
  • Implement network security measures.
  • Secure GCP and Azure services.
  • Implement data encryption and key management strategies.
  • Automate configuration baselines, guardrails, and policy enforcement.
  • Integrate cloud-native security tools for visibility, compliance, and anomaly detection.
  • Develop automation scripts and tooling to detect, notify, and remediate misconfigurations or security drift.
  • Build and maintain CI/CD integrations for vulnerability scanning, policy validation, and data protection controls.
  • Use APIs and SDKs to connect cloud security data to central logging, SIEM, or analytics platforms.
  • Implement automated workflows for security posture management, access reviews, and incident response.

Monitoring & Incident Response

  • Configure and tune alerts from CSPM tools and GCP-native monitoring solutions.
  • Respond to cloud-related security incidents.
  • Develop and maintain detection logic and dashboards.
  • Participate in post-incident reviews.

Compliance & Risk Management

  • Execute security assessments on cloud workloads, data storage, network segmentation, and CI/CD processes.
  • Enforce compliance baselines through automated policy checks and reporting.
  • Document security controls, policies, and exceptions.
  • Evaluate and report on data security risks, IAM misconfigurations, and network exposure.

Collaboration & Support

  • Partner with DevOps, Infrastructure, and Application teams.
  • Provide technical guidance on secure networking, identity federation, workload segmentation, and encryption.
  • Support operational troubleshooting for GCP IAM, firewall rules, policy enforcement, and resource access issues.
  • Participate in on-call rotations or off-hours support for security incidents, vulnerability patching, and data protection reviews.

Essentials For Success

  • 5+ years of experience in cloud security engineering, cloud operations, or DevSecOps (GCP preferred)
  • Hands-on GCP expertise with strong understanding of IAM, networking, KMS, audit logging, and policy enforcement.
  • Strong scripting proficiency in Python, PowerShell, or similar languages.
  • Experience automating with Terraform, Cloud SDK, or GCP API integrations.
  • Familiarity with CI/CD tools and integrating security scanning.
  • Experience with CSPM solutions and log analysis tools.
  • Working knowledge of federated identity, SAML, and Google Cloud Directory Sync (GCDS).
  • Strong understanding of cloud security frameworks.

Preferred Certifications

  • Google Cloud Certified – Professional Security Engineer
  • ISC² CISSP or CCSP
  • ISACA CISM, CISA, or equivalent
  • Experience with container security

Soft Skills

  • Strong troubleshooting and analytical mindset with attention to detail.
  • Comfortable working in fast-moving cloud environments with minimal supervision.
  • Excellent communication skills with both technical and non-technical teams.
  • Highly accountable and proactive — able to identify risks before failures occur.

The pay range for this position is $102,900.00 - $145,000.00 / Year with the opportunity for eligible associates to earn additional compensation pursuant to the Company's bonus plan. Exact pay will be based on factors including, but not limited to relevant education, qualifications, certifications, experience, level, shift, geographic location, and business and organizational needs. Full-time positions are eligible for paid time off, health, dental, vision, life and disability benefits. Part-time positions are eligible for dental, vision, life, and disability benefits. For additional information concerning our benefits, visit our Benefits and Career Development page.

About Ulta Beauty

At Ulta Beauty (NASDAQ: ULTA), the possibilities are beautiful. Ulta Beauty is the largest North American beauty retailer and the premier beauty destination for cosmetics, fragrance, skin care products, hair care products, and salon services. We bring possibilities to life through the power of beauty each and every day in our stores and online with more than 25,000 products from approximately 500 well-established and emerging beauty brands across all categories and price points, including Ulta Beauty’s own private label. Ulta Beauty also offers a full-service salon in every store featuring—hair, skin, brow, and make-up services.

We will consider for employment all qualified applicants, including those with arrest records, conviction records, or other criminal histories, in a manner consistent with the requirements of any applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York City Fair Chance Act.

+ Show Original Job Post
























Sr IT Engineer Cloud Security
Bolingbrook, Illinois, United States
Engineering
About Ulta Beauty