The posting, in Gong's own words
archived Sep 6, 2026Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System unifies data, insights, and workflows into a single, trusted system that observes, guides, and acts alongside the world’s most successful revenue teams. Powered by the Gong Revenue Graph, AI-powered intelligence, specialized agents, and trusted applications, Gong helps more than 5,000 companies around the world deeply understand their teams and customers, automate critical sales workflows, and close more deals with less effort. For more information, visit www.gong.io. At Gong, you will join a company built on innovative products, ambitious goals, and passionate people. We are shaping the future of revenue intelligence and we want people who are excited to build what comes next. You will work with a team that dreams big, moves fast, and cares deeply about the craft and about each other. Here, transparency and trust are core to how we operate, and every person has the opportunity to make a visible impact. If you want to grow, stretch, and do work that truly matters, Gong is the place to do the best work of your career.
Senior Cloud Security Engineer
We’re looking for a Senior Cloud Security Engineer to help secure Gong’s cloud infrastructure across AWS, GCP, and Azure. As part of the Cloud Security team within the Platform Security group, you will build and operate scalable security capabilities across cloud platforms, identity, Kubernetes, workloads, and developer tooling. You will work closely with Application Security, DevSecOps, Cloud Engineering, Infrastructure, and R&D to establish secure-by-default foundations, reduce cloud risk, and enable engineering teams to move quickly and securely.
Read the full posting ↓
You’ll Own:
Cloud security architecture and controls across AWS, GCP, and Azure, including identity, networking, workloads, data, and managed services. Gong’s cloud security posture management capabilities, including coverage, configuration, prioritization, and continuous improvement. Cloud vulnerability and risk management, from identification and prioritization through remediation and validation. Security guardrails for cloud infrastructure and Kubernetes, including IAM, workload identity, RBAC, network policies, secrets, and runtime protection. Cloud security monitoring, detection, and response capabilities across all supported cloud environments. Security automation and security-as-code, including reusable controls, policies, tooling, and developer-facing guardrails.
You’ll Solve:
Cloud misconfigurations, excessive permissions, exposed services, and other infrastructure-security risks. Visibility and accountability gaps across cloud security posture, vulnerabilities, and remediation. Security challenges involving identities, credentials, Kubernetes workloads, networks, and data. The need to embed effective security controls into engineering workflows without creating unnecessary friction. Emerging security risks associated with new architectures, AI services, and data-driven workloads.
You’ll Impact:
The security and resilience of Gong’s AWS, GCP, and Azure environments. A measurable reduction in cloud vulnerabilities, misconfigurations, excessive permissions, and recurring findings. The maturity of Gong’s CSPM, monitoring, vulnerability-management, and security-as-code capabilities. The ability of engineering teams to build and operate cloud services securely by default. Cloud-security decisions and standards through close collaboration with Platform Security, Application Security, DevSecOps, Cloud Engineering, and R&D.
You are:
A senior security engineer with at least 5 years of experience in Cloud Security, Infrastructure Security, Platform Security, or a closely related discipline. Experienced in designing and implementing security controls across cloud-native environments. Strong in cloud identity, least privilege, workload identities, service accounts, secrets management, and credential lifecycle security. Experienced with CSPM, cloud vulnerability management, security monitoring, and security findings remediation. Experienced in securing Kubernetes environments, including RBAC, workload identity, pod security, network policies, secrets, and runtime controls. Proficient with infrastructure as code, policy as code, and security automation using , Python, or similar technologies. Comfortable with working across AWS, GCP, and Azure, with the ability to transfer security principles between platforms. Familiar with , GitOps, GitHub, software supply-chain security, and developer platforms. Able to investigate security issues, identify root causes, and drive remediation through completion. Collaborative, pragmatic, and able to influence engineering teams without formal authority. Experience with security certifications such as CISSP, CCSP, CCSK, CKS, or cloud-security certifications is an advantage.