Senior Cloud Security Engineer

CoStar Group, US-DC Washington DC

Work at CoStar Group

Senior Cloud Security Engineer

Job Description


CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces.  Included in the S&P 500 Index and the NASDAQ 100, CoStar Group is on a mission to digitize the world’s real estate, empowering all people to discover properties, insights and connections that improve their businesses and lives. 

We have been living and breathing the world of real estate information and online marketplaces for over 35 years, giving us the perspective to create truly unique and valuable offerings to our customers.  We’ve continually refined, transformed and perfected our approach to our business, creating a language that has become standard in our industry, for our customers, and even our competitors.  We continue that effort today and are always working to improve and drive innovation.  This is how we deliver for our customers, our employees, and investors.  By equipping the brightest minds with the best resources available, we provide an invaluable edge in real estate.   

Our security team is looking for a Senior Cloud Security Engineer who can identify and implement security improvements across private and public clouds utilized in the delivery of CoStar’s customer facing products and corporate applications.  Implement secure practices, defense in-depth and monitoring and event response tool sets to handle growing threats in the cloud.  Work closely with other operations and development teams to refine and enforce security practices.

This position can be located in Washington, DC or Richmond, VA and offers a hybrid schedule of 3 days on-site and 2 days remote.


  • Engineer and maintain security solutions in a dynamic private and public cloud environment.
  • Secure applications and infrastructure in a large multi-account AWS Organization
  • Establish and maintain least-privilege access to resources
  • Respond to security events and incidents generated from security tools
  • Integrate security tools into SIEM and SOAR platforms to feed to security operations
  • Participate in architecture design reviews providing security guidance for application and enterprise infrastructure in cloud native workloads
  • Secure container workloads during build and at runtime
  • Promote and evangelize security best practices throughout application lifecycle
  • Continuously assess and validate security controls
  • Derive security context from various log sources
  • Create scalable detective, preventative, and reactive security controls

Basic Qualifications

  • Bachelor’s Degree required from an accredited, not for profit university or college (preferably in Computer Science, Cybersecurity or a related field)
  • A track record of commitment to prior employers 
  • 5+ years of cybersecurity experience
  • Relevant experience areas (deep expertise required in at least 3):
    • Engineering cloud security guard rails in AWS, Azure, or GCP at scale
    • Strong understanding of serverless technologies and security implications deployed in public cloud – AWS Lambda, Containers (ECS Fargate, EKS), etc.
    • Securing container images at rest, build, and runtime.
    • Deploying automated security tooling in CI/CD pipelines.
    • Cloud Security Posture Management (CSPM) tools – Cloud Custodian, Prisma Cloud, AWS Config,, AWS Security Hub, Azure Security Center, InsightCloudSec, etc.
    • Infrastructure as Code (IaC) –Terraform, AWS Cloudformation, ARM, etc.
    • Scripting languages such as PowerShell, Python, GoLang, etc.
    • Key Management - Privileged account management solutions in the cloud for key management, service account and secrets management, rotation, and event response, including tools such as Secret Server (Thycotic), Vault (HashiCorp), Cloud KMS, or similar tool set.
    • Industry relevant professional certifications including but not limited to: ISC-2 CISSP, ISC-2 CCSP, SANS GIAC Cloud Security Automation (GCSA), SANS GIAC Cloud Penetration Tester (GCPN), SANS GIAC Public Cloud Security (GPCS), CCSK, AWS Solutions Architect – Associate, AWS Solutions Architect – Professional, AWS SysOps Administrator – Associate, AWS Certified Security – Specialty, Azure Security Engineer Associate, Certified Kubernetes Security Specialist (CKS), Certified Kubernetes Administrator (CKA)

Preferred Qualifications And Skills

  • Experience with AWS native security tools across a multi-region and multi-account deployment: GuardDuty, Detective, SecurityHub, Inspector, Config. Etc.
  • A strong understanding of managed Kubernetes platforms such as EKS, GKE, AKS.
  • Strong understanding of security in core AWS services (EC2, ECS, Lambda, IAM, RDS, DynamoDB, etc.)
  • Ability to communicate with different levels of leadership conveying risk and driving urgency for risk remediation.
  • Experience coordinating with Application Security teams to drive security tooling into the pipelines.
  • Ability to mentor and train team members to work effectively and securely in the cloud.
  • A self-starter who can advance the cloud security program and follow-through ideas to completion.
  • Hands-on experience implementing security tools into CI/CD pipelines.

What’s in it for You

When you join CoStar Group, you’ll experience a collaborative and innovative culture working alongside the best and brightest to empower our people and customers to succeed.

We offer you generous compensation and performance-based incentives. CoStar Group also invests in your professional and academic growth with internal training, tuition reimbursement, and an inter-office exchange program.

Our benefits package includes (but is not limited to):

  • Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug
  • Life, legal, and supplementary insurance
  • Virtual and in person mental health counseling services for individuals and family
  • Commuter and parking benefits
  • 401(K) retirement plan with matching contributions
  • Employee stock purchase plan
  • Paid time off
  • Tuition reimbursement
  • On-site fitness center and/or reimbursed fitness center membership costs (location dependent), with yoga studio, Pelotons, personal training, group exercise classes
  • Access to CoStar Group’s Diversity, Equity, & Inclusion Employee Resource Groups
  • Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks

We welcome all qualified candidates who are currently eligible to work full-time in the United States to apply.  However, please note that CoStar Group is not able to provide visa sponsorship for this position.



CoStar Group is an Equal Employment Opportunity Employer; we maintain a drug-free workplace and perform pre-employment substance abuse testing

About CoStar Group

CoStar Group is the leading provider of online real estate marketplaces, information, and analytics in the commercial and residential property markets.

CoStar Group

Want to learn more about CoStar Group? Visit CoStar Group's website.