- Salary
- $156k – $224k
- Location
- Office - 4353 North 1st Street, United States of America
- Workplace
- Onsite
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Experience
- 10+ years
- Education
- Bachelor
- Source
- Workday
Description
At Bloom Energy, our vision for a world powered by clean, reliable, and affordable energy is more than just a dream—we’re making it reality.
For over two decades, we’ve been at the forefront of the global energy transition, pioneering solutions that empower critical industries to thrive in a rapidly digitizing, energy-intensive world. From revolutionizing power for AI-driven data centers to ensuring resilience for hospitals, electric grids, manufacturing facilities, and utilities, our solid oxide fuel cell (SOFC) and solid oxide electrolyzer (SOEC) technologies are redefining what’s possible by delivering energy abundance for all. With more than 30,000 fuel cell modules deployed worldwide, we are the trusted partner for Fortune 100 companies and innovators alike. Our cutting-edge solutions enable unparalleled “time-to-power” capabilities, reliability, and sustainability, ensuring our customers remain ahead in a world where soaring energy demand and intensifying energy scarcity are rapidly becoming the new norm.
At Bloom, we thrive on collaboration, bold thinking, and relentless innovation. We believe that, together, we can create a brighter, more sustainable future while tackling the most pressing challenges of the 21st century.
We are looking for a Principal Cloud Security Engineer to join our team in one of today’s most exciting technologies. This role will report to Senior Manager, Cloud Engineering and based in San Jose, CA. This is a fully on-site, in office role 5 days a week.
Cloud Security Engineering
Design, implement, automate, and maintain security architectures, controls, and processes across AWS and Microsoft Azure environments
Develop and maintain cloud security reference architectures, patterns, and guardrails aligned with industry best practices and Bloom Energy security standards
Build and operationalize security baseline controls integrated into CI/CD pipelines and Infrastructure-as-Code deployments
Implement policy-as-code and automated compliance validation across cloud environments
Review and approve security-sensitive infrastructure and application changes, including IAM policies, network security controls, secrets management, and cloud-native services
Serve as the cloud security subject matter expert supporting enterprise cloud transformation initiatives across IaaS, PaaS, and SaaS platforms
AI & Machine Learning Security
Define and implement security frameworks for AI/ML systems across the full model lifecycle, including data ingestion, model training, deployment, and monitoring
Assess and mitigate emerging AI security risks such as adversarial attacks, prompt injection, model theft, model inversion, and data poisoning
Secure AI/ML platforms and services including Amazon SageMaker, Bedrock, Azure Machine Learning, OpenAI APIs, and other enterprise AI tooling
Collaborate with AI engineering and data science teams to integrate security controls into MLOps pipelines and AI governance processes
Monitor evolving AI regulations, standards, and frameworks including NIST AI RMF and global AI governance initiatives, translating them into actionable controls and engineering practices
Data Security
Implement and manage Data Security Posture Management (DSPM) capabilities to identify and reduce sensitive data exposure across cloud environments
Design and enforce controls for structured and unstructured data platforms including databases, data lakes, warehouses, object storage, and analytics platforms such as AWS S3.
Drive adoption of data-centric security controls including encryption, tokenization, data classification, retention, and access governance
Partner with application and analytics teams to embed secure data handling practices into engineering workflows
Security Architecture & Leadership
Provide deep technical expertise across cloud, AI, infrastructure, identity, and application security domains
Lead security assessments and threat modeling exercises for cloud services, AI/ML platforms, enterprise applications, and emerging technologies
Enable secure innovation by partnering with engineering teams early in the design and development lifecycle
Support incident response, investigation, and remediation activities related to cloud, AI, and data security events
Collaborate closely with Information and OT Security, Infrastructure, Product Engineering, and Enterprise Architecture teams to drive secure technology adoption across the organization
Contribute to the development of security standards, policies, and operational procedures aligned with business and regulatory requirements
What You Bring
Mindset
Self-starter with strong ownership mentality and ability to manage multiple priorities in a dynamic environment
Passion for DevSecOps, automation, and engineering scalable security solutions
Strong curiosity and practical understanding of the evolving AI threat landscape and modern cloud-native technologies
Collaborative mindset with ability to work effectively across engineering, infrastructure, AI, data, and security teams
Strong communication skills with the ability to influence technical and business stakeholders
Desire to continuously improve security maturity while enabling business agility and innovation
Qualifications
Required
Bachelor's degree in computer science, Engineering, Information Technology, Cybersecurity, or related field
10+ years of experience in security engineering, cloud security architecture, or cybersecurity operations
Strong hands-on expertise with AWS and/or Microsoft Azure security services and cloud-native architectures
Experience implementing security automation within CI/CD and Infrastructure-as-Code environments
Deep understanding of IAM, network security, encryption, secrets management, logging, monitoring, and threat detection
Experience securing enterprise data platforms and modern cloud-native applications
Strong knowledge of security frameworks and best practices including NIST, CIS, Zero Trust, and secure SDLC principles
Preferred
Experience securing AI/ML platforms, GenAI services, or MLOps pipelines
Familiarity with AI governance, AI security risks, and emerging regulatory frameworks
Experience with DSPM, CSPM, CNAPP, SIEM, SOAR, and modern cloud security tooling
Security certifications such as CISSP, CCSP, CCSK, AWS Certified Security Specialty, or Microsoft Certified: Azure Security Engineer Associate
Preferred additional certifications or training in AI security or data privacy/security domains (e.g., CDPSE, CIPP, AI security certifications)
Bloom Energy is an equal opportunity employer and makes employment decisions on the basis of merit. We are committed to compliance with all applicable laws providing equal employment opportunities. All qualified applicants, will receive consideration for employment without regard to race, sex, color, religion, national origin, protected veteran status, or on the basis of disability. Bloom Energy makes reasonable accommodations, consistent with applicable laws, for the known physical or mental limitations of an otherwise qualified applicant or employee with a disability, who can perform the essential job functions, unless undue hardship would result.
At Bloom Energy, we are committed to supporting the well-being of our employees and their families. Our comprehensive benefits package for eligible employees includes competitive Medical, Dental, and Vision plans with a large employer contribution, a 401(k) Retirement Plan with company match, generous Mental Health Support services, Legal services, virtual Physical Therapy access, and Fertility & Family Forming benefits.
Bloom Energy is committed to fair and equitable compensation practices.
FULL TIME ROLE ONLY: The total compensation for this position includes standard company benefits and is based on various factors including, but not limited to, relevant skills and experience.
#LI-NP