Application Guide
How to Apply for Staff Cloud Security Engineer
at SPAN
๐ข About SPAN
SPAN is at the forefront of simplifying clean energy adoption by creating intuitive, user-friendly home interfaces that make renewable energy management accessible to everyone. Working here means contributing to a mission-driven team that values innovation, sustainability, and user-centered design, all while tackling the technical challenges of building a greener future.
About This Role
As a Staff Cloud Security Engineer at SPAN, you will own the security posture of our AWS-based backend, building automated security tools and DevSecOps pipelines that enable developers to ship securely without friction. Your work will directly protect millions of users and ensure the reliability of clean energy systems, making you a critical part of our platform's integrity and trustworthiness.
๐ก A Day in the Life
A typical day might start with reviewing security alerts from AWS GuardDuty and Security Hub, then pairing with a backend engineer to design a secure API endpoint for energy data. After lunch, you might write a Lambda function to automate patching of a known CVE, then lead a threat modeling session for a new feature. The day ends with updating documentation for your DevSecOps pipeline and planning the next sprint's security improvements.
๐ Application Tools
๐ฏ Who SPAN Is Looking For
- You have 6+ years in security engineering with deep hands-on experience hardening AWS environments (e.g., IAM policies, VPC design, GuardDuty, Security Hub, Config rules).
- You write production-grade code in Python, Java, or Node and have built custom security tools or automated vulnerability remediation pipelines.
- You are adept at threat modeling and security architecture reviews, especially for cloud-native systems handling sensitive user data.
- You possess a strong understanding of authentication/authorization protocols (OIDC, SAML, OAuth) and have implemented them in a microservices context.
๐ Tips for Applying to SPAN
Tailor your resume to highlight specific AWS security services you've used (e.g., AWS WAF, Shield, KMS, Secrets Manager) and quantify impact (e.g., 'reduced vulnerability detection time by 40%').
In your cover letter, mention a concrete example of building a DevSecOps pipeline that integrated security scanning (SAST/DAST) into CI/CD, and how it empowered developers.
Research SPAN's product (smart panel, app) and mention how you'd secure IoT device communication or energy data privacy in your application.
If you have experience with compliance frameworks (SOC 2, ISO 27001), highlight itโSPAN likely needs to align with these for energy sector partnerships.
Submit a portfolio or GitHub link with a security tool you've built (e.g., a custom AWS Lambda for automated incident response) to demonstrate your engineering skills.
โ๏ธ What to Emphasize in Your Cover Letter
["Your passion for clean energy and how security enables SPAN's mission to make renewable energy accessible and trustworthy.", 'Specific experience with AWS security hardening, including examples of designing secure architectures (e.g., multi-account strategy, least privilege).', 'Your ability to write code to fix vulnerabilities or build security automation, not just configure tools.', 'How you collaborate with developers to shift left on security, using a DevSecOps approach to reduce friction.']
Generate Cover Letter โ๐ Research Before Applying
To stand out, make sure you've researched:
- โ Read SPAN's blog and press releases to understand their product roadmap, especially any recent launches or partnerships in the energy sector.
- โ Explore SPAN's careers page and employee reviews on Glassdoor to understand their engineering culture and values.
- โ Familiarize yourself with the clean energy industry's security challenges, such as NISTIR 7628 guidelines for smart grid security.
- โ Check if SPAN has any open-source projects or technical talks; mentioning them in an interview shows genuine interest.
๐ฌ Prepare for These Interview Topics
Based on this role, you may be asked about:
โ ๏ธ Common Mistakes to Avoid
- Submitting a generic application that doesn't mention AWS or clean energyโtailor every application to show you understand SPAN's specific stack and mission.
- Focusing only on theoretical security knowledge without demonstrating coding skills; this role requires production-grade code, so show examples.
- Ignoring the DevSecOps aspectโdon't just list security audits; emphasize automation, CI/CD integration, and developer self-service tools.
๐ Application Timeline
This position is open until filled. However, we recommend applying as soon as possible as roles at mission-driven organizations tend to fill quickly.
Typical hiring timeline:
Application Review
1-2 weeks
Initial Screening
Phone call or written assessment
Interviews
1-2 rounds, usually virtual
Offer
Congratulations!