Cloud Security Engineer at WinCo Foods
BOISE, ID
—
Jul 19, 2026
BOISE, ID
Jul 21, 2026
What this job asks for AI summary
A senior individual contributor role focused on securing cloud infrastructure (AWS, Azure, GCP) and SaaS platforms for a large retail grocery chain. Day-to-day work spans designing cloud and SaaS security architectures, managing posture management tools (CSPM/SSPM), enforcing identity and access controls, conducting configuration audits, and leading incident response for cloud-related threats. Suited to an experienced security engineer with at least six years in cloud or cybersecurity who can operate across technical and governance domains.
Senior level · 6+ years · Boise City, ID · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 8 people in the Boise City, ID area plausibly meet what this posting asks for (information security analysts). range 4–15
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $108,351 (middle half $83,875–$141,239).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
WinCo Foods is headquartered in Boise, ID; no explicit work location or remote policy is stated in the posting, so the CBSA is inferred from company HQ and remote is set to false.
The degree requirement states 'Bachelors in a technology related discipline OR demonstrated equivalent experience,' so no hard degree gate is set.
The required skills list names 'proficiency in 2 or more of the following (or similar)' covering a broad menu (SIEM, EDR, Web Security, Firewall, Email Security, NDR, Password Management, PAM, PCI, IAM, GRC, Vulnerability Management, SSO, MFA, BCP, DR). Only the items most directly tied to the core cloud/SaaS security duties described throughout the JD (SSO, MFA, IAM, SSPM, CSPM) are marked required; the remaining menu items are marked preferred since the JD explicitly requires only two from the list.
Cloud certifications (cloud security, vendor, Security+, CISSP) appear under Preferred Qualifications and are marked accordingly.
AWS, Azure, and GCP are listed together with 'and/or' framing; AWS is used as the primary skill name with Azure and GCP as alternatives, but Azure is also emitted separately given the role's explicit multi-cloud scope and the 'and/or' phrasing — both are hard gates on cloud platform knowledge.
No compensation range is disclosed in the posting.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Privileged Access Management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.