About this role
Upwind is a next-generation cloud security platform that uses runtime context to identify and prioritize the risks that actually matter. Our eBPF-powered sensors and agentless posture discovery give us a unique view of cloud environments- from the first commit to the running workload
We're looking for a Cloud Security Researcher to join the platform research team. This is a chance to shape the platform end to end- expand what it sees, define how it thinks about risk, and build the AI systems that act on what it finds
What You'll Do
- Integrate new systems and domains- from cloud to shift-left tooling and AI providers- model their data, analyze and enrich it with context from across the platform to generate meaningful insights
- Map risk vectors, build threat models, and translate them into actionable posture recommendations
- Define how the platform should reason about risk, advancing posture management beyond static rules toward dynamic approaches like graph traversal and reachability analysis
- Shape how AI is applied on top of the platform's findings - from agentic systems for insight, context analysis, and remediation to smarter prioritization and prevention
- Lead research initiatives end-to-end, working with product and engineering to turn them into shipped capabilities
Requirements
- 5+ years in security research, cloud security, or DevSecOps
- Hands-on experience with at least one major cloud provider (AWS, GCP, or Azure), including its identity and data services
- Strong understanding of modern DevOps environments: CI/CD pipelines, Infrastructure-as-Code, containers, and Kubernetes
- Hands-on coding skills (e.g., Python) and comfort with query languages (e.g., SQL) and reasoning about data flows.
- Ability to own research initiatives end-to-end in a fast-moving environment
- Excellent written and spoken English
Advantages
- Experience building AI/LLM-based or agentic systems, or securing AI/ML pipelines
- Experience with DSPM, data classification, or data security tooling
- Background in supply chain security (SBOM, dependency and artifact security)
- Open-source contributions, published research, or conference talks
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?