7 days ago
Lisbon, PortugalStaff+
Responsibilities
- Build and manage cloud security programs across AWS, Azure, and GCP infrastructure.
- Design, implement, and validate secure cloud infrastructure architectures against security standards and requirements.
- Apply Zero Trust principles to cloud infrastructure design and access models.
- Detect, remediate, and resolve cloud vulnerabilities and security misconfigurations using CSPM tools and automation.
- Build automation for continuous cloud infrastructure monitoring and alerting.
- Partner with engineering teams to embed security standards and practices earlier in the development lifecycle.
- Collaborate with the SOC to develop cloud detection engineering capabilities.
- Support Risk and Governance teams with cloud security policies, procedures, and standards.
- Provide security guidance to Platform, DevOps, and Software Engineering teams.
Requirements
- 6–9 years of experience in cloud environments, with AWS as the primary platform, including hands-on cloud security architecture and infrastructure design.
- Proficiency with AWS-native security services including IAM, Config, KMS, Secrets Manager, CloudWatch, CloudTrail, and GuardDuty.
- Experience with cloud identity and access architecture, including federation, RBAC, ABAC, and service-to-service authentication models.
- Hands-on experience with Infrastructure as Code tools such as AWS CDK, CloudFormation, or Terraform.
- Relevant cloud or security certifications such as AWS Certified Solutions Architect, AWS Certified Security – Specialty, CISSP, or CCSP are preferred.
Benefits
- Competitive salary, annual performance bonus, and equity for full-time employees.
- 100% employer-paid health and dental insurance.
- Generous paid time off.
- Hybrid schedule with four days in the office and remote work on Fridays.
