2 months ago
Milan, ItalySenior
Responsibilities
- Own and improve the security posture of Docebo’s multi-account AWS environments, including service control policies, guardrails, baseline configurations, network segmentation, IAM boundaries, and data protection controls.
- Integrate security controls and scanning into infrastructure-as-code and CI/CD workflows using shift-left cloud-security practices.
- Participate in security incident on-call rotations, including triage, containment, escalation, investigation, root-cause analysis, and post-mortem documentation.
- Build and maintain cloud-native threat detection coverage using CloudTrail, GuardDuty, SIEM integrations, and MITRE ATT&CK for Cloud-aligned detection logic.
- Own vulnerability and configuration management for cloud workloads and drive remediation with engineering and infrastructure teams.
- Define and enforce least-privilege IAM, permission boundaries, cross-account roles, federated identity, and just-in-time access practices.
- Develop cloud-security policies, procedures, best practices, documentation, and training for engineering and infrastructure teams.
- Maintain security-vendor relationships and coordinate technical issues and escalations.
Requirements
- 5+ years of relevant cybersecurity experience focused on cloud security in production AWS environments.
- Deep hands-on experience with AWS security services including IAM, SCPs, CloudTrail, GuardDuty, Config, KMS, and VPC security.
- Knowledge of Kubernetes security, including RBAC, pod security standards, network policies, admission controllers, and secrets management.
- Experience with CSPM and CWPP/CNAPP tools, container and image security, runtime protection, and supply-chain risk.
- Experience securing Terraform and CloudFormation IaC pipelines and integrating security scanning into CI/CD workflows.
- Experience with SIEM, detection engineering, cloud-native detection rules, and threat hunting across CloudTrail and application logs.
- Experience using Python, Bash, or similar scripting languages to build security tooling and automate workflows.
- Strong IAM fundamentals, including least privilege, cross-account roles, permission boundaries, federated identity, and privileged access management.
- Multi-cloud exposure across Azure and GCP in addition to AWS.
- Knowledge of MITRE ATT&CK for Cloud, CIS Benchmarks, the AWS Well-Architected Security Pillar, NIST CSF, SOC 2, and ISO 27001.
- Ability and willingness to participate in an after-hours on-call rotation and communicate complex technical issues clearly to non-technical stakeholders.
- Security certifications from ISC2, ISACA, SANS, or CompTIA and cloud architecture certifications such as AWS Security Specialty or AWS Solutions Architect are advantageous.
Benefits
- Hybrid work arrangement with three days per week in the office, Tuesday through Thursday, and flexibility on the remaining days.
- Employee Share Purchase Plan with a 15% discount and a competitive compensation package.
- Health benefits and programs supporting physical, mental, and financial well-being.
- Paid vacation days, two company-wide Docebo Days, floating cultural holidays, and a birthday day off.
- Family coverage and time-off support for new parents.
- Employee Resource Groups and company-wide events.