Docebo

Senior Security Engineer

Docebo
Apply
2 months ago
Milan, ItalySenior

Responsibilities

  • Own and improve the security posture of Docebo’s multi-account AWS environments, including service control policies, guardrails, baseline configurations, network segmentation, IAM boundaries, and data protection controls.
  • Integrate security controls and scanning into infrastructure-as-code and CI/CD workflows using shift-left cloud-security practices.
  • Participate in security incident on-call rotations, including triage, containment, escalation, investigation, root-cause analysis, and post-mortem documentation.
  • Build and maintain cloud-native threat detection coverage using CloudTrail, GuardDuty, SIEM integrations, and MITRE ATT&CK for Cloud-aligned detection logic.
  • Own vulnerability and configuration management for cloud workloads and drive remediation with engineering and infrastructure teams.
  • Define and enforce least-privilege IAM, permission boundaries, cross-account roles, federated identity, and just-in-time access practices.
  • Develop cloud-security policies, procedures, best practices, documentation, and training for engineering and infrastructure teams.
  • Maintain security-vendor relationships and coordinate technical issues and escalations.

Requirements

  • 5+ years of relevant cybersecurity experience focused on cloud security in production AWS environments.
  • Deep hands-on experience with AWS security services including IAM, SCPs, CloudTrail, GuardDuty, Config, KMS, and VPC security.
  • Knowledge of Kubernetes security, including RBAC, pod security standards, network policies, admission controllers, and secrets management.
  • Experience with CSPM and CWPP/CNAPP tools, container and image security, runtime protection, and supply-chain risk.
  • Experience securing Terraform and CloudFormation IaC pipelines and integrating security scanning into CI/CD workflows.
  • Experience with SIEM, detection engineering, cloud-native detection rules, and threat hunting across CloudTrail and application logs.
  • Experience using Python, Bash, or similar scripting languages to build security tooling and automate workflows.
  • Strong IAM fundamentals, including least privilege, cross-account roles, permission boundaries, federated identity, and privileged access management.
  • Multi-cloud exposure across Azure and GCP in addition to AWS.
  • Knowledge of MITRE ATT&CK for Cloud, CIS Benchmarks, the AWS Well-Architected Security Pillar, NIST CSF, SOC 2, and ISO 27001.
  • Ability and willingness to participate in an after-hours on-call rotation and communicate complex technical issues clearly to non-technical stakeholders.
  • Security certifications from ISC2, ISACA, SANS, or CompTIA and cloud architecture certifications such as AWS Security Specialty or AWS Solutions Architect are advantageous.

Benefits

  • Hybrid work arrangement with three days per week in the office, Tuesday through Thursday, and flexibility on the remaining days.
  • Employee Share Purchase Plan with a 15% discount and a competitive compensation package.
  • Health benefits and programs supporting physical, mental, and financial well-being.
  • Paid vacation days, two company-wide Docebo Days, floating cultural holidays, and a birthday day off.
  • Family coverage and time-off support for new parents.
  • Employee Resource Groups and company-wide events.
Docebo

About Docebo

1,001-5,000 employees
Contact me