16 days ago
London, United KingdomSenior
Responsibilities
- Own and improve the security posture of Docebo’s AWS environments, including account structures, service control policies, guardrails, IAM boundaries, network segmentation, and data protection controls.
- Integrate cloud security controls and scanning into infrastructure-as-code and CI/CD workflows using shift-left practices.
- Participate in security incident on-call rotations, leading triage, containment, investigation, escalation, root-cause analysis, and post-mortem documentation.
- Build and maintain cloud threat detection coverage using CloudTrail, GuardDuty, SIEM integrations, and MITRE ATT&CK for Cloud.
- Own cloud workload vulnerability and configuration management and drive remediation with engineering and infrastructure teams.
- Define and enforce least-privilege IAM, permission boundaries, cross-account roles, federated identity, and just-in-time access.
- Develop cloud security policies, procedures, documentation, training, and best practices for engineering and infrastructure teams.
- Manage technical relationships with security vendors and support the operation of security tools and services.
Requirements
- 5+ years of relevant cybersecurity work experience with a strong focus on cloud security in production AWS environments.
- Deep hands-on experience with AWS security services including IAM, SCPs, CloudTrail, GuardDuty, Config, KMS, and VPC security.
- Knowledge of Kubernetes security, including RBAC, pod security standards, network policies, admission controllers, and secrets management.
- Experience with CSPM and CWPP/CNAPP tools, container and image security, runtime protection, and supply-chain risk.
- Experience securing Terraform and CloudFormation IaC pipelines and integrating security scanning into CI/CD workflows.
- Experience with SIEM, detection engineering, cloud-native detection rules, and threat hunting across CloudTrail and application logs.
- Experience using Python, Bash, or similar scripting languages to build security tooling and automate workflows.
- Strong IAM fundamentals, including least privilege, cross-account roles, permission boundaries, federated identity, and privileged access management.
- Multi-cloud exposure across Azure and GCP in addition to AWS is a plus.
- Knowledge of MITRE ATT&CK for Cloud, CIS Benchmarks, the AWS Well-Architected Security Pillar, NIST CSF, SOC 2, and ISO 27001.
- Ability to participate in an after-hours on-call rotation, document incidents and architecture decisions clearly, and communicate technical issues to non-technical stakeholders.
- Security certifications from ISC2, ISACA, SANS, or CompTIA and cloud architecture certifications such as AWS Security Specialty or AWS Solutions Architect are preferred.
Benefits
- Hybrid work arrangement with three office days per week, Tuesday through Thursday, and flexibility for the rest of the week.
- Employee Share Purchase Plan with a 15% discount and a competitive compensation package.
- Health benefits supporting physical, mental, and financial well-being.
- Paid vacation, two company-wide Docebo Days, floating cultural holidays, and a birthday day off.
- Family coverage and time-off support for family needs.
- Employee resource groups and company-wide events.
- Participation in a global, collaborative workplace across North America, EMEA, and APAC.