1GLOBAL

Senior Cloud Security Engineer

1GLOBAL

full-time

Posted on:

Origin:  • 🇵🇹 Portugal

Visit company website
AI Apply
Apply

Job Level

Senior

Tech Stack

AnsibleAWSAzureCloudFirewallsFluxGoGoogle Cloud PlatformKubernetesLinuxPackerPythonTerraform

About the role

  • Embed security into every stage of the infrastructure lifecycle, from design to deployment
  • Design and implement scalable cloud security controls in AWS multi-account environments
  • Lead Kubernetes security architecture, including PodSecurity, RBAC, and network policies
  • Enforce zero trust network architecture and secure segmentation across cloud and hybrid environments
  • Integrate security automation into CI/CD pipelines (image scanning, SAST, IaC analysis)
  • Deploy and manage endpoint and vulnerability management tools such as CrowdStrike and Tenable
  • Continuously monitor infrastructure for vulnerabilities, threats, and misconfigurations
  • Enforce least privilege IAM policies and secure secrets management
  • Conduct regular audits, penetration testing, and hardening of cloud workloads and host systems
  • Conduct network traffic inspection using VPC Flow Logs, packet capture, or NetFlow
  • Tune and respond to alerts from WAF, IDS/IPS, and SIEM systems
  • Collaborate with DevOps and IP teams on security-as-code principles and secure-by-default practices
  • Document security controls, incident response playbooks, and operational runbooks
  • Champion a security-first culture through collaboration, training, and awareness
  • Proactively identify risks, secure network perimeters, and automate remediation where possible

Requirements

  • A minimum of 5 years in DevSecOps, Cloud Security, or Infrastructure Security roles
  • Strong expertise in AWS security services (IAM, KMS, GuardDuty, Config, Security Hub, etc.)
  • In-depth understanding of network security principles (firewalls, routing, segmentation, VPNs, IPsec, etc.)
  • Proven hands-on experience with Kubernetes security (RBAC, NetworkPolicies, OPA/Gatekeeper, Admission Controllers)
  • Experience operating CrowdStrike Falcon and Tenable Nessus / Tenable.io
  • Experience with WAFs, DDoS protection, NIDS/NIPS, and threat intelligence integrations
  • Comfortable with packet inspection, flow analysis, and traffic monitoring (tcpdump, Wireshark, Suricata, etc.)
  • Proficiency in Infrastructure as Code (Terraform, Terragrunt) and configuration management (Ansible, Packer)
  • Strong scripting/programming skills (Python, Go, or Bash) for automation and tooling
  • Solid understanding of Linux security hardening and secure cloud networking
  • Familiarity with service mesh security in Istio or similar
  • Experience with GitOps workflows using tools like Argo CD or Flux
  • Understanding of vulnerability management, secure software development lifecycle (SSDLC), and security controls for containers
  • Exposure to compliance frameworks like ISO 27001, SOC2, NIST, PCI-DSS is a plus
  • Excellent analytical and problem-solving skills with a proactive mindset
  • Certifications such as AWS Certified Security Specialty, CKS, OSCP, or CISSP is a plus
  • Experience with multi-cloud security (Azure/GCP)
  • Background in ethical hacking, bug bounty programs, or red teaming
  • Familiarity with tools like Falco, Sysdig, Trivy, or eBPF-based runtime security tools
Onit

Senior Security Engineer

Onit
Seniorfull-time🇺🇸 United States
Posted: 13 days agoSource: onit.applytojob.com
AnsibleAWSCloudEC2FirewallsLinuxPythonTerraform
CrowdStrike

Senior Engineer, Identity and Access Management – Product Security

CrowdStrike
Seniorfull-time$140k–$215k / year🇺🇸 United States
Posted: 26 days agoSource: crowdstrike.wd5.myworkdayjobs.com
AnsibleAWSAzureCloudCyber SecurityDistributed SystemsGoGoogle Cloud PlatformLinuxPythonSaltStackTerraform+1 more
Abnormal Security

Demo Systems Engineer

Abnormal Security
Mid · Seniorfull-time$127k–$149k / year🇺🇸 United States
Posted: 32 days agoSource: boards.greenhouse.io
AnsibleAWSAzureCloudCyber SecurityDockerGoGoogle Cloud PlatformKubernetesPythonSplunkTerraform
Claroty

Site Reliability Engineer – FedRAMP, AWS GovCloud, Public Sector

Claroty
Mid · Seniorfull-time$200k–$260k / yearNew York · 🇺🇸 United States
Posted: 18 days agoSource: www.comeet.com
AnsibleAWSCloudCyber SecurityDockerEC2FirewallsGrafanaIoTJenkinsKubernetesLinux+3 more
Coalfire

Cloud Infrastructure Administrator II

Coalfire
Juniorfull-time$64k–$112k / year🇺🇸 United States
Posted: 18 days agoSource: jobs.lever.co
AnsibleAWSAzureCloudCyber SecurityDNSDockerGoogle Cloud PlatformGrafanaKubernetesLinuxPrometheus+4 more