Remote job
Senior Product/Cloud Security Engineer
Job details
About this role
Role overview A software company building developer tools is expanding its cloud footprint and hiring a senior engineer to lead product and cloud security across AWS and GCP. The role partners with platform, SRE, and product engineering teams to embed security guardrails into developer workflows, run architecture reviews and threat modeling, and reduce risk without slowing delivery.
Responsibilities - Lead cloud security posture across AWS and GCP, covering IAM, networking, data protection, and workload configuration. - Operate and evolve cloud security and vulnerability-management platforms such as Wiz, Orca Security, Upwind, or Tenable. - Drive triage, prioritisation, and remediation of cloud findings and vulnerabilities across the engineering organisation. - Perform architecture reviews, risk evaluations, and threat modeling for cloud services, APIs, and integrations. - Integrate security checks and guardrails into CI/CD and infrastructure-as-code pipelines, and support incident response and root-cause analysis. - Define meaningful security metrics and contribute to internal standards, runbooks, and reusable security patterns.
Requirements - Established professional experience in security engineering or a closely related domain, securing SaaS products or cloud-native services. - Strong hands-on experience assessing AWS and/or GCP architecture and configurations directly, rather than relying only on tool output. - Practical background operating cloud security posture management and vulnerability-management tooling in production. - Demonstrated ability in security architecture reviews, threat modeling, vulnerability management, and risk-based prioritisation. - A pragmatic mindset that balances controls with developer velocity and a collaborative style across distributed teams. - Excellent written and spoken English.
Nice to have - Building security automation into CI/CD and Terraform or other infrastructure-as-code workflows. - Securing Kubernetes platforms and containerised workloads. - Detection engineering, cloud-native logging and monitoring, or security operations experience. - Scripting or programming in Python, Go, Kotlin, Java, or a similar language. - Contributing to SOC 2, ISO 27001, or equivalent compliance frameworks. - Supporting customer-facing conversations about cloud, product, or platform security.
Benefits and work setup - Competitive base salary reflecting skills and experience. - Flexible work location with the option to work from home or the office, plus up to 30 days per year of remote work from abroad. - Extra paid time off, medical insurance allowance, and access to mental health support. - Learning and development budget, conferences, courses, and language classes. - Lunch allowance or on-site meals, sports benefit, and internal company events. - Relocation support where applicable, with some benefits varying by location.