Remote job
Head of Infrastructure & Cloud Security
Job details
About this role
Role overview The role leads infrastructure and cloud security across cloud, network, identity, endpoint, and data domains in a hybrid environment. The position reports to the CISO, manages a team of security engineers, and enforces a cloud-first security posture while balancing delivery velocity for platform and SRE partners.
Responsibilities - Shape and run the infrastructure and cloud security roadmap, including the guardrails that govern low- and medium-risk platform exceptions. - Hire, lead, and develop security engineers and team leads, building long-term technical depth and on-call discipline. - Own CSPM, CNAPP, CWPP, WAF, DNS security, and infrastructure-as-code scanning across cloud accounts. - Partner with Platform and SRE teams on cloud IAM, security groups, and identity guardrails that don't block delivery. - Strengthen endpoint protection across managed devices, including hardening, telemetry, and health reporting. - Run data security and cryptography controls: KMS, secrets management, PKI, and certificate lifecycle. - Track, analyze, and report enterprise security metrics to leadership.
Requirements - Demonstrated track record leading security engineers and managing technical teams. - Hands-on background in cybersecurity engineering, not only oversight. - Strong experience securing on-premises infrastructure in enterprise settings. - Working knowledge of at least one major cloud provider. - Proficiency with cloud and network security tooling such as CSPM/CNAPP/CWPP, WAF, DNS security, and IaC scanning. - Familiarity with EDR/XDR, MDM, cloud IAM, security-group guardrails, KMS, secrets management, PKI, and certificate management. - Ability to enforce controls without slowing Platform, SRE, or DevOps teams.
Nice to have - Background building or maturing an infrastructure or cloud security function from an early stage. - Experience in fintech, brokerage, trading platforms, payments, or other regulated environments. - Familiarity with Kubernetes and container security in cloud-native architectures. - Exposure to SOC 2, ISO 27001, or DORA compliance frameworks. - Working knowledge of tools such as Wiz, Panorama, Elastic Defender, Entra, or CyberArk.
Benefits and work setup - Remote-friendly opportunity. - 15 paid vacation days and 10 paid sick days per year, plus public holidays. - Medical budget, professional education budget, language learning budget, and a wellness budget for gym membership or sport-related expenses.