As a Security Engineer, you will work closely with our client's agile development teams to ensure they deliver the most secure Point of Sale and Unified Commerce Platform in the world. You will play a key role in designing cloud architectures and environments that are secure by default. By pairing hands-on implementation with practical security leadership, you will build automated guardrails into our SDLC, secure their containers and infrastructure, and empower product teams to ship safely and independently.
What you will do:
- Architect, build, and evolve secure cloud environments, infrastructure, and backend services.
- Drive vulnerability remediation across AWS Security Hub, Inspector, GuardDuty, and Vanta to eliminate overdue findings and hit strict SLA targets.
- Integrate and automate security guardrails seamlessly into our Software Development Life Cycle (SDLC) and CI/CD pipelines to ensure safe deployments without sacrificing developer velocity.
- Own base OS image hardening, ECR container vulnerability scanning, and lifecycle management to prevent recurring container risks.
- Audit, clean up, and decommission unmaintained AWS accounts, orphaned test stacks, and legacy cloud resources.
- Design resilient AWS architectures and own our multi-account setup via Infrastructure as Code (IaC).
- Lead on authentication and authorization patterns and guide teams on secure access.
- Partner with the CISO to automate continuous security evidence collection for SOC 2 and ISO 27001 compliance.
- Champion shared security responsibility through "secure by default" principles, clear guidelines, examples, and mentoring.
You will work closely with the CISO and be part of a small, two-person team.
- A background in software engineering, backend development, or building scalable cloud services.
- Strong hands-on experience with security implementations in modern cloud environments, including securing infrastructure and containers (e.g., Docker, AWS Lambda, AWS ECS).
- Demonstrated experience with Cloud Security Posture Management (CSPM) tools and driving vulnerability remediation across cloud infrastructure.
- Hands-on experience with AWS, Infrastructure as Code (IaC), and least-privilege identity access management (IAM/OIDC).
- Proven ability to build and embed automated security guardrails directly into the SDLC and CI/CD pipelines.
- Proven experience with cloud providers (AWS preferred), Infrastructure as Code (IaC), and least-privilege design.
- You confidently interact with individuals, teams, and organizations to make sure they are informed and empowered, fostering a culture of accountability.
- Professional English, both verbal and written.