JobMatch
← Back to jobs

Cloud Security Engineer - Hybrid - Lisbon - Mid/Senior

La Fosse

RemoteLisbon, PortugalEUR 50k–75kseniorFull-time
Posted
today
Source
LinkedIn (remote, Europe)
Field
Engineering, Security

Skills

Penetration TestingCommunicationKubernetesSecurityPythonCI/CDAWSGCPGo

Description

Location: Lisbon, Portugal Working pattern: 4 days per week onsite Salary: Mid level €50,000 - €75,000 Salary: Senior €75,000 - €95,000 We are looking for a Senior Cloud Security Engineer to join a highly technical security engineering team building and securing cloud-native financial technology at scale. This is an engineering-led security environment where the team works closely with developers, cloud engineers and infrastructure teams to design, build and operate security solutions. The focus is not simply on selecting or configuring security products - the team has a strong preference for building automation, controls and tooling themselves. You will have the opportunity to work across cloud security, infrastructure security, threat modelling, security architecture and security automation, with significant autonomy over how complex security problems are approached. The role You will: - Lead the design and implementation of cloud-native preventative and detective security controls. - Work closely with engineering teams throughout planning, architecture, development and testing. - Design and review secure cloud and distributed-system architectures. - Perform threat modelling, security reviews and technical risk assessments. - Build automation to assess infrastructure, infrastructure-as-code and cloud environments. - Develop security tooling and integrations using code. - Work with cloud and platform engineering teams to maintain a secure production environment. - Review security controls across containerised and Kubernetes environments. - Conduct security testing and vulnerability assessments. - Lead complex security engineering projects from design through to delivery. - Contribute to security architecture, strategy and tooling decisions. - Mentor engineers and influence security decisions across the wider engineering organisation. What we're looking for Essential: - Strong experience in cloud security engineering. - Hands-on experience with AWS and/or GCP. - Experience securing containerised environments and Kubernetes. - Strong understanding of cloud networking, infrastructure and distributed systems. - Experience with infrastructure-as-code and CI/CD. - Strong programming or scripting capability, ideally Python, Go or a similar language. - Experience building security automation or security tooling. - Experience with security architecture, threat modelling and technical design reviews. - Strong understanding of security controls and how they are implemented technically. - Experience working closely with software, platform or infrastructure engineers. - Excellent communication skills and the ability to influence technical decisions. Desirable: - Experience operating distributed systems at scale. - Experience with cloud provider APIs. - Penetration testing or security testing experience. - Knowledge of cloud security frameworks such as Well-Architected or CSA-CCM. - Contributions to the security community through research, blogging, presentations or open-source work. The environment This is a particularly good opportunity for someone who wants to be a security engineer rather than a security tool administrator. You will work alongside experienced AppSec and CloudSec engineers and highly capable developers who already understand the importance of security. Discussions can therefore get into the technical detail of how a control should actually be engineered, rather than spending time convincing engineering teams that security matters. The team is collaborative and risk-led. Security decisions are made through evidence, technical judgement and discussion, with an emphasis on delivering the greatest security benefit for the engineering effort invested.

JobMatch aggregates public listings. Always apply through the original posting.