Principal Security Engineer (Remote from Switzerland)
Role details
Job location
Tech stack
Job description
- Implement and maintain security controls across multi-cloud environments (AWS, Azure, GCP, AliCloud) and on-premises infrastructure.
- Own and execute IAM strategy, designing secure, scalable identity and access models for cloud and enterprise systems.
- Design and operate key management and custody security controls, including HSMs, secrets management, and secure key handling.
- Harden CI/CD pipelines, securing software delivery processes and embedding security into cloud provisioning and system configuration.
- Configure and manage corporate security tooling, including endpoint protection, MDM/Jamf, DLP, and identity management systems.
- Respond to security incidents by triaging, investigating, containing, and remediating threats efficiently.
- Conduct security assessments for infrastructure and applications, identifying vulnerabilities and implementing mitigations.
- Automate security operations, including detection, alerting, and response, to enhance operational efficiency.
Requirements
Requirements:8+ years of hands-on experience in security engineering or security operations.Strong expertise and well-defined philosophy on IAM design and implementation across cloud environments.In-depth knowledge of cloud security controls, especially AWS and Azure.Experience securing CI/CD platforms, with GitLab preferred.Familiarity with corporate IT security tooling such as Jamf, endpoint protection, DLP, and SSO/IdP.Comfortable in Linux environments and proficient in scripting (Python, Bash, or similar).Experience with infrastructure-as-code tools (Terraform, Pulumi, etc.) is a plus.Exposure to financial services, crypto, or regulated environments is advantageous but not required.Demonstrated practical skills and hands-on experience prioritized over certifications.Benefits:Direct ownership of security implementation with measurable impact.Work in a small, technical team with high visibility of your contributions., Exposure to low-latency trading infrastructure and digital asset