> Markdown version of [/jobs/ext/1997709-senior-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/1997709-senior-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cloud Security Engineer - **Company:** Cint - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Amazon Cloudfront, Amazon Elastic Compute Cloud, Amazon S3, Software System Penetration Testing, Bash Shell, BigQuery, Business Software, Cloud Computing, Cloud Computing Security, Cloud Storage, Protocol Stack, Continuous Delivery, Data Security, Linux, Domain Name System (DNS), Multi-Factor Authentication, Elasticsearch, Identity and Access Management, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Node.Js, OAuth, Program Analysis, Ansible, Prometheus, Ruby, Security Assertion Markup Language (SAML), Scala (Programming Language), Systems Integration, Scripting, Cloud Platform System, Okta, Statsd, Amazon ElastiCache, Grafana, Software Security, Electronic Medical Records, Amazon Virtual Private Cloud (VPC), Amazon Relational Database Service, Kubernetes, Graphite, Terraform, Devsecops, Docker, Jenkins, Golang, Programming Languages - **Published:** August 9, 2026 - **Apply:** https://www.buscojobs.com.es/senior-cloud-security-engineer-en-barcelona-ID-366737737 ## About the Role Three years or more experience in Cloud Infrastructure roles (predominantly AWS) working within teams that practice DevSecOps Ability to interact comfortably with AWS via CLI and/or API Proficient in managing Infrastructure exclusively with Terraform Specific expertise in threat assessment, attack surface management, data security, the network stack at L4 and L7, DNS, VPC security, IGW, WAF and CloudFront Experience designing and managing IAM policies, roles and trust policies Good knowledge of most of VPN, MFA, SAML, OAuth2, KMS and TLS Good knowledge of some IdP (Okta, OneLogin, Auth0) frameworks and integrations Experience building and running Docker images/containers securely, including container orchestration security Experience of code security audit, static and dynamic analysis, defensive programming techniques and visualisation and measurement of security KPIs Expertise in at least one scripting or programming language (Python, Bash, Ruby, Node, Golang, Java) Plays well with others - we build and ship as a team Advantageous Qualifications AWS Certified Security Specialist Hands on experience designing and implementing security controls within GCP Experience defining and operating a Security Incident Response process Good knowledge of monitoring and alerting using one or more of: Graphite, Statsd, Prometheus, Grafana, OpenSearch Any experience of ISO***** certification processes Understanding of "cloud native" and 12-Factor applications Offensive or defensive penetration testing experience ## Description Cint is a pioneer in research technology (ResTech). Our customers use the Cint platform to post questions and get answers from real people to build business strategies, confidently publish research, accurately measure the impact of digital advertising, and more. The Cint platform is built on a programmatic marketplace, which is the world's largest, with nearly 300 million respondents in over 150 countries who consent to sharing their opinions, motivations, and behaviours.We are searching for an experienced Senior Cloud Infrastructure Security Engineer with an unquenchable thirst for automation and a passion for DevSecOps methodology. You'll be working with a team of other engineers to build out and secure our expanding cloud infrastructure in AWS. While this is a hands?on engineering position (not a CISO or a consulting role), you will need the confidence and gravitas to heavily influence engineers and managers across a wide technical function.The team holds itself accountable to a high standard of build quality. We have recently completed the first major phase of a completely green-field infrastructure and platform rebuild that is designed to underpin Cint's business applications for the next decade, while scaling to support a 10?fold growth in revenue. We are compulsive about infrastructure as code (nothing in our platform is created or deployed unless via a code change) and driven to achieve a full end to end continuous deployment pipeline.Major elements of our platform include AWS (we make significant use of S3, RDS, Kinesis, EC2, EMR, ElastiCache, ElasticSearch and EKS). Elements of the platform will start to expand into GCP (Compute Engine, Cloud Storage, Google Kubernetes Engine and BigQuery). Other significant tools of the platform include Linux, Terraform, Kubernetes, Docker, Packer, Ansible and Jenkins. We support applications and services written in Golang, Python, Java, Scala and .Net. We monitor and alert on everything we deploy via Grafana, Prometheus, Graphite and ELK stacks.You will be someone that shares our values and ambitions and can bring security best practices and specific cloud security expertise to the party. You will additionally be the kind of person that is energised by complex challenges, teamwork and problem solving. In return, we can offer a great tech culture, highly competitive compensation packages and employment benefits.ResponsibilitiesWork as part of the Infrastructure team defining and improving our general security posture across legacy and green field resources including data, applications and networksProvide point of expertise on application, data and network security to our wider engineering teams - engaging with them in order to ensure consistent adoption of security policies and best practiceParticipate in the automation of software to our cloud platform and embed security into our methodology, embracing DevSecOpsImprove our monitoring and alerting systems to enhance them with specific and relevant security data pointsParticipate in an on-call rotation and assist with troubleshooting issues that ariseDefining and implementing a Security Incident Response process/policy with regular evolvement, testing and adherenceRequired QualificationsThree years or more experience in Cloud Infrastructure roles (predominantly AWS) working within teams that practice DevSecOpsAbility to interact comfortably with AWS via CLI and/or APIProficient in managing Infrastructure exclusively with TerraformSpecific expertise in threat assessment, attack surface management, data security, the network stack at L4 and L7, DNS, VPC security, IGW, WAF and CloudFrontExperience designing and managing IAM policies, roles and trust policiesGood knowledge of most of VPN, MFA, SAML, OAuth2, KMS and TLSGood knowledge of some IdP (Okta, OneLogin, Auth0) frameworks and integrationsExperience building and running Docker images/containers securely, including container orchestration securityExperience of code security audit, static and dynamic analysis, defensive programming techniques and visualisation and measurement of security KPIsExpertise in at least one scripting or programming language (Python, Bash, Ruby, Node, Golang, Java)Plays well with others - we build and ship as a teamAdvantageous QualificationsAWS Certified Security SpecialistHands on experience designing and implementing security controls within GCPExperience defining and operating a Security Incident Response processGood knowledge of monitoring and alerting using one or more of: Graphite, Statsd, Prometheus, Grafana, OpenSearchAny experience of ISO***** certification processesUnderstanding of "cloud native" and 12-Factor applicationsOffensive or defensive penetration testing experienceOur ValuesCollaboration is our superpowerWe uncover rich perspectives across the worldSuccess happens togetherWe deliver across borders.Innovation is in our bloodWe're pioneers in our industryOur curiosity is insatiableWe bring the best ideas to life.We do what we sayWe're accountable for our work and actionsExcellence comes as standardWe're open, honest and kind, always.We are caringWe learn from each other's experiencesStop and listen; every opinion mattersWe embrace diversity, equity and inclusion.More About CintWe're proud to be recognised in Newsweek's **** Global Top 100 Most Loved Workplaces, reflecting our commitment to a culture of trust, respect, and employee growth.In June ****, Cint acquired Berlin?based GapFish - the world's largest ISO certified online panel community in the DACH region - and in January ****, completed the acquisition of US?based Lucid - a programmatic research technology platform that provides access to first?party survey data in over 110 countries.Cint Group AB (publ), listed on Nasdaq Stockholm, this growth has made Cint a strong global platform with teams across its many global offices, including Stockholm, London, New York, New Orleans, Singapore, Tokyo and Sydney. (Additionally, in a world of AI, we want our candidates to understand our approach to the use of AI during the interview and hiring process, so we'd appreciate you reading our AI usage guide.#J-*****-Ljbffr ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Fireside Chat with Werner Vogels, VP & CTO, Amazon.com & Daniel Gebler, CTO at Picnic](https://www.wearedevelopers.com/videos/1405-fireside-chat-with-werner-vogels-vp-cto-amazon-com-daniel-gebler-cto-at-picnic) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [7 Most Popular Web Developer Jobs in Europe](https://www.wearedevelopers.com/magazine/163-7-most-popular-web-developer-jobs-in-europe)