Cloud Infrastructure Security Engineer

ProntoPro
Barcelona, Spain
14 days ago
Apply on es.trabajo.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Shift work
Job source

Tech stack

Java (Programming Language) .NET Framework Application Programming Interfaces (APIs) Amazon Web Services Amazon Cloudfront Amazon Elastic Compute Cloud Amazon S3 Software System Penetration Testing Bash Shell BigQuery Business Software Cloud Computing
+40 more
Cloud Computing Security Cloud Storage Protocol Stack Continuous Delivery Data Security Linux Domain Name System (DNS) Multi-Factor Authentication Elasticsearch Identity and Access Management Virtual Private Networks (VPN) Python (Programming Language) Network Security Node.Js OAuth Program Analysis Ansible Prometheus Ruby Security Assertion Markup Language (SAML) Scala (Programming Language) Systems Integration Scripting Cloud Platform System Okta Statsd Amazon ElastiCache Grafana Software Security Electronic Medical Records Amazon Virtual Private Cloud (VPC) Amazon Relational Database Service Kubernetes Graphite Terraform Devsecops Docker Jenkins Golang Programming Languages

Requirements

You’ll be working with a team of other engineers to build out and secure our expanding cloud infrastructure in AWS - While this is a hands-on engineering position (not a CISO or a consulting role), you will need the confidence and gravitas to heavily influence engineers and managers across a wide technical function - The team holds itself accountable to a high standard of build quality - We have recently completed the first major phase of a completely green-field infrastructure and platform rebuild that is designed to underpin Cint’s business applications for the next decade, while scaling to support a 10-fold growth in revenue - We are compulsive about infrastructure as code (nothing in our platform is created or deployed unless via a code change) and driven to achieve a full end to end continuous deployment pipeline - Major elements of our platform include AWS (we make significant use of S3, RDS, Kinesis, EC2, EMR, ElastiCache, ElasticSearch and EKS). Elements of the platform will start to expand into GCP (Compute Engine, Cloud Storage, Google Kubernetes Engine and BigQuery). Other significant tools of the platform include Linux, Terraform, Kubernetes, Docker, Packer, Ansible and Jenkins - We support applications and services written in Golang, Python, Java, Scala and .Net - We monitor and alert on everything we deploy via Grafana, Prometheus, Graphite and ELK stacks - Work as part of the Infrastructure team defining and improving our general security posture across legacy and green field resources including data, applications and networks - Provide point of expertise on application, data and network security to our wider engineering teams - engaging with them in order to ensure consistent adoption of security policies and best practice - Participate in the automation of software to our cloud platform and embed security into our methodology, embracing DevSecOps - Improve our monitoring and alerting systems to enhance them with specific and relevant security data points - Participate in an on-call rotation and assist with troubleshooting issues that arise - Defining and implementing a Security Incident Response process/policy with regular evolvement, testing and adherence- We are searching for an experienced Senior Cloud Infrastructure Security Engineer with an unquenchable thirst for automation and a passion for DevSecOps methodology - Good knowledge of some IdP (Okta, OneLogin, Auth0) frameworks and integrations - Plays well with others - we build and ship as a team - Ability to interact comfortably with AWS via CLI and/or API - Experience of code security audit, static and dynamic analysis, defensive programming techniques and visualisation and measurement of security KPIs - Three years or more experience in Cloud Infrastructure roles (predominantly AWS) working within teams that practice DevSecOps - Expertise in at least one scripting or programming language (Python, Bash, Ruby, Node, Golang, Java) - Specific expertise in threat assessment, attack surface management, data security, the network stack at L4 and L7, DNS, VPC security, IGW, WAF and CloudFront - Experience designing and managing IAM policies, roles and trust policies - Good knowledge of most of VPN, MFA, SAML, OAuth2, KMS and TLS - Proficient in managing Infrastructure exclusively with Terraform - Experience building and running Docker images/containers securely, including container orchestration security - You will be someone that shares our values and ambitions and can bring security best practices and specific cloud security expertise to the party - You will additionally be the kind of person that is energised by complex challenges, teamwork and problem solving. In return, we can offer a great tech culture, highly competitive compensation packages and employment benefits - Hands on experience designing and implementing security controls within GCP - AWS Certified Security Specialist - Good knowledge of monitoring and alerting using one or more of: Graphite, Statsd, Prometheus, Grafana, OpenSearch - Experience defining and operating a Security Incident Response process - Any experience of ISO27001 certification processes - Understanding of “cloud native” and 12-Factor applications - Offensive or defensive penetration testing experience

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on es.trabajo.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:30 min

Falling in love with Ruby and creating Basecamp

David Heinemeier Hansson David Heinemeier Hansson +1 · Coffee With Developers

Videos

See all

Related articles

See all