Cloud Security Engineer

Werfen S.a.
Barcelona, Spain
9 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Cloud Computing Security Cloud Engineering Cyber Security Continuous Integration DevOps Network Security Cloud Services Zero Trust Network Access Runbook Data Logging Information Technology
+1 more
Vulnerability Analysis

Job description

Job Summary Es esencial asegurarse de que cumple con los requisitos como solicitante para este puesto; por favor, lea atentamente la información a continuación.The Cloud Security Engineer is responsible for designing, implementing, and operating security controls across cloud environments to ensure that applications, data, identities, and infrastructure are protected against modern threats.This role partners closely with Cloud Engineering, Security Operations, Architecture, DevOps, and IT teams to enforce secure-by-default patterns, automate guardrails, and maintain continuous compliance across cloud platforms.Key AccountabilitiesImplement and maintain secure cloud configurations, controls, and guardrails aligned with Zero Trust and best practices.Automate security enforcement using IaC, CI/CD integration, and policy?as?code tools.Manage cloud identity and access security, including least?privilege roles, workload identity, and privileged access.Operate and tune cloud?native threat protection, logging, and monitoring services in partnership with Security Operations.Support incident response with cloud-specific visibility, forensics, and remediation actions.Perform vulnerability scanning, misconfiguration detection, and drive remediation across cloud workloads.Implement secure networking patterns such as private endpoints, WAFs, segmentation, and API protection.Collaborate with DevOps, Cloud Engineering, and Architecture teams to embed security into cloud deployments and projects.Document security patterns, runbooks, and provide guidance to engineering teams.Networking/Key relationships:Governance, Risk and Compliance: Collaborate close with GRC to align controls to risk and compliance requirements.Infrastructure Teams: Collaborate with IT to implement secure and resilient infrastructure on the Cloud.Security Operations: Coordinate with IR/SOC team to enhance detection and response.Minimum Knowledge & Experience for the position:Education: Bachelor’s degree in computer science, cybersecurity, or related field.Experience: 3+ years of hands-on experience in cybersecurity role.Skills & Capabilities:Strategic Thinking: Align operational goals with business risk and security strategy.Technical Depth: Solid understanding of tools, threats, and mitigation techniques.Communication: Clear and effective reporting to technical and executive audiences.Collaboration: Strong cross-functional engagement and influence.Continuous Learning: Commitment to continuous professional development.Travel requirements:Up to 5% of time.Individual Contributor Core Competencies:Managing WorkEffectively managing one’s time and resources to ensure that work is completed efficiently.Emotional Intelligence EssentialsEstablishing and sustaining trusting relationships by accurately perceiving and interpreting own and others’ emotions and behavior; leveraging insights to effectively manage own responses so that one’s behavior matches one’s values and delivers intended results.Building PartnershipsDeveloping and leveraging relationships within and across work groups, including cross-functional groups, to achieve results.Decision MakingIdentifying and understanding problems and opportunities by gathering, analyzing, and interpreting quantitative and qualitative information; choosing the best course of action by establishing clear decision criteria, generating and evaluating alternatives, and making timely decisions; taking action that is consistent with available facts and constraints and optimizes probable consequences.Continuous ImprovementOriginating action to improve existing conditions and processes; identifying improvementopportunities, generating ideas and implementing solutions.xqysrnhContinuous LearningActively identifying new areas for learning; regularly creating and taking advantage of learning opportunities; using newly gained knowledge and skill on the job and learning through their application.

Requirements

This role partners closely with Cloud Engineering, Security Operations, Architecture, DevOps, and IT teams to enforce secure-by-default patterns, automate guardrails, and maintain continuous compliance across cloud platforms.Key AccountabilitiesImplement and maintain secure cloud configurations, controls, and guardrails aligned with Zero Trust and best practices.Automate security enforcement using IaC, CI/CD integration, and policy?as?code tools.Manage cloud identity and access security, including least?privilege roles, workload identity, and privileged access.Operate and tune cloud?native threat protection, logging, and monitoring services in partnership with Security Operations.Support incident response with cloud-specific visibility, forensics, and remediation actions.Perform vulnerability scanning, misconfiguration detection, and drive remediation across cloud workloads.Implement secure networking patterns such as private endpoints, WAFs, segmentation, and API protection.Collaborate with DevOps, Cloud Engineering, and Architecture teams to embed security into cloud deployments and projects.Document security patterns, runbooks, and provide guidance to engineering teams.Networking/Key relationships:Governance, Risk and Compliance: Collaborate close with GRC to align controls to risk and compliance requirements.Infrastructure Teams: Collaborate with IT to implement secure and resilient infrastructure on the Cloud.Security Operations: Coordinate with IR/SOC team to enhance detection and response.Minimum Knowledge & Experience for the position:Education: Bachelor’s degree in computer science, cybersecurity, or related field.Experience: 3+ years of hands-on experience in cybersecurity role.Skills & Capabilities:Strategic Thinking: Align operational goals with business risk and security strategy.Technical Depth: Solid understanding of tools, threats, and mitigation techniques.Communication: Clear and effective reporting to technical and executive audiences.Collaboration: Strong cross-functional engagement and influence.Continuous Learning: Commitment to continuous professional development.Travel requirements:Up to 5% of time.Individual Contributor Core Competencies:Managing WorkEffectively managing one’s time and resources to ensure that work is completed efficiently.Emotional Intelligence EssentialsEstablishing and sustaining trusting relationships by accurately perceiving and interpreting own and others’ emotions and behavior; leveraging insights to effectively manage own responses so that one’s behavior matches one’s values and delivers intended results.Building PartnershipsDeveloping and leveraging relationships within and across work groups, including cross-functional groups, to achieve results.Decision MakingIdentifying and understanding problems and opportunities by gathering, analyzing, and interpreting quantitative and qualitative information; choosing the best course of action by establishing clear decision criteria, generating and evaluating alternatives, and making timely decisions; taking action that is consistent with available facts and constraints and optimizes probable consequences.Continuous ImprovementOriginating action to improve existing conditions and processes; identifying improvementopportunities, generating ideas and implementing solutions. xqysrnhContinuous LearningActively identifying new areas for learning; regularly creating and taking advantage of learning opportunities; using newly gained knowledge and skill on the job and learning through their application.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

Videos

See all

Related articles

See all