> Markdown version of [/jobs/ext/2724209-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/2724209-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** Happyrobot Inc. - **Location:** Spain - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Continuous Integration, Identity and Access Management, Python (Programming Language), Role-Based Access Control, Security Information and Event Management, TypeScript, Policy as Code, Data Logging, Scripting, Google Cloud, Multi-Cloud, Kubernetes, Terraform - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/cloud-security-engineer-happyrobot-inc-8954299 ## About the Role * 4-6 years in cloud security or platform/infrastructure security. * Expert depth in at least one major cloud provider (AWS, Azure, or GCP): IAM, networking, KMS/encryption, and logging. * Hands-on experience with a CNAPP/CSPM - Wiz strongly preferred - including triage, prioritization, and driving remediation with engineering teams. * Terraform in production plus policy-as-code experience (OPA/Rego, Checkov, tfsec, or similar) integrated in CI/CD. * Kubernetes security fundamentals: RBAC, admission control, and image scanning. * Scripting proficiency in Python or Go. * English B2+ (professional working proficiency). Nice to Have * Working experience across 2+ cloud providers - we deploy on AWS, Azure, and GCP. * Cross-cloud and Kubernetes certifications: CCSK, CKA, CKS, AWS Security Specialty, or equivalent. * EKS/AKS/GKE hardening and container runtime security experience. * TypeScript or Go beyond scripting. * SIEM/detection exposure - we run RunReveal. * SOC 2 / ISO 27001 cloud control evidence experience. ## Description We are looking for a Cloud Security Engineer to join our team. You will be the single accountable owner for cloud security posture across AWS, Azure, and GCP - bringing the technical depth and operational discipline to keep our infrastructure hardened, our findings remediated on SLA, and our security baseline consistent across every environment we run. This is not a governance or advisory role. Your deepest strength is the ability to own outcomes end-to-end: triaging Wiz findings by real-world exploitability, shipping policy-as-code gates that catch misconfigurations before they hit production, and getting remediation done by engineering teams you don't manage. That said, you operate with a platform mindset - building guardrails that scale rather than manually reviewing every change. What You'll Do * Cloud Posture Management Own the CNAPP end-to-end. Triage Wiz findings by exploitability and business impact, drive remediation across engineering teams to SLA and keep the backlog from accumulating. Be the person who actually gets findings closed, not just reported. * IaC Security Design and ship policy-as-code gates in the Terraform pipeline that block misconfigurations at PR and plan time, before they reach production. Use OPA/Rego, Checkov, tfsec, or equivalent - and calibrate gates to stop bad patterns without creating friction that causes teams to route around them. * Multi-Cloud Baseline Define, document, and enforce a consistent security baseline across AWS, Azure, and GCP - covering IAM, networking, KMS/encryption, and logging. Own the documentation that supports enterprise customer security reviews and audit evidence requests. * Kubernetes & Container Security Harden clusters, images, and admission paths across EKS, AKS, and GKE. Set and enforce RBAC policies, admission controls, and image scanning standards. * Remediation Leadership Drive fixes through engineering teams you don't have direct authority over. Track SLAs, communicate risk clearly to technical and non-technical stakeholders, and escalate when needed - without creating noise. * Shift-Left Guardrails Grow the share of cloud infrastructure managed via Terraform with active security checks, quarter over quarter. Trend new critical misconfigurations reaching production to zero., We take full responsibility for our work and outcomes. No excuses, no blame-shifting. If something needs fixing, we own it. Craftsmanship We sweat the details because details compound. We never settle for "just fine" - whether it's a scoping document, a prototype demo, or a customer conversation. We are "Majos" Be a good human. Friendly, genuine, kind. We're building something ambitious and it's better when we enjoy it together. Urgency with Focus Move fast, but in the right direction. Prioritize ruthlessly. Act decisively. Aim for the highest leverage action. Talent Density and Meritocracy Every hire raises the bar. Ability over seniority. Ownership goes to those who earn it. First-Principles Thinking Strip problems to their fundamentals, ignore industry dogma, and rebuild from scratch when needed. It's how we build what others think is impossible. ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Building a Cloud Platform Where Everything is Just Another Kubernetes Resource](https://www.wearedevelopers.com/videos/100137-building-a-cloud-platform-where-everything-is-just-another-kubernetes-resource) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)