> Markdown version of [/jobs/ext/2900640-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/2900640-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** Montash - **Location:** Sevilla, Spain - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Continuous Integration, Python (Programming Language), Security Information and Event Management, Google Cloud, Cloud Platform System, Git Flow, Kubernetes, Terraform, Prisma Cloud Platform, Docker, Microservices - **Published:** September 14, 2026 - **Apply:** https://www.buscojobs.com.es/cloud-security-engineer-en-sevilla-ID-370942146 ## About the Role Solid grasp of how attackers operate in the cloud (credential abuse, lateral movement, exploiting misconfigurations) and how to detect it Time spent with CNAPP/CSPM tooling (Wiz, Prisma Cloud, Lacework, or similar) A track record of owning security incidents start to finish - investigation, containment, and writing it up Comfort building or working within event-driven detection setups and SIEM/SOAR platforms Understanding of microservices and cloud-native architecture, with an eye toward scalability and resilience Real-world experience with Kubernetes, Docker, and the major cloud platforms (AWS, Azure, GCP) Working knowledge of Infrastructure as Code (Terraform, CI/CD, GitOps) and shift-left approaches Some scripting or automation ability (Python or similar) Clear communicator in English, able to translate technical findings for non-security audiences ## Description Location:Madrid or Barcelona (Hybrid, 2-3 days/week in office)Employment type:Full-timeWere looking for a Cloud Security Engineer to join a fast-growing security team working across AWS, Azure, and GCP.Youll help us stay ahead of cloud-native threats, strengthen our security posture, and build the automation that lets us scale securely.What Youll DoReview and triage cloud security alerts across AWS, Azure, and GCP, focusing effort where risk and business impact are highestOwn the fix for cloud security posture gaps - misconfigurations, identity risks, and exposed resourcesInvestigate and respond to live threats, piecing together signals from different data sourcesKeep an eye on SaaS security health, spotting issues like identity drift or risky third-party accessBuild out and refine detection logic in our SIEM, and help grow our SOAR automationPartner with engineering and platform teams to roll out security guardrails and drive adoption of best practicesPush shift-left security forward by embedding it into IaC and CI/CD pipelinesHelp the team keep getting better through automation, solid documentation, and sharing what you learnWhat You BringPractical experience locking down cloud environments (AWS, Azure, and/or GCP)Solid grasp of how attackers operate in the cloud (credential abuse, lateral movement, exploiting misconfigurations) and how to detect itTime spent with CNAPP/CSPM tooling (Wiz, Prisma Cloud, Lacework, or similar)A track record of owning security incidents start to finish - investigation, containment, and writing it upComfort building or working within event-driven detection setups and SIEM/SOAR platformsUnderstanding of microservices and cloud-native architecture, with an eye toward scalability and resilienceReal-world experience with Kubernetes, Docker, and the major cloud platforms (AWS, Azure, GCP)Working knowledge of Infrastructure as Code (Terraform, CI/CD, GitOps) and shift-left approachesSome scripting or automation ability (Python or similar)Clear communicator in English, able to translate technical findings for non-security audiencesWhy This RoleA team thats going places- continuously growing, working with the latest technologies including AI, and genuinely pushing the boundaries of what a modern team looks likeInvest in yourself- the company invests heavily in learning & development?Great offices, real flexibility- hybrid working (2-3 days in office) from Barcelona or Madrid, with a terrace and stunning viewsBuild your own path- take ownership, show what youve got, and grow within the team and the company on your own terms??People come first-flexible working, healthcare, parental leave, and genuine wellbeing supportCompetitive package+ €2k annual compensation + health insurance, a dedicated learning budget, and more perks on top ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)