> Markdown version of [/jobs/ext/2906811-security-cloud-engineer](https://www.wearedevelopers.com/jobs/ext/2906811-security-cloud-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Cloud Engineer - **Company:** Montash - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Continuous Integration, Python (Programming Language), Google Cloud, Cloud Platform System, Kubernetes, Terraform, Prisma Cloud Platform, Docker, Microservices - **Published:** September 14, 2026 - **Apply:** https://www.buscojobs.com.es/security-cloud-engineer-en-barcelona-ID-371280290 ## About the Role Solid grasp of how attackers operate in the cloud (credential abuse, lateral movement, exploiting misconfigurations) and how to detect it Time spent with CNAPP/CSPM tooling (Wiz, Prisma Cloud, Lacework, or similar) A track record of owning security incidents start to finish - investigation, containment, and writing it up Understanding of microservices and cloud-native architecture, with an eye toward scalability and resilience Real-world experience with Kubernetes, Docker, and the major cloud platforms (AWS, Azure, GCP) Working knowledge of Infrastructure as Code (Terraform, xqziphu CI/CD, GitOps) and shift-left approaches Some scripting or automation ability (Python or similar) Clear communicator in English, able to translate technical findings for non-security audiences Great offices, real flexibility - hybrid working (2-3 days in office) from Barcelona or Madrid, with a terrace and stunning views ## Description Location: Madrid or Barcelona (Hybrid, 2-3 days/week in office) Employment type: Full-timeWe're looking for a Cloud Security Engineer to join a fast-growing security team working across AWS, Azure, and GCP.You'll help us stay ahead of cloud-native threats, strengthen our security posture, and build the automation that lets us scale securely.Review and triage cloud security alerts across AWS, Azure, and GCP, focusing effort where risk and business impact are highestInscríbase ahora, lea los detalles del trabajo desplazándose hacia abajo.Verifique que posee las habilidades necesarias antes de enviar una solicitud.Own the fix for cloud security posture gaps - misconfigurations, identity risks, and exposed resourcesInvestigate and respond to live threats, piecing together signals from different data sourcesKeep an eye on SaaS security health, spotting issues like identity drift or risky third-party accessPartner with engineering and platform teams to roll out security guardrails and drive adoption of best practicesPush shift-left security forward by embedding it into IaC and CI/CD pipelinesPractical experience locking down cloud environments (AWS, Azure, and/or GCP)Solid grasp of how attackers operate in the cloud (credential abuse, lateral movement, exploiting misconfigurations) and how to detect itTime spent with CNAPP/CSPM tooling (Wiz, Prisma Cloud, Lacework, or similar)A track record of owning security incidents start to finish - investigation, containment, and writing it upUnderstanding of microservices and cloud-native architecture, with an eye toward scalability and resilienceReal-world experience with Kubernetes, Docker, and the major cloud platforms (AWS, Azure, GCP)Working knowledge of Infrastructure as Code (Terraform, xqziphu CI/CD, GitOps) and shift-left approachesSome scripting or automation ability (Python or similar)Clear communicator in English, able to translate technical findings for non-security audiencesGreat offices, real flexibility - hybrid working (2-3 days in office) from Barcelona or Madrid, with a terrace and stunning viewsPeople come first -flexible working, healthcare, parental leave, and genuine wellbeing support Competitive package + €2k annual compensation + health insurance, a dedicated learning budget, and more perks on top ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) - [We adopted DevOps and are Cloud-native, Now What?](https://www.wearedevelopers.com/videos/485-we-adopted-devops-and-are-cloud-native-now-what) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Most Popular Web Developer Jobs in Europe](https://www.wearedevelopers.com/magazine/163-7-most-popular-web-developer-jobs-in-europe) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)