> Markdown version of [/jobs/ext/3072454-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/3072454-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** Stratesys - **Location:** Ávila, Spain - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Computer Networks, Identity and Access Management, Performance Tuning, Software Engineering, Multi-Cloud, Infrastructure as Code (IaC), Kubernetes, Information Technology, Devsecops, Serverless Computing, Docker, Vulnerability Analysis - **Published:** September 25, 2026 - **Apply:** https://www.buscojobs.com.es/cloud-security-engineer-en-avila-ID-373616287 ## About the Role Qualifications Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or equivalent practical experience. 3+ years of dedicated experience securing public cloud workloads, with a strong understanding of the shared responsibility model. Deep technical knowledge of Docker, Kubernetes, and container orchestration; ability to secure a pod, restrict container privileges, and manage network policies. Proven, hands-on experience deploying and tuning cloud security platforms (CWPP / CNAPP). Strong grasp of cloud-native networking (VPCs, Security Groups) and Identity and Access Management (least-privilege roles, service accounts). Proficiency in written and spoken English (C1 or above). #J-*****-Ljbffr ## Description Roche - Cloud Security Engineer specializing in Cloud Workload Protection Job Responsibilities Cloud Workload Protection (CWPP): Architect, deploy, and manage Cloud Workload Protection Platforms across multi-cloud environments (AWS, Azure, and/or GCP).Container & Kubernetes Security: Implement runtime defense, vulnerability scanning, and configuration hardening for containerized applications and orchestration platforms (EKS, AKS, GKE).Extending Core Services to the Cloud: Adapt our existing strategies for EDR and Application Control to function effectively in ephemeral, cloud-native workloads without degrading performance.DevSecOps Integration: Embed security controls directly into CI/CD pipelines (Shift-Left), ensuring images, registries, and Infrastructure as Code (IaC) templates are scanned and secured before deployment.Automated Remediation: Develop automated response playbooks for cloud misconfigurations and workload alerts using serverless functions and native cloud APIs.Qualifications Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or equivalent practical experience.3+ years of dedicated experience securing public cloud workloads, with a strong understanding of the shared responsibility model.Deep technical knowledge of Docker, Kubernetes, and container orchestration; ability to secure a pod, restrict container privileges, and manage network policies.Proven, hands-on experience deploying and tuning cloud security platforms (CWPP / CNAPP).Strong grasp of cloud-native networking (VPCs, Security Groups) and Identity and Access Management (least-privilege roles, service accounts).Proficiency in written and spoken English (C1 or above).#J-*****-Ljbffr ## Related Videos - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)