Product/Cloud Security Engineer

JetBrains GmbH
München, Germany
7 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Java (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Software as a Service Cloud Computing Security Cloud Engineering Cyber Security Computer Programming Continuous Integration Identity and Access Management Intrusion Detection and Prevention Python (Programming Language)
+20 more
Reliability Engineering Cloud Services Software Engineering Systems Integration Software Vulnerability Management JetBrains Data Logging Scripting Google Cloud Cloud Platform System Delivery Pipeline Kotlin Containerization Kubernetes Infrastructure Automation Frameworks CIS Benchmarks Terraform Serverless Computing Golang Microservices

Job description

As our cloud footprint grows, we are investing heavily in the security of the platforms and products that support them. We are looking for a Senior Product/Cloud Security Engineer to help us strengthen the security of the JetBrains Air platform and the services built on top of it.

In this role, you’ll take ownership of cloud and product security across our AWS and GCP environments. You’ll work directly on design choices, architecture reviews, and automation that reduce risk across the entire software development lifecycle. You’ll partner closely with platform engineering, SRE, and product teams to make secure choices the easiest path for developers.

You will have substantial ownership and influence across teams while staying close to technical details.

Day to day, you will:

  • Lead and continuously improve cloud security across JetBrains Air, including security posture, preventive controls, detection, and remediation.
  • Define, maintain, and measure security baselines for AWS and GCP environments, covering IAM, networking, data protection, and workload configuration.
  • Operate and evolve cloud security platforms and vulnerability-management solutions (e.g. Wiz, Orca Security, Upwind, Tenable, etc.).
  • Establish effective processes for triaging, prioritizing, assigning, and remediating cloud security findings and vulnerabilities.
  • Partner with platform engineering, SRE, and product engineering teams to design and implement practical security controls that fit naturally into developer workflows.
  • Perform security design and architecture reviews for cloud services, APIs, and integrations. Conduct threat modeling and risk assessments to provide clear, actionable recommendations.
  • Review product and platform changes for security implications throughout the entire software development lifecycle, from early design to production.
  • Help improve security automation by integrating security checks, guardrails, and evidence into engineering and delivery pipelines.
  • Support incident response, root-cause analysis, and drive systemic improvements that reduce recurrence.
  • Develop meaningful metrics for cloud and product security, communicate trends and risks, and help prioritize security investments.
  • Contribute to security standards, guidance, runbooks, and patterns that make secure engineering easier across JetBrains.

Requirements

  • A pragmatic engineering mindset that balances security controls with developer velocity.
  • A strong sense of ownership and the initiative to spot complex risks and address them early.
  • Excellent communication skills, with the ability to explain technical trade-offs clearly to both engineers and stakeholders.
  • A collaborative mentality when working across distributed teams and engineering disciplines.
  • A high bar for quality and a commitment to building sustainable, long-term security baselines.
  • A curious and analytical approach to threat modeling and architectural risk., * Established professional experience in security engineering or a closely related technical security domain, securing SaaS products or cloud-native services.
  • Strong experience with AWS and/or GCP security - specifically the ability to assess architecture and configurations directly, rather than relying solely on tool outputs.
  • Practical experience deploying, operating, or integrating cloud security and vulnerability-management platforms (e.g., Wiz, Orca Security, Upwind, Tenable).
  • Hands-on experience with security architecture reviews, threat modeling, vulnerability management, and risk-based prioritization.
  • Solid understanding of modern SaaS architectures (APIs, microservices, containers, Kubernetes, identity providers, networking, and managed cloud services).
  • Experience working closely with engineering, SRE, and product teams to translate security requirements into practical engineering solutions.
  • Excellent written and spoken English., * Experience building security automation or integrating security controls into CI/CD and infrastructure-as-code (IaC) workflows.
  • Hands-on experience with Terraform or other IaC tools.
  • Experience securing Kubernetes-based platforms and containerized workloads.
  • Familiarity with detection engineering, cloud-native logging and monitoring, or security operations workflows.
  • Scripting or programming experience in Python, Go, Kotlin, Java, or a similar language.
  • Experience contributing to SOC 2, ISO 27001, or other security and compliance frameworks for SaaS products.
  • Experience supporting customer-facing conversations about cloud, product, or platform security.

Benefits & conditions

  • Strong base salary. We offer competitive pay that reflects your skills and experience.
  • Flexible work location. Enjoy the freedom to work from home or from the office.
  • Remote work. Spend up to 30 days per year working remotely from abroad.
  • Extra time off. More days to relax, recharge, and do the things you love.
  • Medical insurance allowance. Enjoy peace of mind for you and your family
  • Learning and development opportunities. Access to conferences, courses, and language classes.
  • Relocation support. We help make your move as smooth and stress-free as possible.
  • Language classes. Pick up the local language or sharpen your English skills.
  • Fuel your day. Enjoy a hot meal or receive a lunch allowance on workdays.
  • Mental health support. To help you feel your best, we provide easy access to professional mental health services.
  • Sports benefit. Enjoy an on-site gym or sports club stipend.
  • Internal events. Join company-wide celebrations and team gatherings.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Loading talks and stories from around this role…