Senior Cloud Security Engineer
Job description
About the role
Become a key player in a rapidly growing fintech company that operates in 29 countries and safeguards payment systems for over a billion users. As a Senior Cloud Security Engineer, you will be an integral part of the IT Operations team, focusing on maintaining secure and efficient systems while spearheading security initiatives across our expansive global platform.
Key facts
What you'll do
- Design, implement, and continuously enhance security measures within AWS and GCP infrastructures to ensure robust protection against threats.
- Take the lead on security investigations, working collaboratively with various departments to identify vulnerabilities and implement corrective actions to avert future incidents.
- Create and optimize automation scripts and tools using Python, Infrastructure as Code (IaC), and Kubernetes to streamline processes and reduce manual intervention.
- Maintain compliance with industry standards such as PCI-DSS, ISO-27001, ISO-27701, and ISO-27718, ensuring that all systems meet necessary security requirements.
- Oversee the management of secure infrastructure through tools like Terraform and CloudFormation, ensuring best practices are followed.
- Collaborate closely with Engineering, Cloud Platform, FinOps, and Governance, Risk, and Compliance (GRC) teams to embed security considerations into architectural designs and development workflows.
- Produce comprehensive documentation and advocate for security best practices throughout the organization, fostering a culture of security awareness.
- Participate in regular security audits and assessments to identify potential risks and recommend improvements to enhance overall security posture.
- Stay updated on the latest security trends, vulnerabilities, and technologies to ensure the organization remains ahead of potential threats.
- Mentor junior team members and share knowledge to elevate the overall skill set of the IT Ops team.
- Engage in incident response planning and execution, ensuring that the organization is prepared to respond effectively to security incidents.
- Contribute to the development of security policies and procedures that align with organizational goals and compliance requirements.
Requirements
- Demonstrated experience in cloud security roles, particularly within AWS, GCP, or Azure environments.
- Hands-on experience with Infrastructure as Code (IaC) tools such as Terraform or CloudFormation for managing cloud resources securely.
- Strong programming skills in Python or similar scripting languages to facilitate automation and enhance operational efficiency.
- Familiarity with security frameworks and compliance standards, including PCI-DSS and ISO-27001, is essential.
- Proven track record in managing security incidents and leading investigations to resolve security breaches effectively.
- Experience with Linux systems administration and container orchestration using Kubernetes.
- A proactive attitude with a strong sense of ownership, capable of thriving in cross-functional team settings.
- Excellent communication skills, both verbal and written, to effectively convey security concepts to non-technical stakeholders.
Nice to have
- Relevant certifications such as AWS Security Specialty or Google Professional Cloud Security Engineer to validate your expertise.
- Additional cloud certifications for AWS, GCP, or Azure that demonstrate a commitment to professional development.
- Background in environments that are PCI-DSS or ISO certified, showcasing familiarity with compliance requirements.
- Experience working with high-scale, mission-critical systems that demand robust security measures.
- Contributions to open-source projects, particularly in automation or security, reflecting a passion for community engagement.
- Experience in securing Kubernetes clusters in production environments, ensuring that containerized applications are protected.
Skills & tools
- Proficient in cloud platforms: AWS, GCP, Azure
- Programming expertise in Python
- Familiar with Infrastructure as Code tools: Terraform, CloudFormation
- Knowledgeable in Linux administration
- Experienced with Kubernetes for container orchestration
- Understanding of compliance standards: PCI-DSS, ISO-27001, ISO-27701, ISO-27718
Practical notes
Ebanx offers a competitive benefits package that includes an annual performance bonus program known as WAVES, meal allowances, and educational budgets for professional development and certifications. Employees enjoy comprehensive medical and dental coverage, life insurance, childcare support, and extended parental leave. Additional perks include transportation assistance, language classes, and access to the Ebanx Play well-being program, which features resources like Wellhub and SESC. The role also provides semi-flexible working hours and a year-end break between Christmas and New Year, promoting a healthy work-life balance.