Senior II Security Engineer
Job description
About the role
You will own the design, implementation, and operation of platform security across AWS, Kubernetes, and GCP, with a strong focus on detection, alerting, and incident response readiness. You will lead key platform security initiatives end-to-end, from problem definition through rollout and iteration, ensuring security decisions are practical, measurable, and scalable. As a strong technical voice, you will define how platform security is designed, implemented, and operated across the organization. You will evolve monitoring from basic log collection to a detection and response capability that is effective, trusted, and actionable by the business. You will work hands-on with current tooling such as Datadog as your SIEM, Okta as the primary IdP, and a range of SaaS platforms to secure access and data flows. You will drive cross-functional platform security initiatives in partnership with SRE, Data, Engineering, and GRC from problem definition to production rollout. You will strengthen cloud and platform security across AWS and Kubernetes, with expanding scope in GCP, through practical guardrails, secure patterns, and automation. You will improve the robustness of access to internal infrastructure, including identity, privileged access, and auditability, to reduce risk across the environment. You will mature detection and response capability using Datadog, improving log coverage and data quality for cloud, Kubernetes, CI/CD, identity, and key SaaS platforms. You will build and tune actionable detections with clear severity, ownership, and expected frequency to guide rapid response.
Key facts
What you'll do
- Own platform security across AWS, Kubernetes, and GCP, with a strong focus on detection, alerting, and incident response readiness.
- Lead key platform security initiatives end-to-end, from problem definition through rollout and iteration.
- Act as a strong technical voice in defining how platform security is designed, implemented, and operated at Preply.
- Evolve our monitoring from "we have a SIEM" to a detection and response capability that is effective, trusted, and actionable.
- Work hands-on with our current tooling, including Datadog as our SIEM, Okta as our primary IdP, and a range of SaaS platforms.
- Drive cross-functional platform security initiatives from problem definition to production rollout, partnering with SRE, Data, Engineering, and GRC.
- Strengthen cloud and platform security across AWS and Kubernetes, with expanding scope in GCP, through practical guardrails, secure patterns, and automation.
- Improve the robustness of access to internal infrastructure, including identity, privileged access, and auditability.
- Improve security of Kubernetes deployments, including cluster and workload security, policy enforcement, and secure workload identity patterns.
- Mature detection and response capability using Datadog.
- Improve log coverage and data quality (cloud, Kubernetes, CI/CD, identity, and key SaaS).
- Build and tune actionable detections with clear severity, ownership, and expected frequency.
- Reduce noise through correlation, deduplication, enrichment, and continuous tuning.
- Establish repeatable triage workflows and clear escalation paths, being part of the Security on-call rotations.
- Create investigation playbooks and runbooks so alerts can be handled consistently and quickly.
- Partner with Data teams to improve monitoring for suspicious activity and sensitive access patterns, with an emphasis on practical, high-signal alerting.
- Improve secrets management and reduce exposure risk across CI/CD and runtime.
- Build security automation that makes the secure path the easy path for engineers.
Requirements
Strong experience securing cloud and platform environments, especially AWS and Kubernetes, and the ability to extend that security approach into GCP.
Hands-on experience driving and delivering technical security initiatives end-to-end in production environments.
Strong understanding of the software development lifecycle, and comfort working with CI/CD and infrastructure as code.
Practical experience improving identity and access security, with strong familiarity with Okta event monitoring and identity-focused detection patterns.
Experience building or maturing security operations and incident response practices, including practical runbooks and escalation paths.
Comfort working in a fast-paced, high-growth environment with ambiguous problems and evolving priorities.
Strong collaboration skills and the ability to influence without direct authority across engineering and operations teams.
Commitment to self-direction, continuous learning, and active contribution to a growing security program.
Nice to have
Exposure to compliance frameworks such as ISO 27001 and GDPR.
Experience with security automation and DevSecOps practices in cloud-native environments.
Familiarity with modern SIEM workflows, log analytics, and detection engineering principles.
Practical notes
Hours: Full-time.
Location: Barcelona.