Cyber Security Staff Engineer
Job description
About the role
This role is responsible for the security lifecycle of embedded finance operations within our European platform. The hire will translate banking regulations into concrete technical controls that protect customer data and financial transactions. Decisions made in this position directly affect how partner organizations serve their customers and maintain trust. You will own the design and implementation of security measures for critical financial workflows. The position requires a deep understanding of threat models specific to digital banking environments. You will act as a security translator between regulatory requirements and engineering execution. Your work will ensure that the platform remains resilient against evolving financial crime techniques.
Key facts
What you'll do
- Design and manage AWS WAF configurations to protect applications and APIs from application-layer attacks, including OWASP Top 10 risks, automated bots, and emerging zero-day exploits.
- Build and manage multi-account cloud structures using AWS Organizations and Control Tower, and define Service Control Policies to isolate environments and limit unauthorized access scope.
- Identify security technical debt in existing infrastructure and refactor legacy configurations into secure Infrastructure as Code using Terraform, including auditing templates for misconfigurations before deployment.
- Lead incident response for cloud events, analyzing AWS security alerts, performing forensic investigation, and coordinating containment actions with engineering teams to restore normal operations.
- Guide identity and access management strategy by shifting legacy roles toward least-privilege access and owning policy reviews for IAM, resource permissions, and authorization paths.
- Monitor cloud-native detection and logging tools and validate coverage across AWS Security Hub, GuardDuty, CloudTrail, Inspector, and KMS, identifying gaps and defining measurable improvements.
- Maintain compliance with financial regulations and internal standards by implementing controls aligned with NIST, CIS benchmarks, and BaFin requirements through continuous validation and testing.
- Drive security automation initiatives to reduce manual operations and improve detection accuracy across the AWS estate, using orchestration to streamline response workflows.
- Evaluate native AI services such as Bedrock and Quick, assessing security implications for new workflows and data pipelines to ensure safe adoption.
- Partner with cloud architects to review current environments, retire deprecated resources, and refactor legacy components into secure architectures that meet modern standards.
Requirements
- Hold a degree in Computer Science, Cloud Computing, Cyber Security, Information Technology, or have equivalent professional experience that demonstrates comparable knowledge depth.
- Bring more than five years of professional cloud security experience with a demonstrated history of securing complex AWS environments in production settings.
- Show advanced skills in AWS WAF, Shield, and CloudFront, with experience designing and tuning protections for public-facing endpoints under real-world attack conditions.
- Write secure infrastructure code in Terraform and audit existing templates for drift and misconfigurations to prevent deployment of vulnerable states.
- Master AWS security and identity services, with expertise in IAM, KMS, Security Hub, GuardDuty, and multi-account security models that enforce centralized governance.
- Use business-level English when communicating with engineering and architecture teams, ensuring that technical concepts are clear and actionable for cross-functional stakeholders.
- Hold AWS Certified Security
- Specialty certification as a mandatory requirement, with AWS Certified Solutions Architect (Associate or Professional) preferred for broader architectural understanding.
- Think analytically to untangle legacy environments and define clear, secure milestones and migration paths that reduce risk over time.
- Collaborate effectively within cross-functional teams and avoid siloed work, enabling secure delivery across engineering groups without compromising operational integrity.
Nice to have
- Understand agile delivery and lean principles, with experience contributing to process improvements that enhance security delivery speed and reliability.
Practical notes
- Location is fixed in Berlin, requiring full-time onsite presence.
- The engagement is full-time based on standard employment terms.
- Details regarding requirements and submission instructions are confirmed on the official application page, and candidates must verify these before proceeding.
About the company
Based in Bolechowo-Osiedle near Poznań, this company builds public transport vehicles. It operates as a unit of Spanish rolling stock maker CAF. Focused on buses, Solaris serves European routes. Electric bus offerings hold roughly 18 percent of the regional market. Operations center on Polish production, with engineering directed toward city transit needs. The firm supplies municipal and commercial operators, supporting urban mobility across multiple countries with its specialized vehicle designs.