Senior Security Engineer I
Job description
About the role
In this position, you will be responsible for designing, implementing, and maintaining security measures that safeguard our cloud infrastructure and edge services. Your role involves translating high-level security architecture into practical, scalable solutions through infrastructure-as-code (IaC) tools, ensuring our global platforms are protected against a wide range of modern cyber threats. You will focus on cloud-native workloads and AI functionalities, working closely with engineering teams to embed security best practices into development and deployment processes. This role requires a proactive approach to identifying vulnerabilities, managing security risks, and ensuring compliance with industry standards. You will be a key player in maintaining the security integrity of Talkdesk's cloud environment, contributing to a secure, resilient, and compliant infrastructure that supports the company's growth and innovation.
Key facts
What you'll do
- Serve as the primary owner of the Cloud-Native Application Protection Platform (CNAPP), overseeing its deployment, configuration, and ongoing management to ensure comprehensive security coverage across multiple cloud providers.
- Identify misconfigurations, vulnerabilities, and compliance issues within cloud environments using CNAPP and Cloud Security Posture Management (CSPM) tools, and develop strategies to remediate these issues effectively.
- Use CNAPP and CSPM to gain detailed visibility into identity management, secrets management, and data security risks, enabling prioritization of security issues based on potential impact.
- Deploy, configure, and manage Web Application Firewalls (WAF) and edge security solutions to defend against Layer 7 attacks, DDoS attacks, malicious bots, and other web-based threats.
- Oversee Endpoint Detection and Response (EDR) and Cloud Workload Protection Platforms (CWPP) to secure containers, serverless functions, and virtual machines, ensuring they are protected against exploitation and malware.
- Develop and implement secure key management systems (KMS) and identity-aware access policies (IAM) to support Zero Trust security models, ensuring that access is granted based on strict identity verification and least privilege principles.
- Integrate CNAPP findings and alerts into the CI/CD pipeline, automating security checks and risk remediation processes using Infrastructure as Code (IaC) tools such as Terraform or Ansible.
- Collaborate with development and operations teams to translate security alerts into actionable remediation steps, fostering a security-first culture across engineering teams.
- Conduct regular security assessments, vulnerability scans, and configuration audits to identify potential weaknesses and recommend improvements.
- Support incident response efforts related to cloud security breaches or threats, participating in investigations and remediation activities.
- Stay current with emerging cloud security threats, industry best practices, and new security tools to continuously enhance the security posture of Talkdesk's infrastructure.
- Document security policies, procedures, and configurations, ensuring compliance with internal standards and external regulations.
- Provide training and guidance to engineering teams on cloud security best practices, helping to embed security considerations into the development lifecycle.
- Participate in security reviews of new projects and features, ensuring security controls are integrated from the outset.
- Maintain an understanding of the latest security trends related to cloud-native applications, edge computing, and AI security to proactively address potential vulnerabilities.
Requirements
- Extensive hands-on experience working with Cloud-Native Application Protection Platforms (CNAPP), with a focus on Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP).
- Proven ability to manage and prioritize cloud security risks, including misconfigurations, vulnerabilities, and compliance issues, using centralized security platforms.
- Strong background in edge security services, including Web Application Firewalls (WAF), DDoS mitigation, and Zero Trust Network Access (ZTNA).
- Proficiency with Infrastructure as Code (IaC) tools such as Terraform or Ansible, especially in integrating security controls and performing pre-deployment security scans.
- Deep understanding of AWS security services, including Identity and Access Management (IAM), Key Management Service (KMS), and CloudTrail, with experience in configuring and managing these services.
- Excellent communication skills, capable of translating complex CNAPP alerts into clear, actionable steps for engineering teams.
- Knowledge of the OWASP Top 10 security risks and common cloud security vulnerabilities, with experience in mitigating these risks.
- Familiarity with Linux/Unix operating systems, including command-line tools and security best practices.
- Ability to work collaboratively in a fast-paced environment, managing multiple priorities and projects simultaneously.
- Strong problem-solving skills and a proactive attitude toward security challenges.
- Experience working in a security engineering or security operations role within a cloud environment.
Nice to have
- Experience with serverless security solutions and edge computing platforms, such as Edge Workers or similar technologies.
- Familiarity with automated security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Interactive Application Security Testing (IAST).
- Knowledge of compliance frameworks such as ISO 27001, NIST, and SOC2, especially as they relate to cloud environments.
- Relevant security certifications, such as AWS Security Specialty, Certified Cloud Security Professional (CCSP), Certified Cloud Security Knowledge (CCSK), or CNAPP-specific certifications.
- Experience with container security tools and practices, including image scanning and runtime protection.
- Understanding of data encryption, tokenization, and data masking techniques in cloud environments.
Skills & tools
- Cloud-Native Application Protection Platforms (CNAPP)
- Cloud Security Posture Management (CSPM)
- Cloud Workload Protection (CWPP)
- Web Application Firewalls (WAF)
- Endpoint Detection and Response (EDR)
- Infrastructure as Code (Terraform, Ansible)
- AWS security services (IAM, KMS, CloudTrail)
- Security assessment and vulnerability scanning tools
- DDoS mitigation solutions
- Zero Trust security frameworks
Practical notes
This role may require occasional travel for team meetings, training, or industry events. Talkdesk offers competitive benefits, including health insurance, flexible working arrangements, and opportunities for professional growth. We encourage applications from candidates who meet the outlined qualifications and are passionate about advancing cloud security practices. Candidates should be prepared to demonstrate their experience through technical discussions and practical assessments during the interview process. We value diversity and are committed to creating an inclusive environment for all employees.