Cloud Security Engineer (NXJ-208)
Brak informacji o wynagrodzeniu
SeniorFull-time
#447901·Dodano 5 dni temu·3
Źródło: NewxelTech Stack / Keywords
AzureAWSGCPTerraformKubernetesOPASentinelAzure PolicyCNAPPPython
Firma i stanowisko
The platform transforms live sports broadcasts into personalized, publication-ready highlight packages while games are actively in progress. It processes massive data volumes in real-time to power consumer-facing media products. The core cloud infrastructure relies on Azure (with AWS/GCP workloads), provisioned through Terraform and automated CI/CD pipelines. Workloads run on Kubernetes (AKS) with policy enforcement via OPA, Sentinel, and Azure Policy. Vulnerability management and runtime monitoring are driven through a CNAPP platform, and Python is used for automation and custom security integrations.
Wymagania
- 4+ years of hands-on experience in Cloud Security or Security Engineering within multi-cloud environments
- Deep expertise in Azure security architecture and cloud-native controls
- Strong practical knowledge of Kubernetes security including RBAC, network policies, admission controllers, and image scanning
- Hands-on proficiency with Terraform and Infrastructure as Code using policy-as-code principles
- Experience integrating security controls (SAST, DAST, SCA, secret scanning) into CI/CD pipelines
- Clear communication skills with ability to partner directly with engineering and management
- Familiarity with security requirements for LLM and AI infrastructure
Nice to have:
- Proficiency in Python for custom security tooling and automation
- Experience with SOC2 compliance frameworks and audit readiness
- Prior experience as a security lead or hands-on technical lead
- Exposure to modern container security practices including image signing, SBOMs, and runtime protection
Obowiązki
- Architect and enforce multi-cloud security strategy across Azure, AWS, and GCP covering IAM, network security, and secrets management
- Embed automated guardrails in Terraform and CI/CD pipelines using policy-as-code (OPA, Sentinel, Azure Policy)
- Manage Kubernetes (AKS) cluster security including RBAC, network policies, pod security standards, and admission controls
- Lead vulnerability and posture management via the CNAPP platform, managing findings to closure
- Integrate automated SAST, DAST, SCA, and secret scanning into CI/CD workflows and assist engineering teams with remediation
- Lead cloud security incident response, including post-mortems and preventive actions
- Collaborate with DevOps, MLOps, and FinOps teams to embed security baselines into workflows without impacting delivery velocity
- Manage customer security assessments and technical questionnaires alongside Sales and Legal stakeholders
Newxel
7 aktywnych ofert