Our client is expanding its cloud security engineering capability to support secure workloads across cloud environments. As a Cybersecurity Engineer, you will implement security controls, automate remediation, and ensure continuous compliance across cloud and containerised environments.
Key Responsibilities
- Cloud Security Engineering — Implement guardrails, secure configurations, and workload protections across AWS, Azure, and GCP.
- IAM Engineering — Enforce least-privilege access, manage service accounts and workload identity, and oversee role governance.
- Terraform Security — Build secure Infrastructure-as-Code (IaC) modules, enforce policy-as-code, and automate the deployment of security controls.
- Kubernetes Security — Secure clusters, admission controllers, network policies, and runtime protection.
- SIEM Integration — Integrate cloud logs and security findings into SIEM platforms such as Splunk, Chronicle, and QRadar.
- CSPM/CNAPP — Support Cloud Security Posture Management (CSPM) and Cloud-Native Application Protection Platform (CNAPP) tooling and continuous security posture management.
- Security Reviews & Threat Modelling — Conduct security reviews, threat modelling, and remediation activities.
- Regulatory Compliance — Ensure compliance with GDPR/DSGVO, BSI C5, NIS2, and relevant financial-sector regulatory frameworks.
Required Skills & Experience
- 4–8 years of experience in cloud security engineering or DevSecOps.
- Hands-on experience with cloud security services across AWS, Azure, and/or GCP.
- Strong experience with Terraform and CI/CD security.
- Solid understanding of Kubernetes and container security.
- Experience with SIEM, CSPM, CNAPP, and cloud-native detection tooling.
- Familiarity with German and EU regulatory requirements.
Nice to Have
- Relevant certifications, such as:
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate
- HashiCorp Certified: Terraform Associate
- Experience within financial services or other regulated environments.
- Exposure to multi-cloud landing zones or sovereign cloud concepts.