Cloud Security Policy Engineer
Copenhagen, Denmark — Hybrid
Cloud Software | Policy-as-Code | Cloud Security | Platform Security | DevSecOps
Our client, a growing Cloud Software company based in Copenhagen, is looking for a Cloud Security Policy Engineer to build policy-as-code systems that automatically enforce security and infrastructure standards across AWS and Kubernetes environments.
You'll work at the intersection of Cloud Security, Platform Engineering, and DevSecOps, translating security requirements into scalable, testable guardrails that prevent insecure infrastructure from reaching production.
What You'll Work On
• Design and implement policy-as-code controls using OPA and Rego
• Build preventative security guardrails across Kubernetes and AWS
• Enforce infrastructure standards throughout Terraform workflows
• Develop policies covering IAM, networking, workloads, and cloud configuration
• Integrate automated policy checks into CI/CD pipelines
• Build security tooling and automation in Python
• Prevent insecure Kubernetes configurations before deployment
• Automate validation of Terraform plans and cloud infrastructure changes
• Test, version, and maintain security policies as production code
• Improve developer feedback when infrastructure violates security standards
• Partner with Platform and Cloud teams to make compliant infrastructure the default
Core Skills
• 4+ years in Cloud Security, Platform Security, DevSecOps, Cloud Engineering, or similar roles
• OPA / Open Policy Agent
• Rego
• Terraform
• Kubernetes
• AWS
• IAM
• Python
• Strong understanding of cloud-native security and infrastructure-as-code
Nice to Have
Kyverno
Terraform policy frameworks
Kubernetes admission control
AWS Organizations / Control Tower
GitHub Actions / GitLab CI
Policy testing and CI/CD automation
CIS benchmarks
Security-as-Code
GitOps / Argo CD
Container security
Experience building developer-facing security guardrails