As a DevSecOps / Cloud Security Engineer, you will be responsible for embedding security into every stage of our infrastructure lifecycle, from design to deployment. You will lead the implementation of cloud-native security controls in AWS, harden Kubernetes environments, and drive best practices across CI/CD pipelines. Your role includes continuous vulnerability management, network protection, monitoring for threats, and working with development, DevOps and IP teams to ensure secure-by-default practices. You’ll also proactively identify risks, secure network perimeters, and automate remediation wherever possible.
This role can be based in our Berlin, Lisbon, or Warsaw offices. Relocation is required if you are not currently based in one of these cities.
About the Role
Design, implement, and evolve scalable cloud security controls across AWS multi-account environments using security-as-code principles
Own Kubernetes security architecture including workload isolation, RBAC, pod security standards, and network segmentation
Embed security automation into CI/CD pipelines, including image scanning, IaC validation, and policy enforcement
Continuously assess cloud and Kubernetes environments for vulnerabilities, misconfigurations, and emerging threats
Design and maintain strong IAM and secrets management practices, enforcing least-privilege access
Partner with DevOps, Platform, and IP/Network teams to deliver security controls as code and by design
Analyze network traffic and security telemetry using flow logs, metrics, and targeted packet inspection where required
Ensure alignment with internal security policies and external frameworks (CIS, NIST, ISO 27001, etc.)
Produce and maintain clear documentation, including security architectures, runbooks, and incident response playbooks
Act as a security champion, driving best practices, awareness, and secure engineering culture across teams
About You
A minimum of 3+ years of experience with Cloud Security / DevSecOps / Infrastructure Security
Solid Linux security and cloud networking fundamentals
Hands-on Kubernetes security (RBAC, NetworkPolicies, pod security, image scanning)
Infrastructure as Code (Terraform) and Git-based workflows
Scripting for automation (Python or Go or Bash)
Experience with vulnerability management and container security
Security-first mindset with strong troubleshooting skills
Experience with WAFs and cloud DDoS protection
Comfortable with packet inspection, flow analysis, and traffic monitoring (tcpdump, Wireshark, Suricata, etc.)