TU PRÓXIMO CAPÍTULO
Cloud Security Engineer
Sobre el puesto
• Own hands-on security engineering and build the security function as the company grows
• Review source code and architecture across APIs, backend services, and internal tooling
• Conduct targeted penetration testing and work with engineers on root causes and practical fixes
• Manage vulnerabilities and commissioned external penetration tests
• Own alerting, intrusion detection, incident processes, and the on-call path
• Harden cloud and platform security, including access control, network boundaries, secrets, containers, deployment pipelines, CI/CD, repositories, and dependencies
• Secure APIs through authentication, authorization, tenant isolation, token scoping and lifecycle, abuse prevention, enterprise SSO, and audit trails
• Secure AI systems against prompt injection and risks involving tools, agents, MCP, retrieval, data ingestion, and data residency
• Manage identity and company security, including employee SSO, MFA, privileged access, onboarding/offboarding, access reviews, MDM, endpoint security, and SaaS access
• Conduct threat modelling and secure design reviews across engineering pods
• Set security priorities and roadmap based on actual risk
• Decide what security capabilities to build, buy, automate, or defer
• Grow the security team and hire into it
• Represent security to enterprise clients
• Lead the SOC 2 programme on Drata
• 5+ years of hands-on security work spanning more than one discipline
• Application security depth, including web/API attack knowledge, code review, and targeted penetration testing
• Strong grasp of authentication and authorization, including OAuth, OIDC, sessions, token handling, and access control
• Cloud security fundamentals covering identity, network, workload, and pipeline security
• Defensive experience investigating real incidents and building or improving detection and alerting
• Threat modelling and secure architecture for cloud, container, and API systems
• Engineering background; ability to work comfortably in a codebase and build security solutions
• Prior Go experience is a plus, not a requirement
• Experience in resource-constrained environments such as startups, small security teams, or consultancies
• Appetite to build and eventually lead a security team; prior leadership experience is a plus, not a requirement
• Working proficiency with Claude Code; specific examples required
• Judgement about security pace in a company that ships daily
• Experience of SOC 2, ISO 27001, or demanding enterprise security reviews
• Excellent spoken and written English
• European or African time zones (±3 hours from CET)
• Available full-time, 40 hours per week
• Nice-to-have: AI and LLM security, early security hire experience, security engineering leadership or mentoring, Go, security tooling or automation, MDM, endpoint protection, identity provider administration, compliance automation tooling, security certifications, GDPR, travel or GDS exposure, German
• Full-time employment (40 hours per week)