- Company Name
- Cognism
- Job Title
- Security Engineer
- Job Description
-
**Job title:** Security Engineer
**Role Summary:**
Responsible for strengthening and maintaining Cognism’s security posture across cloud, application, and infrastructure layers. Works cross‑functionally with IT, engineering, data, and product teams to implement secure practices, manage security tools, support compliance frameworks, and reduce technical debt in a zero‑trust environment.
**Expectations:**
- 7+ years of security engineering experience.
- Proven hands‑on expertise in cloud‑native environments, especially AWS architecture and IAM.
- Experience securing SaaS platforms and integrations.
- Strong knowledge of containerisation, Kubernetes, IaC, CI/CD, and log management.
- Proficiency with application security tools: SAST, SCA, CSPM, DAST.
- Familiarity with ISO/IEC 27001, SOC 2 Type II, NIST CSF, and related compliance programs.
- Excellent written and verbal communication in English; self‑directed, ownership‑driven mindset.
**Key Responsibilities:**
- Enhance overall security posture by proactively identifying and mitigating risks.
- Maintain, update, and scale security tools and automations across the organization.
- Manage security of AWS cloud architecture and IAM services, applying best practices.
- Implement and monitor application security (SAST, SCA, CSPM, DAST) to reduce vulnerabilities.
- Secure containerised workloads, Kubernetes clusters, CI/CD pipelines, and IaC workflows.
- Support ISO 27001, SOC 2 Type II, NIST CSF compliance initiatives and audit activities.
- Collaborate with IT, Engineering, Data, and Product teams to embed security practices.
- Identify technical debt, standardise security processes, and drive continuous improvement.
**Required Skills:**
- Cloud security (AWS, IAM, cloud‑native architecture).
- Containerisation, Kubernetes, infrastructure‑as‑code, and CI/CD.
- Shell scripting, log‑management, and automation.
- Application security tools: SAST, SCA, CSPM, DAST.
- Compliance frameworks: ISO/IEC 27001, SOC 2 Type II, NIST CSF.
- Strong communication, documentation, and stakeholder collaboration.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent work experience).
- Security certifications (preferred): CISSP, CompTIA Security+, AWS Security Specialty, or equivalent.