- Company Name
- Theoris
- Job Title
- Cloud Engineer
- Job Description
-
**Job Title:** Cloud Security Engineer
**Role Summary:**
Design, implement, and maintain secure cloud infrastructure and secret management solutions in a highly regulated financial services environment. Focus on automation, infrastructure‑as‑code, and integration of security controls into CI/CD pipelines to enhance reliability and compliance.
**Expectations:**
* Deliver hands‑on operations for HashiCorp Vault and other security tooling.
* Develop secure, modular IaC with Terraform across multiple environments.
* Harden AWS/Azure/GCP workloads and enforce least‑privilege access.
* Script automation for policy enforcement, compliance checks, and incident response.
* Collaborate with DevOps, SRE, and security teams to embed security into build‑and‑deploy processes.
* Participate in on‑call rotations and post‑incident reviews.
**Key Responsibilities:**
* Configure and maintain Vault (auth, secrets engines, policies, namespaces, HA/DR).
* Integrate Vault with CI/CD pipelines for secrets injection and dynamic rotation.
* Write and maintain automation scripts (Python, Bash, Go/Ruby) for security tasks.
* Build and review Terraform modules, manage remote state, and apply policy‑as‑code.
* Harden AWS services (EC2, IAM, VPC, S3, KMS, Config, CloudTrail) and run multi‑account governance.
* Support containerized deployments: Docker, Kubernetes, RBAC, probes, ingress, network policies.
* Implement security scanning and compliance gates in Jenkins, GitLab CI, or GitOps workflows.
* Troubleshoot Unix/Linux systems, kernel events, performance, and network issues.
* Collaborate on incident response, post‑mortems, and toil reduction initiatives.
**Required Skills:**
* Hands‑on Vault administration (auth, dynamic secrets, policy, HA/DR).
* Strong scripting/programming (Python, Bash; Go or Ruby optional).
* Terraform IaC design, multi‑env patterns, remote state, policy‑as‑code (Sentinel/OPA).
* Cloud expertise in AWS (EC2, IAM, VPC, S3, KMS, Config, CloudTrail); Azure/GCP knowledge a plus.
* Unix/Linux system administration, debugging, and performance tuning.
* Containerization skills: Docker, Kubernetes (RBAC, pods, ingress, network policies).
* CI/CD pipeline management (Jenkins, GitLab CI, GitOps).
* Experience in security best practices (least‑privilege IAM, encrypted resources, audit logging).
**Required Education & Certifications:**
* Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
* Professional certifications preferred:
- HashiCorp Certified: Vault Associate or Professional
- HashiCorp Certified: Terraform Associate
- AWS Certified Security – Specialty (or equivalent Azure/GCP security cert).