- Company Name
- Fimador
- Job Title
- Cloud Security Engineer
- Job Description
-
**Job title**
Cloud Security Engineer
**Role Summary**
Senior cloud security engineer responsible for integrating secure software development practices into large-scale platforms. Acts as a technical leader and security coach, shaping culture, driving accountability, and ensuring compliance with global security standards.
**Expectations**
- Mastery of AWS security best practices, gap analysis, remediation, and architecture reviews.
- Lead threat modeling, penetration testing coordination, and incident‑response support.
- Ensure compliance with GDPR, ISO 27001/27017, HIPAA, EU AI Act, Data Act, and similar regulations.
- Mentor engineering teams and influence secure design principles across product roadmaps.
**Key Responsibilities**
1. Lead security initiatives and secure‑dev improvements in collaboration with engineering, product, and operations teams.
2. Serve as a security coach, mentoring teams on best practices and challenging them to exceed compliance expectations.
3. Partner with Product Managers, Engineering Leaders, and stakeholders to prioritize security deliverables and embed them into product roadmaps.
4. Identify and resolve process inefficiencies to streamline secure‑dev workflows.
5. Champion industry‑leading security practices and drive continuous improvement.
6. Conduct AWS security reviews, architecture assessments, and gap analyses.
7. Coordinate penetration testing with external partners, filter false positives, and translate findings into actionable engineering improvements.
8. Perform threat modeling to uncover realistic attack vectors and implement pragmatic controls.
9. Support incident response, remediation planning, deployment of fixes, and communication of mitigations.
10. Ensure adherence to financial and data‑privacy regulations and emerging legal requirements.
**Required Skills**
- Deep expertise in AWS security framework, including IAM, VPC, KMS, CloudTrail, GuardDuty, Security Hub, and Config.
- Experience with cloud security architecture reviews, gap analysis, and remediation planning.
- Proficient in secure DevOps practices, CI/CD pipeline hardening, and compliance automation.
- Skilled in threat modeling (STRIDE, PASTA), penetration testing management, and incident‑response coordination.
- Knowledge of regulatory frameworks: GDPR, ISO 27001/27017, HIPAA, EU AI Act, Data Act.
- Strong communication and mentorship abilities; capable of influencing cross‑functional teams.
- Ability to assess and quantify security risks and translate them into business impacts.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or a related technical field (minimum 5 years of relevant experience).
- AWS Certified Security – Specialty (preferred and required for senior role).
- Additional certifications in ISO 27001 Lead Implementer, or similar compliance credentials, are highly valued.