# Senior Security Engineer - Cloud Security

**Company:** [Nasuni](https://hotfix.jobs/companies/nasuni)
**Location:** Warsaw, Poland
**Role:** Security Engineering
**Experience:** 6+ years
**Skills:** AWS, Azure, GCP, Aws Iam, Amazon Vpc, Guardduty, Aws Security Hub, Cloudtrail, Aws Kms, Wiz, Kubernetes, Terraform, CloudFormation, Python
**Posted:** 2026-08-03

> Senior individual contributor responsible for improving multi-cloud security posture, leading vulnerability management, hardening infrastructure, and embedding DevSecOps controls. Requires 6–9 years of security experience, deep AWS expertise, and experience with cloud-native environments and vulnerability programs.

## Job Description

## Responsibilities

### Cloud Security Engineering and Posture Management
- Improve cloud security posture across AWS, Azure, and Google Cloud, including workload security, IAM hardening, network segmentation, encryption, and least-privilege enforcement.
- Lead cloud security assessments and configuration reviews using Wiz and cloud-native tools.
- Drive zero-trust initiatives and cloud-native security controls across multi-cloud infrastructure.
- Translate security architecture standards into operational controls and provide implementation feedback.
- Evaluate and implement security controls for containers, Kubernetes workloads, CI/CD pipelines, and Infrastructure as Code.
- Contribute to cloud security architecture and design reviews, implementation guidance, operational security expertise, and risk assessments.

### Vulnerability Management
- Lead execution and continuous improvement of the vulnerability management program across AWS, Azure, and Google Cloud.
- Define and enforce vulnerability SLAs and risk-based prioritization frameworks.
- Analyze vulnerability data, synthesize trends, and produce executive-ready reporting on exposure, remediation velocity, and risk posture.
- Drive systemic remediation with DevOps, SRE, IT/infrastructure, and engineering teams.
- Tune scanning coverage, detection fidelity, and vulnerability-management platform configuration.
- Identify program gaps, define improvement roadmaps, and present recommendations to security leadership.

### DevSecOps and Infrastructure Hardening
- Embed security controls into CI/CD pipelines, Infrastructure as Code templates, and cloud provisioning workflows.
- Drive policy-as-code, automated misconfiguration detection, and runtime security controls.
- Define and enforce secure configuration baselines across cloud workloads, operating systems, and network infrastructure.
- Harden container and Kubernetes environments and support secrets management and workload identity practices.

### Incident Response
- Support complex and high-severity incident responses involving cloud and infrastructure security.
- Improve incident response playbooks and runbooks for cloud and infrastructure-related security events.
- Conduct cloud threat hunting and contribute to detection engineering.
- Participate in post-incident reviews and systemic improvements.

### Compliance and Governance
- Align vulnerability-management and cloud-security controls with compliance requirements.
- Prepare technical evidence and control documentation for audits and compliance activities.
- Advise engineering and business teams on security considerations for technologies, integrations, and infrastructure decisions.

### Mentorship and Team Contribution
- Mentor colleagues and peers and guide technical decisions.
- Lead security tooling evaluations and contribute to platform investment decisions.
- Design and scale AI-assisted security workflows for vulnerability analysis, cloud security assessments, remediation prioritization, and operational efficiency, with strong validation and risk-management practices.

## Requirements

### Experience
- 6–9 years of experience in security engineering, cloud security, or a closely related discipline.
- Ownership of complex cloud security workstreams in a multi-cloud or cloud-native environment.
- Experience leading or significantly contributing to a vulnerability management program, including tool operation, process design, and stakeholder engagement.
- Experience securing cloud-native SaaS products or working in complex cloud-first technology environments.
- Experience designing or operationalizing repeatable AI-assisted workflows for security engineering, vulnerability management, security analysis, automation, or operational efficiency.

### Cloud Security
- Deep hands-on AWS security expertise, including IAM, VPC/networking, GuardDuty, Security Hub, CloudTrail, KMS, and AWS-native hardening practices.
- Additional Azure and Google Cloud experience is a plus.
- Strong working knowledge of CSPM tools; direct Wiz experience is highly advantageous.
- Experience with container security, Kubernetes security, and Infrastructure as Code security tooling such as Terraform or CloudFormation.
- Familiarity with CI/CD security integration and DevSecOps practices.

### Technical Foundations
- Strong understanding of network security, protocols, and infrastructure security fundamentals, including TCP/IP, DNS, TLS, VPN, and firewall design.
- Working knowledge of IAM, Zero Trust principles, secrets management, OAuth 2.0, OIDC, and SAML.
- Scripting or automation experience with Python, Bash, or equivalent.
- Ability to validate AI-generated outputs using security expertise, testing, data analysis, or structured review before production use.

### Frameworks and Compliance
- Familiarity with NIST CSF, CIS Benchmarks, and OWASP frameworks.
- Strong command of CVSS, EPSS, and risk-based prioritization methodologies.
- Experience conducting technical risk assessments and security design reviews.

### Communication and Influence
- Ability to explain complex security risks and trade-offs clearly to engineering and business stakeholders.

## Similar jobs

- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr
- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Compliance Engineer](https://hotfix.jobs/jobs/63197ba5-a12d-497a-a0b9-91e5e7050ac1) - Retell AI - Remote - $72k – $90k/yr
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr

**Apply:** https://hotfix.jobs/jobs/eb980e9f-de90-418c-8ee5-d45f19084e84
**Canonical:** https://hotfix.jobs/jobs/eb980e9f-de90-418c-8ee5-d45f19084e84