Cloud Security Engineer
Indexed description
Role Overview
This is a builder-operator position requiring a combination of technical engineering and operational excellence. Success in this role is defined by a fully managed and secured endpoint environment, the implementation of short-lived credentialing for engineering workflows, and the establishment of robust monitoring and alerting systems. You will ensure that ISO 27001 controls are integrated into daily operations, facilitating efficient evidence collection for audits. Working alongside external security partners and our internal DevOps team, you will serve as the primary technical lead for security implementation.
Key Responsibilities
- Endpoint Security Management — Direct the deployment and optimization of the security stack across the Mac and Windows fleet. Manage MDM baselines, EDR configuration, and the triage of escalations from managed detection services.
- Cloud Security Operations — Maintain least-privilege IAM principles across AWS and GCP environments. Implement SSO, hardware-based MFA, and manage service account hygiene, secrets, and cloud governance guardrails.
- Detection Engineering — Centralize telemetry from cloud audit logs, endpoints, and networks. Develop and maintain high-fidelity alerting for critical security events, including unauthorized IAM changes and anomalous data egress.
- Incident Response — Serve as the primary responder for security incidents. Conduct investigations, execute containment strategies, and produce comprehensive post-incident reviews while maintaining updated runbooks.
- ISMS Operations — Operationalize ISO 27001 controls through automation. Facilitate evidence collection, conduct periodic access reviews, and manage corrective actions to support internal and external audits.
- Security SDLC Integration — Collaborate with engineering teams to integrate security into the development lifecycle. Implement secret scanning, dependency analysis, and conduct security reviews for high-risk architectural changes.
- Security Culture & Advocacy — Lead security awareness initiatives and phishing simulations. Act as a subject matter expert and accessible resource for security-related inquiries across the organization.
What We're Looking For
Required:
- 3+ years hands-on security or DevOps/infrastructure experience with meaningful security ownership — title matters less than what you've operated
- Working proficiency with at least one major cloud (AWS or GCP): IAM, audit logging, and security tooling (GuardDuty, Security Command Center, or equivalents)
- Experience deploying or administering endpoint management/EDR tooling across a fleet (any of: Intune, Jamf, Kandji, CrowdStrike, SentinelOne, Defender)
- Scripting ability for automation (Python, Bash, or PowerShell) — enough to glue systems together and automate evidence collection
- You can investigate an incident: read logs, build a timeline, distinguish evidence from assumption, and write it up clearly
- Thai and English working proficiency
Nice to have:
- ISO 27001 exposure from the inside — you've lived through an audit, owned controls, or closed nonconformities
- PDPA familiarity, or GDPR experience that translates
- Experience at a SaaS or fintech company
- Infrastructure-as-code experience (Terraform) for codifying security baselines
- Certifications like AWS Security Specialty, ISO 27001 LA/LI, GIAC, or CISSP — valued, never required
What We Offer
- Build products used by tens of thousands of businesses.
- Ship code that reaches customers quickly.
- High ownership with minimal bureaucracy.
- Learn from experienced engineers and product leaders.
- Flexible work hours and 45 days/year work from anywhere.
- Competitive compensation, health & accident insurance from day one.
- 17–19 public holidays, 12 personal leave days, and 8 annual leave days.
- A friendly, collaborative team that genuinely enjoys building together.
- Clear opportunities to grow your career as the company scales.
Location
- BKK BangRak Office (MRT Samyan or BTS Saladaeng)
Why join us:
🚀 Work with a modern tech stack | 💡 Impact thousands of users | 🤝 Collaborative, growth-oriented team
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search