Cloud Security Engineer
Indexed description
Why this role exists
This is the role focussed on ensuring our systems are secure and our security posture is not only well documented, but proudly advertised.
This role is a technical lead of our compliance engine.
What You'll Own
Corporate IT & identity
- Identity as the backbone: SSO, MFA, least-privilege access, and clean joiner/mover/leaver flows across all locations.
- SaaS administration and access governance across our tool estate.
- Harden our cloud environment (network, secrets, key management, logging, config baselines) as the portal scales to millions of users.
- Partner with engineering on secure SDLC: dependency and vulnerability management, security review of new services, and remediation tracking.
- MDM across the fleet, disk encryption, patch baselines, and a sane BYOD/company-device policy.
- Centralised logging/alerting, a workable detection baseline, and an incident-response runbook.
- Implement and operate the technical controls behind SOC 2 and ISO 27001, and own continuous evidence collection so audits are boring.
- Feed vendor/third-party security assessments.
- Lightweight, useful security training and phishing resilience for the team.
- 3–6 years in security engineering, cloud security, or IT/infrastructure with a strong security lean.
- Hands-on cloud security on at least one hyperscaler (AWS, GCP or Azure): IAM, networking, secrets/key management, logging, config hardening.
- Solid identity & access fundamentals (SSO/SAML/OIDC, MFA, RBAC) and endpoint management (MDM).
- Working understanding of SOC 2 and/or ISO 27001 controls — you've supplied evidence for an audit, or you can clearly show you know what one demands.
- Comfortable scripting/automating (Python/Bash) and reading infrastructure-as-code.
- Autonomous and pragmatic: you secure things without becoming the department of "no."
- AWS Security Specialty, AZ-500, CCSP, CISSP, or ISO 27001 Lead Implementer.
- Infrastructure-as-code security (Terraform + Checkov/tfsec) and SIEM experience.
- Prior security work at a product SaaS with an enterprise buyer base.
- AI/LLM security exposure (prompt-injection defence, model/endpoint hardening) — relevant as we run ML on motion data.
- Having stood something up from scratch in a small, scrappy team.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search