Job Closed
This listing is no longer active.
Somos una empresa de tecnología que busca impulsar y habilitar el comercio digital en Latinoamérica.
Cloud Security Engineer
Location
Colombia
Posted
73 days ago
Salary
0
Seniority
Senior
Job Description
Cloud Security Engineer
Addi
• Own and drive cloud security across Addi's AWS infrastructure, laying the technical foundation for a mature, scalable cloud security program. • Conduct a comprehensive cloud security assessment across all AWS accounts within the first 60 days, producing a prioritized findings inventory and a remediation roadmap, ensuring 100% of critical and high-severity findings are remediated in the SLA. • Design, configure, and operationalize CrowdStrike CNAPP from the ground up, achieving full AWS environment coverage and enabling continuous posture monitoring, misconfiguration detection, and threat detection across cloud workloads. • Assess the current Terraform codebase and define secure IaC standards and best practices, including policy-as-code controls, secrets management, and least privilege enforcement, with ≥80% of new infrastructure deployments following the defined standards. • Own and maintain the cloud security controls required to sustain ISO 27001 certification, ensuring zero critical gaps in cloud-related control domains and delivering the necessary evidence and documentation for ongoing audits. • Establish continuous cloud security monitoring and alerting within CrowdStrike NG-SIEM, ensuring all critical cloud events are correlated and actionable, with defined SLAs for response to cloud-originated alerts.
Job Requirements
- Deep AWS Security Expertise (Must-Have)
- Hands-on experience securing AWS environments, including IAM, VPC, S3, CloudTrail, GuardDuty, Security Hub, and KMS.
- Strong understanding of the AWS shared responsibility model, attack surface management, and cloud-native threat vectors.
- Proven ability to assess and harden AWS environments against CIS Benchmarks, AWS Well-Architected Security Pillar, and ISO 27001 controls.
- CNAPP / CSPM Operational Experience (Must-Have)
- Experience operating CNAPP or CSPM platforms (CrowdStrike Falcon Cloud Security, Wiz, Prisma Cloud, or equivalent) in production environments.
- Ability to configure detection rules, suppress false positives, and translate posture findings into actionable remediation tasks for engineering teams.
- Comfortable building cloud security dashboards and reporting for technical and non-technical audiences.
- Cloud Vulnerability & Risk Management (Must-Have)
- Experience managing cloud security findings end to end, from identification and prioritization through remediation tracking and closure.
- Ability to assess risk based on exploitability, exposure, and business impact rather than CVSS score alone.
- Track record of driving cross-functional remediation with engineering and platform teams.
- Collaboration & Communication (Must-Have)
- Comfortable working as an individual contributor embedded in a cybersecurity team, partnering closely with platform and engineering teams.
- Able to translate complex cloud security risks into clear, prioritized recommendations for both technical and business stakeholders.
- Terraform & Secure IaC (Nice to Have)
- Hands-on experience writing and reviewing Infrastructure as Code in production AWS environments.
- Experience implementing security controls within IaC pipelines, including static analysis tools (e.g., Checkov, tfsec), secrets detection, and least privilege IAM patterns.
- Ability to assess existing infrastructure code, identify security gaps, and drive adoption of secure coding standards across engineering teams.
- Compliance & Audit Support (Nice-to-Have)
- Familiarity with ISO 27001 requirements as they apply to cloud environments.
- Experience gathering and maintaining evidence for cloud-related control domains in support of audits and certifications.
Benefits
- Competitive compensation & meaningful ownership
- Generous salary
- Equity in the company
- Benefits that go beyond the basics to support your growth
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• New Logo Acquisition (Primary KPI): Identify, engage, and close net‑new enterprise and mid‑market customers in the UAE • Build and maintain a 3–5x qualified pipeline against quota • Own the full sales cycle from prospecting and discovery through negotiation and close • Map target accounts across key UAE sectors: Government & Semi-Government, BFSI, Oil & Gas / Energy, Large Enterprise & Conglomerates • Develop territory plan aligned to UAE buying cycles and budgets • Build CXO/CISO relationships and position cybersecurity as a business risk conversation • Run value-based selling vs product pitching • Navigate complex buying groups and procurement frameworks • Lead large deal cycles (typically $50K–$500K+ ACV) • Manage RFP/RFI processes common in UAE public and enterprise sectors • Ensure strong forecasting accuracy and pipeline hygiene • Apply the Sales Methodology (MEDDPICC) consistently during sales cycle • Partner closely with regional channel partners, distributors, and system integrators
Senior Staff Enterprise Cybersecurity Engineer – Security Architect
DexcomEmpowering people to take control of health
• Provide input into the Enterprise Security roadmap and help execute aligned initiatives • Lead engineering for DLP solutions (e.g., Netskope, Purview) by building and tuning advanced policies to reduce false positives and protect sensitive data across endpoints, SaaS, email, and cloud • Develop secure AI automation and contribute to practical guardrails for the safe use of AI services • Define and enforce practical standards for IAM, PAM, EPM, CASB, and ZTNA • Build and operate enterprise-wide security controls that balance protection with usability • Perform security and vendor assessments, and design reviews to identify risks and define secure reference architecture • Support privacy and compliance by coordinating PIAs/DPIAs, testing control effectiveness, gathering audit evidence, and driving remediation to closure • Collaborate across IT, engineering, and business teams, mentor peers, and lead blameless post-incident reviews that strengthen processes • Manage technical vendor relationships and run proof-of-concepts with clear success criteria
SAP Security Consultant – Contractor
YASH TechnologiesTransform your business, go #digital with #automation. #YASHTechnologies
• Hands-on experience in User Administration, Role Design, Role Maintenance • Strong experience in SAP Security administration • Good knowledge of SAP Authorization concepts • Experience with SUIM, PFCG, ST01, STAUTHTRACE • Experience in SAP GRC Access Control (added advantage) • Understanding of SoD, risk analysis, remediation • Ability to work independently in a remote environment • Experience supporting audits, compliance requirements • Strong communication skills and ability to coordinate with functional/technical teams
• Build an identity engine that powers the whole company and supercharges our security program • Create applications that enable and enforce our identity framework across the company • Develop integrations that unify identities across IdPs, cloud providers, SaaS tools, and internal systems • Automate identity lifecycle operations: provisioning, access reviews, offboarding • Collaborate with other IAM engineers and partner teams to define architecture and ship iteratively




