Job Closed

This listing is no longer active.

Addi logo
Addi

Somos una empresa de tecnología que busca impulsar y habilitar el comercio digital en Latinoamérica.

Cloud Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 201-500H1B No SponsorCompany SiteLinkedIn

Location

Colombia

Posted

73 days ago

Salary

0

Seniority

Senior

Bachelor DegreeEnglishAWSCloudCyber SecurityTerraform

Job Description

Cloud Security Engineer

Addi

• Own and drive cloud security across Addi's AWS infrastructure, laying the technical foundation for a mature, scalable cloud security program. • Conduct a comprehensive cloud security assessment across all AWS accounts within the first 60 days, producing a prioritized findings inventory and a remediation roadmap, ensuring 100% of critical and high-severity findings are remediated in the SLA. • Design, configure, and operationalize CrowdStrike CNAPP from the ground up, achieving full AWS environment coverage and enabling continuous posture monitoring, misconfiguration detection, and threat detection across cloud workloads. • Assess the current Terraform codebase and define secure IaC standards and best practices, including policy-as-code controls, secrets management, and least privilege enforcement, with ≥80% of new infrastructure deployments following the defined standards. • Own and maintain the cloud security controls required to sustain ISO 27001 certification, ensuring zero critical gaps in cloud-related control domains and delivering the necessary evidence and documentation for ongoing audits. • Establish continuous cloud security monitoring and alerting within CrowdStrike NG-SIEM, ensuring all critical cloud events are correlated and actionable, with defined SLAs for response to cloud-originated alerts.

Job Requirements

  • Deep AWS Security Expertise (Must-Have)
  • Hands-on experience securing AWS environments, including IAM, VPC, S3, CloudTrail, GuardDuty, Security Hub, and KMS.
  • Strong understanding of the AWS shared responsibility model, attack surface management, and cloud-native threat vectors.
  • Proven ability to assess and harden AWS environments against CIS Benchmarks, AWS Well-Architected Security Pillar, and ISO 27001 controls.
  • CNAPP / CSPM Operational Experience (Must-Have)
  • Experience operating CNAPP or CSPM platforms (CrowdStrike Falcon Cloud Security, Wiz, Prisma Cloud, or equivalent) in production environments.
  • Ability to configure detection rules, suppress false positives, and translate posture findings into actionable remediation tasks for engineering teams.
  • Comfortable building cloud security dashboards and reporting for technical and non-technical audiences.
  • Cloud Vulnerability & Risk Management (Must-Have)
  • Experience managing cloud security findings end to end, from identification and prioritization through remediation tracking and closure.
  • Ability to assess risk based on exploitability, exposure, and business impact rather than CVSS score alone.
  • Track record of driving cross-functional remediation with engineering and platform teams.
  • Collaboration & Communication (Must-Have)
  • Comfortable working as an individual contributor embedded in a cybersecurity team, partnering closely with platform and engineering teams.
  • Able to translate complex cloud security risks into clear, prioritized recommendations for both technical and business stakeholders.
  • Terraform & Secure IaC (Nice to Have)
  • Hands-on experience writing and reviewing Infrastructure as Code in production AWS environments.
  • Experience implementing security controls within IaC pipelines, including static analysis tools (e.g., Checkov, tfsec), secrets detection, and least privilege IAM patterns.
  • Ability to assess existing infrastructure code, identify security gaps, and drive adoption of secure coding standards across engineering teams.
  • Compliance & Audit Support (Nice-to-Have)
  • Familiarity with ISO 27001 requirements as they apply to cloud environments.
  • Experience gathering and maintaining evidence for cloud-related control domains in support of audits and certifications.

Benefits

  • Competitive compensation & meaningful ownership
  • Generous salary
  • Equity in the company
  • Benefits that go beyond the basics to support your growth

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 1,001-5,000Since 1985H1B Sponsor

• New Logo Acquisition (Primary KPI): Identify, engage, and close net‑new enterprise and mid‑market customers in the UAE • Build and maintain a 3–5x qualified pipeline against quota • Own the full sales cycle from prospecting and discovery through negotiation and close • Map target accounts across key UAE sectors: Government & Semi-Government, BFSI, Oil & Gas / Energy, Large Enterprise & Conglomerates • Develop territory plan aligned to UAE buying cycles and budgets • Build CXO/CISO relationships and position cybersecurity as a business risk conversation • Run value-based selling vs product pitching • Navigate complex buying groups and procurement frameworks • Lead large deal cycles (typically $50K–$500K+ ACV) • Manage RFP/RFI processes common in UAE public and enterprise sectors • Ensure strong forecasting accuracy and pipeline hygiene • Apply the Sales Methodology (MEDDPICC) consistently during sales cycle • Partner closely with regional channel partners, distributors, and system integrators

United Arab Emirates
Job Closed
Full TimeRemoteTeam 10,001+Since 1999H1B Sponsor

• Provide input into the Enterprise Security roadmap and help execute aligned initiatives • Lead engineering for DLP solutions (e.g., Netskope, Purview) by building and tuning advanced policies to reduce false positives and protect sensitive data across endpoints, SaaS, email, and cloud • Develop secure AI automation and contribute to practical guardrails for the safe use of AI services • Define and enforce practical standards for IAM, PAM, EPM, CASB, and ZTNA • Build and operate enterprise-wide security controls that balance protection with usability • Perform security and vendor assessments, and design reviews to identify risks and define secure reference architecture • Support privacy and compliance by coordinating PIAs/DPIAs, testing control effectiveness, gathering audit evidence, and driving remediation to closure • Collaborate across IT, engineering, and business teams, mentor peers, and lead blameless post-incident reviews that strengthen processes • Manage technical vendor relationships and run proof-of-concepts with clear success criteria

Philippines
YASH Technologies logo

SAP Security Consultant – Contractor

YASH Technologies

Transform your business, go #digital with #automation. #YASHTechnologies

ContractRemoteTeam 5,001-10,000Since 1996H1B Sponsor

• Hands-on experience in User Administration, Role Design, Role Maintenance • Strong experience in SAP Security administration • Good knowledge of SAP Authorization concepts • Experience with SUIM, PFCG, ST01, STAUTHTRACE • Experience in SAP GRC Access Control (added advantage) • Understanding of SoD, risk analysis, remediation • Ability to work independently in a remote environment • Experience supporting audits, compliance requirements • Strong communication skills and ability to coordinate with functional/technical teams

India
Job Closed
Full TimeRemoteTeam 501-1,000Since 2017H1B No Sponsor

• Build an identity engine that powers the whole company and supercharges our security program • Create applications that enable and enforce our identity framework across the company • Develop integrations that unify identities across IdPs, cloud providers, SaaS tools, and internal systems • Automate identity lifecycle operations: provisioning, access reviews, offboarding • Collaborate with other IAM engineers and partner teams to define architecture and ship iteratively

California
$147K - $253K / year