Senior Engineer - Cloud Engineering

Accelya Colombia SAS

Bogotá ciudad

Hybrid

COP 90,000,000 - 140,000,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Accelya Colombia SAS is seeking a Cloud Security Engineer to drive vulnerability analysis, remediation, and incident response across AWS environments. In a hybrid Bogotá setting, you will partner with engineering teams to remediate CSPM/CNAPP findings, improve detection workflows, and support secure software delivery.

The role requires hands-on AWS security experience, IaC remediation skills, and strong communication in English to collaborate with global teams.

Qualifications

  • 3+ years of hands-on cloud security experience, with deep AWS expertise.
  • Direct experience remediating CSPM/CNAPP findings (Upwind, Wiz, Prisma Cloud, Orca).
  • Experience analyzing and remediating code-level vulnerabilities (SAST, SCA).
  • Working knowledge of Terraform/CloudFormation and remediating misconfigurations in IaC.

Responsibilities

  • Analyze code for security vulnerabilities and drive remediation.
  • Triage and fix CSPM findings across AWS accounts, workloads, and services.

Skills

AWS security
CSPM remediation
SAST/SCA
IaC remediation
Python/Bash
Incident response
Log analysis
English fluency
Communication

Tools

AWS Security Hub
GuardDuty
Config
Inspector
Upwind
Wiz
Prisma Cloud
Orca

Job description

For more than 40 years, Accelya has been the industry's partner for change, simplifying airline financial and commercial processes and empowering the air transport community to take better control of the future. Whether partnering with IATA on industry-wide initiatives or enabling digital transformation to simplify airline processes, Accelya drives the airline industry forward and proudly puts control back in the hands of airlines so they can move further, faster.

Location: Bogota, Colombia (Hybrid Scheme: 2 days per week in the office)

Key Responsibilities
Vulnerability Analysis & Remediation
  • Analyze code for security vulnerabilities (SAST/SCA output, dependency issues, insecure configurations, IaC misconfigurations) and work with development teams to remediate.
  • Triage, prioritize, and drive remediation of Upwind CSPM findings across AWS accounts, workloads, and services.
  • Own remediation runbooks and track findings through to closure, including root-cause fixes rather than one-off patches.
  • Partner with engineering teams to remediate issues in Terraform/CloudFormation, container images, and application code.
Cloud Security Operations
  • Act as the go-to SME for AWS security tooling and findings (Security Hub, GuardDuty, Config, IAM Access Analyzer, Inspector, Upwind, and related CNAPP/CSPM tools).
  • Maintain and improve detection and remediation workflows, including automation where feasible (Lambda, EventBridge, SSM Automation).
  • Track posture metrics and report on remediation velocity, aging findings, and risk trends.
Incident Response & Investigations
  • Assist in cloud security incident investigations — log analysis (CloudTrail, VPC Flow Logs, GuardDuty findings), scoping impact, and supporting containment/remediation.
  • Contribute to post-incident reviews and help translate findings into preventive controls.
Architecture & Design Review
  • Participate in cloud security architecture reviews for new services and major changes, evaluating IAM design, network segmentation, encryption, and data protection.
  • Provide practical, risk-based recommendations that balance security with delivery timelines.
Required Qualifications
  • 3+ years of hands-on experience in cloud security, with deep, practical AWS experience (IAM, VPC, KMS, S3, CloudTrail, Security Hub, GuardDuty, Config, Inspector).
  • Direct experience remediating findings from a CSPM/CNAPP platform (Upwind, Wiz, Prisma Cloud, Orca, or similar) — not just reviewing dashboards, but fixing the underlying issues.
  • Experience analyzing and remediating application/code-level vulnerabilities (SAST, SCA, container image scanning).
  • Working knowledge of Infrastructure as Code (Terraform and/or CloudFormation) and the ability to remediate misconfigurations directly in code.
  • Scripting ability in Python and/or Bash for automation and investigation tasals.
  • Familiarity with incident response processes and cloud-native log sources.
  • Strong written and verbal communication skills — able to explain technical risk to both engineers and non-technical stakeholders.
  • Fluent English: Interviews will be held in this language.
Preferred Qualifications
  • Experience securing containerized workloads (EKS, ECR, Kubernetes security policies).
  • Exposure to CI/CD security integration (scanning gates, policy-as-code, pipeline hardening).
  • Familiarity with compliance frameworks relevant to the business (SOC 2, ISO 27001, PCI-DSS, GDPR) and especially, NIST 800-53 Baseline Controls.
  • AWS certifications (Security Specialty, Solutions Architect) or vendor CSPM certifications.
  • Prior experience in a dedicated cloud security or DevSecOps team.
What Success Looks Like in This Role
  • Upwind findings backlog is actively triaged, with clear ownership and shrinking mean-time-to-remediate.
  • Code-level vulnerabilities are caught and fixed before or shortly after deployment, not left open indefinitely.
  • Engineering teams see this role as a trusted partner for fixing issues, not just flagging them.
  • Incident investigations move faster because this person can navigate logs, findings, and architecture without hand-holding.
Nice To Haves
  • Experience with ethical hacking.
  • Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), GIAC Certified Incident Handler, (GCIH), Certified Information Systems Security Professional (CISSP).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Engineer - Cloud Engineering
Senior Engineer - Cloud Engineering

Accelya • Bogotá ciudad

Hybrid
COP 120,000,000 - 180,000,000
Senior Cloud Security Engineer: AWS Remediation & CSPM
Senior Cloud Security Engineer: AWS Remediation & CSPM

Accelya • Bogotá ciudad

Hybrid
COP 120,000,000 - 180,000,000
Senior Cloud Security Engineer (AWS & CSPM)
Senior Cloud Security Engineer (AWS & CSPM)

Accelya Colombia SAS • Bogotá ciudad

Hybrid
COP 90,000,000 - 140,000,000
Infrastructure Engineer
Infrastructure Engineer

Venaro • Bogotá ciudad

Remote
COP 258,925,000 - 388,387,000
8995 - Cybersecurity Cloud, Infrastructure and ITOps Senior, Lead Argentina, Colombia, Mexico, Paraguay, Bolivia, United Kingdom Published 7 days ago
8995 - Cybersecurity Cloud, Infrastructure and ITOps Senior, Lead Argentina, Colombia, Mexico, Paraguay, Bolivia, United Kingdom Published 7 days ago

Unosquare, Inc. • Colombia

Remote
COP 186,840,000 - 280,260,000
CloudOps Engineer - Remote (Colombia)
CloudOps Engineer - Remote (Colombia)

Connect Tech+Talent • Colombia

On-site
COP 90,000,000 - 140,000,000
Vulnerability Management Specialist CLOUD Manager
Vulnerability Management Specialist CLOUD Manager

Auxis • Bogotá ciudad

On-site
COP 12,000,000 - 18,000,000
Application Engineer
Application Engineer

Venaro • Bogotá ciudad

Remote
COP 97,097,000 - 178,011,000
Vulnerability Management Specialist INFRA Senior Associate
Vulnerability Management Specialist INFRA Senior Associate

Auxis • Bogotá ciudad

On-site
COP 277,675,000 - 370,233,000
Lead Engineer
Lead Engineer

Venaro • Bogotá ciudad

Remote
COP 120,000,000 - 210,000,000