Senior Cloud Platform Engineer

Cloud Protection by WithSecure

Helsinki

Hybrid

EUR 90,000 - 130,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible work arrangements
Work abroad up to 30 days per year
Paid sick leave from day one
Mental health support
Continuous learning

Job summary

Cloud Protection by WithSecure in Helsinki seeks a Senior Cloud Platform Engineer to own the AWS foundation for CPSF. You will design and implement the multi-account landing zone, build IaC in Terraform, and ensure secure production readiness across regions.

The role spans networking, IAM, encryption, observability, and CI/CD with a focus on compliance and risk-aware decision making. Hybrid work in Helsinki, fluent English, and hands-on experience with migration of live workloads are key.

Qualifications

  • Substantial hands-on experience building and running production AWS at multi-account, multi-region scale.
  • Deep Terraform experience, incl. state, imports, module design, and review workflow.
  • Breadth across networking, IAM, encryption and key management, logging and audit, CI/CD, and cost.

Responsibilities

  • Design, build, and operate the AWS landing zone with multi-account setup and guardrails.
  • Own IaC estate in Terraform including modules and environment layers.
  • Build and maintain network: multi-region VPCs, centralized egress, DNS, private connectivity.
  • Own data protection and identity: encryption, key management, SSO federation, least privilege.
  • Own the observability plane: logging, configuration recording, security findings, dashboards, alerts.
  • Own delivery: OIDC deployment from CI, registries, policy checks on changes.
  • Plan and migrate live workloads into the new environment with rehearsals and cutover.
  • Build a controls baseline mapped to SOC 2/ISO 27001 and ensure query-based reporting.
  • Flag irreversible decisions early and take end-to-end ownership.

Skills

AWS architecture
Terraform
Networking
IAM & encryption
Logging & audit
CI/CD
Cost management
Migration experience
Decision ownership
Documentation literacy

Tools

Terraform
AWS
CloudFormation
AWS Control Tower

Job description

Cloud Protection protects Fortune 500 enterprises and government organizations worldwide from malware, phishing, and identity-based attacks in Salesforce. Our work builds on more than 30 years of experience in analyzing malware and defending against advanced threats - expertise few security companies can match.

It's our people who make that possible. Newly independent after years as WithSecure's most autonomous business unit, we combine the focus and speed of a startup with decades of cybersecurity depth. We're a diverse team that values passion, purpose, and genuine wellbeing at work, and we're looking for people who want to set the standard for Salesforce security with us. If that sounds like you, we'd love to hear from you.

We're looking for a Senior Cloud Platform Engineer to help build and own the AWS foundation for Cloud Protection for Salesforce (CPSF) - a fast-growing cybersecurity SaaS product by WithSecure™.

CPSF is a real-time threat protection solution that scans files, URLs, and QR codes across Salesforce workflows - including Sales Cloud, Service Cloud, Experience Cloud, and Agentforce. It's already trusted by Fortune 500 companies globally, and we're scaling fast. We're building a new, independent AWS environment from the ground up, and you'll own entire layers of that foundation end to end - designing it, building it in Terraform, proving it works, and standing behind it in production.

This is a small, hands-on team, so the scope is broad: the judgment you bring to decisions that can't be undone later matters as much as the code you write.

Key Responsibilities
  • Design, build, and operate our AWS landing zone - multi-account organization, guardrails, and account vending - so every new account is governed from the moment it exists.
  • Own our infrastructure-as-code estate in Terraform, including the module library, layered environments, and the review gates on the changes that carry real risk.
  • Build and own the network: multi-region VPCs, centralized egress, DNS, and private connectivity to external services.
  • Own data protection and identity: encryption and key management, SSO federation, least-privilege access, and break-glass paths that are actually rehearsed.
  • Own the evidence and observability plane: audit logging, configuration recording, security findings, dashboards, and alerting from the first day of every account's life.
  • Own delivery: OIDC-based deployment from CI, artifact and container registries, and policy and security checks that run on every change.
  • Plan and execute the migration of live production workloads into the new environment - staged rehearsals, cutover, soak period, and decommissioning what's left behind.
  • Build and maintain a controls baseline as code mapped to the frameworks we report against (SOC 2, ISO 27001), and keep the environment answerable by query rather than screenshots.
  • Spot the decisions that can't be undone later, flag them early, and take end-to-end ownership of the ones that affect the whole organization.
What are we looking for?
  • Substantial hands-on experience building and running production AWS at multi-account, multi-region scale - not just consuming it.
  • Deep Terraform experience, including the unglamorous parts: state, imports, adopting resources you didn't create, module design, and the review workflow around them.
  • Real breadth across networking, IAM, encryption and key management, logging and audit, backup and recovery, CI/CD, and cost.
  • Experience with at least one migration, re-platforming, or carve-out that touched live production - including the parts that went wrong.
  • A track record of owning an irreversible infrastructure decision, and being able to talk through how you approached it.
  • Comfortable working where the documentation is imperfect and the right answer has to be established, not just looked up.
  • Based in Finland (Uusimaa area) - this is a hybrid role with regular time in our Helsinki office.
  • Fluent English - written and verbal.

Nice to have: compliance-driven infrastructure work (SOC 2, ISO 27001, or similar), AWS Control Tower and account-vending automation, and CloudFormation experience.

If you don’t tick every box above, don’t worry - we're more interested in your potential and willingness to learn.

The salary displayed on this page represents a starting point for the role. Final compensation is discussed individually and depends on experience, skills, and the local market.

What will you get from us
  • Meaningful work with real-world impact - your work helps protect businesses and critical infrastructure from modern cyber threats.
  • Flexible ways of working, including up to 30 days per year working abroad and paid sick leave from day one.
  • A strong focus on well-being, with mental health support and comprehensive benefits.
  • Continuous learning, modern tools, and a people-first culture that values trust and collaboration.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Account Executive
Account Executive

Cloud Protection by WithSecure • Helsinki

Hybrid
EUR 70,000 - 120,000
Flexible work options
Travel abroad up to 30 days/yr
Senior Cloud Platform Engineer AWS & Terraform Expert
Senior Cloud Platform Engineer AWS & Terraform Expert

Cloud Protection by WithSecure • Helsinki

Hybrid
EUR 90,000 - 130,000
Flexible work arrangements
Work abroad up to 30 days per year
Paid sick leave from day one
+2
Security Engineer, SecOps
Security Engineer, SecOps

Hoxhunt • Finland

Hybrid
EUR 4,000 - 6,000
Extensive healthcare
Office gym and swimming pool
Flexible working hours
Senior Software Engineer, Backend/Full-Stack
Senior Software Engineer, Backend/Full-Stack

F-Secure • Helsinki

Hybrid
EUR 61,000 - 73,000
Hybrid work
Remote options
ESSP
+2
Staff Security Engineer
Staff Security Engineer

Supermetrics • Helsinki

On-site
EUR 90,000 - 130,000
Equity
Home office allowance
Annual personal learning budget
+1
Head of Security for a Sustainability SaaS
Head of Security for a Sustainability SaaS

One Click LCA Ltd • Helsinki

Hybrid
EUR 140,000 - 180,000
Remote working supported
Domain Lead, AI & Delivery Platform
Domain Lead, AI & Delivery Platform

WithSecure • Helsinki

Hybrid
EUR 85,000 - 110,000
Flexible work arrangements
Up to 30 days working abroad
Paid sick leave from day one
+2
Cloud Security Architect
Cloud Security Architect

Wärtsilä • Helsinki

On-site
EUR 90,000 - 120,000
Security Engineer
Security Engineer

Hoxhunt • Helsinki

Hybrid
EUR 50,000 - 67,000
Healthcare benefits
Helsinki office
Gym access
+1
Senior AI Developer
Senior AI Developer

WithSecure • Helsinki

Hybrid
EUR 70,000 - 90,000
Flexible working arrangements
Up to 30 days working abroad
Mental health support
+1