Cloud Security Engineer

Avaloq

Philippines

On-site

PHP 900,000 - 1,500,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Avaloq is seeking a proactive Cloud Security Engineer to design, implement and operate security controls with a strong OCI focus. You will transform security requirements into automated, repeatable solutions emphasizing GitOps and IaC.

You will help harden cloud resources, automate certificate and key management, and enable secure-by-default configurations using Terraform and OCI services. Collaboration with developers and platform engineers is essential.

Qualifications

  • 3–6+ years in security engineering or related fields.
  • Experience deploying endpoint security agents at scale.
  • End-to-end certificate lifecycle management and TLS troubleshooting.
  • Strong OCI experience; AWS/Azure beneficial.
  • Knowledge of OCI Cloud Guard, Security Zones, Vault, WAF, Bastion, Identity Domains, NSGs.
  • GitOps with GitHub: branch protection, CI/CD pipelines.
  • Terraform configurations for OCI provider; remote state management.
  • Automation scripting in Python or Bash for security tasks.
  • Hands-on ability to implement security controls, not only advise.

Responsibilities

  • Data Security: Deploy and manage DLP policies across endpoints, cloud, and network.
  • Endpoint Security: Deploy and manage endpoint security agents at scale.
  • Network Security: Tune IDS/IPS, WAF policies, and rate-limiting rules.
  • Cryptography & Certificate Management: Automate certificate lifecycle across services; manage encryption.
  • Cloud Security & Secure-by-Default: Create Terraform modules and guardrails for OCI baselines.
  • GitOps Practices & Automation: Use GitHub as source of truth; write Terraform modules and CI/CD pipelines.
  • Automation scripting: Python/Bash for log parsing, bulk changes, compliance reporting.

Skills

Security engineering
SecOps
Infrastructure security
Automation mindset
Python scripting

Tools

OCI Terraform
Terraform
GitHub Actions
Python
Bash

Job description

Company Description

Founded and headquartered in Switzerland, Avaloq is continuously expanding its global footprint with around 2,500 colleagues in 12 countries, and more than 170 clients in 35 countries. We are an industry-leading provider of wealth management technology and services for financial institutions around the world, including private banks and wealth managers, investment managers, as well as retail and neo banks. Our research led approach and continual innovation is powered by the passion and creativity of our colleagues.

We are always looking for talented people to join us on our mission to orchestrate the financial ecosystem and democratize access to wealth management. Avaloq offers the opportunity to work closely with some of the world’s leading financial institutions as we jointly develop and shape careers. Championing a collaborative, supportive and flexible work environment empowers our colleagues to reach their full potential.

Job Description

We are looking for a proactiveCloud Security Engineer who possesses hands‑on experience in building, configuring, deploying, and operating security controls, with a special emphasis on Oracle Cloud Infrastructure (OCI). The ideal candidate is capable of transforming security requirements into automated, repeatable, and functional solutions, prioritising practical execution over theoretical expertise. There is a strong focus on GitOps methodologies, Infrastructure as Code, and secure‑by‑default engineering principles.

Key Responsibilities
  • Data Security: Deploy and manage DLP policies across endpoints, cloud, and network to prevent unauthorized data movement. Continuously refine DLP rules to reduce false positives.
  • Endpoint Security: Deploy and manage endpoint security agents at scale across servers, VMs, and containers. Operate host-based intrusion detection, and log collection with tuned alerting. Configure antivirus/antimalware schedules, exclusions. Build automated response playbooks.
  • Network Security: Tune IDS/IPS, WAF policies, and rate‑limiting rules. Conduct firewall rule audits to eliminate overly permissive access and enforce least privilege.
  • Cryptography & Certificate Management: Automate the full certificate lifecycle (generate, deploy, rotate, revoke) across all services. Configure encryption in transit and at rest using cloud‑native and third‑party KMS. Manage secrets management solutions with rotation, access policies, and CI/CD integration.
  • Cloud Security & Secure‑by‑Default Configuration (OCI Preferred): Create secure‑by‑default templates (Terraform modules, cloud policies, guardrails) so all new resources meet security baselines. Operationalise OCI‑native security services: Cloud Guard, Security Zones, Vulnerability Scanning, Bastion, WAF, and IAM compartment policies. Harden cloud resources (compute, storage, databases) and enforce tagging compliance. Remediate misconfigurations through code and automation, not just detection.
  • GitOps Practices & Automation: Use GitHub as the single source of truth for all security configurations and infrastructure changes (version‑controlled). Write and maintain Terraform modules (OCI provider) for security infrastructure provisioning. Enforce GitHub repository governance (branch protection, code owners, merge policies). Build CI/CD pipelines via GitHub Actions for terraform plan/apply, static analysis, policy‑as‑code enforcement, and automated security scans. Manage Terraform state securely (remote backends, state locking, encryption, RBAC). Script automation (Python/Bash) for log parsing, bulk changes, compliance reporting, and alert enrichment.
Qualifications
  • 3–6+ years’ experience in Security Engineering, SecOps, or Infrastructure Security, focusing on building and operating security controls.
  • Experience deploying and managing endpoint security agents at scale, tuning detection rules
  • Ability to manage certificate lifecycles from end to end, configure encryption services, set up secrets management, and troubleshoot certificate and TLS issues.
  • Hands‑on skill in securing cloud infrastructure, with strong preference for Oracle Cloud Infrastructure (OCI); experience with AWS and/or Azure is advantageous.
  • Ability to configure and operate OCI Cloud Guard, Security Zones, Vault, WAF, Bastion, Identity Domains, and NSGs.
  • Hands‑on experience with GitOps workflows using GitHub, including branch protections, code reviews, and CI/CD pipelines.
  • Competence in writing, maintaining, and troubleshooting Terraform configurations using the OCI Terraform Provider, managing remote state, and building reusable modules.
  • Experience in building and maintaining security pipelines with GitHub Actions or similar tools.
  • Ability to write functional automation scripts in Python and/or Bash for operational security needs.
  • Someone who builds solutions, not just advises on controls. You implement security measures, not just recommend them.
  • An automation‑first mindset: if you have performed a task manually more than once, you automate it with a script or Terraform module.
  • Comfortable working in the terminal, including SSH sessions, coding, log reading, and configuration debugging.
  • Iterative and pragmatic, able to deploy secure defaults rapidly and improve them over time rather than waiting for the ideal solution.
  • Collaborative and communicative, able to work alongside developers and platform engineers, explaining how to fix issues, not just reporting them.
  • Curious and self‑motivated, continuously learning, experimenting, and enhancing infrastructure security and automation.
Additional Information

We realize that managing work life balance is a challenge we all face in our daily lives and in order to support with this we are pleased to offer hybrid and flexible working for most of our Avaloqers to maintain work life balance and still continue our fantastic Avaloq culture in our global offices.

In Avaloq we are proud to embrace diversity and understand the success of our business is built on the power of different opinions, we are whole heartedly committed to fostering an equal opportunity environment and inclusive culture where you can be your true authentic self.

We hire, compensate and promote regardless of origin, age, gender identity, sexual orientation or any other fantastic traits that make us all unique, we have done our best to write this advert in an inclusive and neutral way.

Please be aware that we will not accept speculative CV submissions for any of our roles from recruitment agencies, and any unsolicited candidate submissions will be exempt from any payment expectations.

#LI-Hybrid

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

Avaloq • Makati

Hybrid
PHP 1,200,000 - 1,800,000
Hybrid work model
Flexible working
Inclusive culture
Cloud Security Engineer
Cloud Security Engineer

Avaloq • Metro Manila

Hybrid
PHP 900,000 - 1,500,000
Hybrid work arrangement
Flexible working hours
Inclusive culture
+1
Java Developer
Java Developer

Avaloq • Makati

Hybrid
PHP 1,808,000 - 2,713,000
System Engineer - Data Platform (APAC Region)
System Engineer - Data Platform (APAC Region)

Avaloq • Makati

Hybrid
PHP 1,200,000 - 2,400,000
Hybrid work model
Inclusive culture
System Engineer - Data Platform (APAC Region)
System Engineer - Data Platform (APAC Region)

Avaloq Group • Philippines

Hybrid
PHP 1,500,000 - 2,100,000
Hybrid work model
Flexible working hours
Endpoint Security Service Owner - Engineer
Endpoint Security Service Owner - Engineer

Avaloq Philippines Inc. • Makati

Hybrid
PHP 1,674,000 - 2,567,000
Hybrid work model
Observability Engineer
Observability Engineer

Avaloq • Metro Manila

Hybrid
PHP 1,200,000 - 2,400,000
Identity and Access Management Engineer
Identity and Access Management Engineer

Avaloq • Philippines

Hybrid
PHP 900,000 - 1,800,000
Hybrid work model
Flexible working arrangements
DevOps Engineer - Technology R&D Lab
DevOps Engineer - Technology R&D Lab

Avaloq Philippines Inc. • Makati

Hybrid
PHP 900,000 - 1,300,000
Hybrid work model
Flexible working hours
Software Engineer - Client Lifecycle Management (CLM)
Software Engineer - Client Lifecycle Management (CLM)

Avaloq Philippines Inc. • Makati

Hybrid
PHP 800,000 - 1,200,000
Hybrid work
Flexible working