Description
Tango is a successful, market leader, a live-streaming Platform with 450+ Million registered users, in an industry projected to reach $240 BILLION in the next couple of years.
The B2C platform, based on the best-quality global video technology, allows millions of talented people around the world to create their own live content, engage with their fans, and monetize their talents.
Tango live stream was founded in 2018 and is powered by 500+ global employees operating in a culture of growth, learning, and success!
The Tango team is a vigorous cocktail of hard workers, creative brains, energizers, geeks, overachievers, athletes, and more. We push the limits to bring our app from “one of the top” to “the leader”.
The best way to describe Tango's work style is not to use the word “impossible”. We believe that success is a thorny path that runs on sleepless nights, corporate parties, tough releases, and of course our users' smiles (and as we are a LIVE app, we truly get to see our users all around the world smiling right in front of us in real-time!).
Do you want to join the party?
Responsibilities
Tango is a global live-streaming platform serving a large international audience across a multi-cloud infrastructure. We are building out our security function, and cloud security is the centre of that investment.
We are looking for a Cloud Security Lead to own cloud security end to end — the strategy, the architecture, the tooling, and the engineering work to make it real. This is a domain-ownership role, not a ticket-queue role. You will set the direction for how we secure our cloud environments, and you will be hands-on in delivering it.
- Cloud Architecture & Standards: Design and own secure multi-cloud architecture, reference patterns, hardened baselines (CIS), and lead threat modeling.
- Infrastructure & Workload Protection: Manage CNAPP/CSPM (Wiz), runtime/container security (Kubernetes), vulnerability patching SLAs, and attack surface visibility.
- IaC & CI/CD Pipeline Security: Embed automated security guardrails, policy-as-code, IaC scanning, and secrets management into release workflows.
- Identity & Access Governance: Architect IAM, least-privilege models, just-in-time access, and eliminate standing privileges across environments.
- Detection, Response & Resilience: Build cloud logging pipelines into SIEM, create detections and playbooks, and support cloud incident response and ransomware recovery.
- Leadership & Team Growth: Serve as trusted security partner, mentor engineers, report metrics to executives, scale the cloud security team, and support compliance audits.
Requirements
- 5+ years in security engineering, with at least 3 years focused on cloud security in production environments
- Deep, practical expertise in at least one major cloud provider — Google Cloud is our primary environment
- Strong Kubernetes and container security experience: workload identity, admission control, network policy, image supply chain, runtime protection
- Hands-on Infrastructure-as-Code experience (Terraform or equivalent) and the ability to enforce policy through code rather than documents
- Real depth in cloud identity and access management: entitlement design, privilege escalation paths, cross-account and cross-project trust, federation with an IdP such as Okta
- Working proficiency in Python, Go, or a comparable language — you automate rather than accumulate manual process
- Demonstrated ability to build a capability from a low baseline: you have taken a cloud environment from unmanaged to well-governed and can walk through exactly how
- Experience running or materially contributing to cloud security incidents
- The credibility and communication skill to influence senior engineers without formal authority, and to present clearly to executives
- Fluent English
Nice to have
- Experience as the first or only dedicated cloud security engineer in an organisation
- Consumer-scale platform experience — high traffic, rapid release cadence, real cost pressure
- Detection engineering in cloud environments; familiarity with eBPF-based tooling
- Experience operating across heterogeneous cloud providers and consolidating them onto a common standard
- Experience mentoring or leading engineers, formally or informally
- Relevant certifications (Google Professional Cloud Security Engineer,CKS,CKA)
- Familiarity with SOC 2, ISO 27001, or PCI DSS control expectations
What we offer
- Stock options grant (we’re a Silicon Valley Company)
- Competitive salary
- Medical insurance for you and 75% off for your relatives
- On-site position with 4 days at the office and 1 day WFH
- Budget for lunch
- Parking
- Multisport card
- Cheerful team spirit and fun office atmosphere