Cloud Security Engineer (NXJ-208)

Newxel

Warszawa

On-site

PLN 240,000 - 360,000

Full time

12 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Newxel seeks a dedicated Security Engineer to own cloud security across Azure, AWS, and GCP, embedding policy-as-code guardrails into CI/CD pipelines and automation.

You will collaborate with DevOps, MLOps, and engineering teams to maintain rapid delivery while enforcing strong security baselines and incident response readiness across AI infrastructure.

Qualifications

  • 4+ years in Cloud Security or Security Engineering.
  • Deep expertise in Azure security architecture and cloud-native controls.
  • Strong Kubernetes security know‑how including RBAC and network policies.
  • Experience integrating security controls (SAST/DAST/SCA/secret scanning) into CI/CD pipelines.

Responsibilities

  • Architect and enforce the unified multi-cloud security strategy across Azure, AWS, and GCP, covering IAM, network security, and secrets management.
  • Embed automated guardrails in Terraform and CI/CD pipelines using policy-as-code (OPA, Sentinel, Azure Policy).
  • Own Kubernetes (AKS) security with RBAC, network policies, pod security standards, and admission controls.
  • Drive end-to-end vulnerability and posture management through CNAPP and manage findings to closure with SLAs.
  • Integrate SAST, DAST, SCA, and secret scanning into CI/CD workflows with engineering teams.
  • Lead cloud security incident response procedures and implement preventive measures.
  • Collaborate with DevOps, MLOps, and FinOps to embed security baselines in development workflows without slowing delivery.
  • Manage customer security assessments and technical questionnaires with Sales and Legal.

Skills

Cloud security
Kubernetes security
Terraform
CI/CD policy-as-code
Communication
AI security

Tools

Azure
AWS
GCP
OPA
Sentinel
Azure Policy

Job description

The Role

As the sole security engineer across the entire company, you will take full ownership of the end-to-end cloud security architecture and strategy. The core challenge is not gatekeeping, but designing policy-as-code guardrails and proactive security baselines that embed natively into automated pipelines. You will work directly with DevOps, MLOps, and engineering teams to maintain high software delivery velocity while securing scalable cloud and AI infrastructure.

About the Product

The platform transforms live sports broadcasts into personalized, publication-ready highlight packages while games are actively in progress. Operating at continuous scale, it automatically ingests, analyzes, and tags video streams to identify key moments. The system processes massive data volumes with zero tolerance for latency, directly powering downstream consumer-facing media products.

Technology Stack: The core cloud infrastructure relies on Azure (with AWS/GCP workloads), provisioned through Terraform and automated CI/CD pipelines. Workloads run on Kubernetes (AKS) with policy enforcement via OPA, Sentinel, and Azure Policy. Vulnerability management and runtime monitoring are driven through a CNAPP platform, while Python is utilized for automation and custom security integrations.

What You’ll Be Doing
  • Architect and enforce the unified multi-cloud security strategy across Azure, AWS, and GCP covering IAM, network security, and secrets management
  • Embed automated guardrails in Terraform and CI/CD pipelines using policy-as-code (OPA, Sentinel, Azure Policy) to block misconfigurations before deployment
  • Own Kubernetes (AKS) cluster security, establishing RBAC, network policies, pod security standards, and admission control controls
  • Drive end-to-end vulnerability and posture management through the CNAPP platform, managing findings to closure under strict SLAs
  • Integrate automated SAST, DAST, SCA, and secret scanning into CI/CD workflows, partnering with engineering teams on remediation
  • Lead cloud security incident response procedures, conducting post-mortems and implementing preventive preventive measures
  • Collaborate with DevOps, MLOps, and FinOps teams to embed security baselines directly into development workflows without impacting delivery velocity
  • Manage customer security assessments and technical questionnaires in coordination with Sales and Legal stakeholders
What We Expect
Must-have
  • 4+ years of hands-on experience in Cloud Security or Security Engineering within multi-cloud environments Deep expertise in Azure security architecture and cloud-native controls
  • Strong practical knowledge of Kubernetes security, including RBAC, network policies, admission controllers, and image scanning
  • Hands-on proficiency with Terraform and Infrastructure as Code using policy-as-code principles Proven background integrating security controls (SAST/DAST/SCA/secret scanning) into CI/CD pipelines alongside DevOps teams
  • Clear communication skills with experience partnering directly with engineering and management stakeholders
  • Familiarity with security requirements for LLM and AI infrastructure
Nice-to-have
  • Proficiency in Python for developing custom security tooling and automation
  • Working experience with SOC2 compliance frameworks and audit readiness
  • Prior experience serving as a security lead or hands-on technical lead
  • Exposure to modern container security practices including image signing, SBOMs, and runtime protection
Why This Role Is Worth Your Time
  • You have complete autonomy and ownership as the single security authority shaping the security roadmap for a fast-growing AI platform
  • You are building practical, developer-friendly guardrails rather than acting as a traditional gatekeeper, directly embedding security into high-velocity engineering workflows
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud and Automation Security Engineer
Cloud and Automation Security Engineer

Euroclear • Polska

Hybrid
PLN 180,000 - 280,000
Software Engineer and Security Researcher
Software Engineer and Security Researcher

Commit • Warszawa

On-site
PLN 190,000 - 270,000
Product Security Engineer
Product Security Engineer

StackAI • Poland

On-site
PLN 235,848 - 321,612
Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM • Poland

On-site
PLN 85,000 - 110,000
Cloud Security Engineer
Cloud Security Engineer

YGO GmbH • Polska

Hybrid
PLN 180,000 - 320,000
Security & Compliance Engineer
Security & Compliance Engineer

Nomagic • Warszawa

On-site
PLN 180,000 - 260,000
Equity
Relocation package
Hybrid work in Warsaw
CloudSec Client #1 | Backend Team Lead
CloudSec Client #1 | Backend Team Lead

SD Solutions • Warszawa

On-site
PLN 180,000 - 250,000
Senior Security Engineer - Cloud Security
Senior Security Engineer - Cloud Security

Nasuni • Poland

On-site
PLN 80,000 - 100,000
IT & Security Engineer
IT & Security Engineer

Nomagic, Inc. • Warszawa

Hybrid
PLN 180,000 - 240,000
Equity for every employee
Relocation package
Hybrid work from Warsaw
Lead Security Operations Engineer
Lead Security Operations Engineer

Gainsight • Wrocław

On-site
PLN 180,000 - 240,000