Senior Security Engineer - Cloud Security

Nasuni

Poland

On-site

PLN 80,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nasuni is seeking a Senior Security Engineer to enhance cloud security across AWS, Azure, and GCP environments. This role involves leading security initiatives, managing vulnerabilities, and collaborating with security teams to establish robust security protocols.

The ideal candidate will possess 6-9 years of experience in security engineering, strong cloud security knowledge, and relevant certifications. This position offers flexible working arrangements and opportunities for professional growth.

Qualifications

  • 6-9 years of experience in security engineering or cloud security.
  • Demonstrated ownership of complex cloud security workstreams.
  • Experience securing cloud-native SaaS products.

Responsibilities

  • Lead initiatives to improve cloud security posture across AWS, Azure, and GCP.
  • Drive zero-trust initiatives and implement security controls.
  • Support incident responses and improve security workflows.

Skills

Cloud Security
Vulnerability Management
AWS Security
Container Security

Education

Bachelor's degree in Computer Science or related field
Certifications such as AWS Security Specialty or CISSP

Tools

Wiz
Terraform

Job description

About the Role

We are looking for a Senior Security Engineer with deep cloud security expertise to own complex security workstreams across our multi-cloud environment and drive our vulnerability management program to the next level of maturity. This is a senior individual contributor role for a security engineer who independently leads complex technical initiatives, influences security decisions across engineering teams, and serves as a trusted cloud security subject matter expert. The role combines deep technical execution with cross‑functional influence, while partnering with Security leadership and the Principal Security Architect on broader security strategy and architecture direction.

Success In This Role Looks Like
  • Improved cloud security posture across key cloud platforms
  • Increased vulnerability remediation effectiveness and SLA attainment
  • Expanded visibility and coverage of cloud security controls
  • Reduced recurring security findings through automation and systemic improvements
  • Increased adoption of secure‑by‑default cloud engineering practices
What You Will Do
Cloud Security Engineering and Posture Management
  • Lead initiatives that continuously improve Nasuni's cloud security posture across AWS, Azure, and GCP, including workload security, IAM hardening, network segmentation, encryption, and least‑privilege enforcement.
  • Lead cloud security assessments and configuration reviews, identifying and remediating misconfigurations and security gaps using Wiz and cloud‑native tools.
  • Drive zero‑trust initiatives and cloud‑native security controls across our multi‑cloud infrastructure.
  • Partner closely with the security leadership to translate architectural standards into enforceable, operational controls, and provide ground‑level feedback to shape those standards.
  • Evaluate and implement security controls for container and Kubernetes workloads, CI/CD pipelines, and Infrastructure as Code.
  • Contribute to cloud security architecture and design reviews by providing implementation guidance, operational security expertise, and risk assessments for new technologies and infrastructure changes.
Vulnerability Management Program Ownership
  • Lead execution and continuous improvement initiatives within Nasuni's vulnerability management program, partnering with Security leadership to influence strategy, tooling direction, prioritization frameworks, and program maturity across AWS, Azure, and GCP.
  • Assess and enforce vulnerability SLAs and risk‑based prioritization frameworks aligned to business risk appetite.
  • Analyze vulnerability data across environments, synthesize trends, and produce executive‑ready reporting on exposure, remediation velocity, and risk posture.
  • Drive systemic remediation through collaboration with DevOps, SRE, IT/infrastructure, and engineering teams, moving beyond ticket‑by‑ticket fixes toward structural improvements.
  • Continuously tune and optimize scanning coverage, detection fidelity, and platform configuration across all vulnerability management tooling.
  • Identify program gaps, define improvement roadmaps, and present recommendations to security leadership.
DevSecOps and Infrastructure Hardening
  • Partner with DevOps and SRE teams to embed security controls into CI/CD pipelines, IaC templates, and cloud provisioning workflows.
  • Drive adoption of security‑as‑code practices including policy‑as‑code, automated misconfiguration detection, and runtime security controls.
  • Define and enforce secure configuration baselines across cloud workloads, operating systems, and network infrastructure.
  • Assess and harden container and Kubernetes environments; support secrets management and workload identity practices.
Incident Response
  • Support the SecOps team by contributing to complex and high‑severity incident responses within your domain.
  • Advise the SecOps team on the development and improvement of incident response playbooks and runbooks for cloud and infrastructure‑related security events.
  • Conduct threat hunting in cloud environments and contribute to detection engineering efforts in collaboration with the SecOps team.
  • Participate in post‑incident reviews and systemic improvements that reduce recurrence of cloud security events or incidents.
Compliance and Governance
  • Partner with GRC to ensure the vulnerability management and cloud security controls align with compliance requirements.
  • Own technical evidence preparation and control documentation within your workstreams for audit and compliance activities.
  • Advise engineering and business teams on security considerations for new technologies, integrations, and infrastructure decisions.
Mentorship and Team Contribution
  • Mentor colleagues and peers, guiding technical decisions, sharing expertise, and improving the team's overall cloud security capabilities.
  • Lead security tooling evaluations and contribute to decisions on platform investments and program improvements.
  • Design, improve, and scale repeatable AI‑assisted security workflows that enhance vulnerability analysis, cloud security assessments, remediation prioritization, and operational efficiency while maintaining strong validation, security, and risk‑management practices.
What You Will Bring
Experience
  • 6‑9 years of experience in security engineering, cloud security, or a closely related discipline.
  • Demonstrated ownership of complex cloud security workstreams in a multi‑cloud or cloud‑native environment.
  • Proven experience leading or significantly contributing to a vulnerability management program, including tool operation, process design, and stakeholder engagement.
  • Experience securing cloud‑native SaaS products or operating within complex cloud‑first technology environments.
  • Experience designing or operationalizing repeatable AI‑assisted workflows that improve security engineering, vulnerability management, security analysis, automation, or operational efficiency.
Cloud Security Depth
  • Deep hands‑on expertise with AWS security, including IAM, VPC/networking, GuardDuty, Security Hub, CloudTrail, KMS, and AWS‑native hardening practices. Additional Azure and GCP experience a plus.
  • Strong working knowledge of CSPM tools; direct experience with Wiz is highly advantageous.
  • Experience with container security, Kubernetes security, and IaC security tooling (Terraform, CloudFormation, or equivalent).
  • Familiarity with CI/CD security integration and DevSecOps practices.
Technical Foundations
  • Strong understanding of network security, protocols, and infrastructure security fundamentals (TCP/IP, DNS, TLS, VPN, firewall design).
  • Working knowledge of IAM, Zero Trust principles, secrets management, and authentication protocols (OAuth 2.0, OIDC, SAML).
  • Experience with scripting or automation for security workflows (Python, Bash, or equivalent).
  • Demonstrated ability to validate AI‑generated outputs using security expertise, testing, data analysis, or other structured review mechanisms before applying recommendations in production environments.
Frameworks and Compliance
  • Familiarity with NIST CSF, CIS Benchmarks, and OWASP frameworks.
  • Strong command of vulnerability severity frameworks (CVSS, EPSS) and risk‑based prioritization methodologies.
  • Experience conducting technical risk assessments and security design reviews.
Communication and Influence
  • Ability to explain complex security risks and trade‑offs clearly to both engineering and IT/infrastructure peers and non‑technical leadership.
  • Strong written communication skills for producing vulnerability reports, security assessments, and architectural recommendations.
  • Collaborative working style, you influence through expertise and build trust across teams.
Education and Certifications
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related field; or equivalent practical experience.
  • Certifications preferred: AWS Security Specialty, CISSP, CCSP, GIAC GCSA, or equivalent cloud security credentials.

Nasuni is an equal opportunity employer. The equal employment opportunity policy at Nasuni protects employees and job applicants from discrimination on the bases of race, religion, color, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, family medical history or genetic information, political affiliation, military service, or other non‑merit based factors. These protections extend to all management practices and decisions, including recruitment and hiring practices, appraisal systems, promotions, and training and career development programs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer — Vulnerability & Zero-Trust Leader
Senior Cloud Security Engineer — Vulnerability & Zero-Trust Leader

Nasuni • Poland

Hybrid
PLN 80,000 - 100,000
security engineer
security engineer

Enfint • Warszawa

On-site
PLN 260,000 - 350,000
Relocation assistance
Security Solutions Architect - Pre-Sales
Security Solutions Architect - Pre-Sales

The Redesign Group • Poland

On-site
PLN 324,000 - 433,000
Medical Insurance
401(k) plan with employer match
Flexible time off
+1
Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM • Poland

On-site
PLN 85,000 - 110,000
AI Security Architect
AI Security Architect

Sapiens • Poland

On-site
PLN 180,000 - 240,000
Network Security Engineer
Network Security Engineer

Uvation • Poland

On-site
PLN 100,000 - 120,000
Software Engineer and Security Researcher
Software Engineer and Security Researcher

Commit • Warszawa

Hybrid
PLN 190,000 - 270,000
Senior Staff Software Engineer - Netwrix Privilege Secure Discovery
Senior Staff Software Engineer - Netwrix Privilege Secure Discovery

Netwrix Corporation • Kraków

On-site
Competitive Health Benefits
Continuous Learning and Development Opportunities
Team-Oriented, Collaborative Work Environment
+1
Cyber Security Engineer
Cyber Security Engineer

Interact Software • Poland

On-site
PLN 120,000 - 180,000
CyberSecurity Specialist
CyberSecurity Specialist

SEIDOR • Warszawa

On-site
PLN 180,000 - 240,000