Cyber Security Staff Engineer - AWS Cloud

Solaris

Sweden

Hybrid

SEK 993,158 - 1,324,210

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Home office budget
Learning budget €1000/year
Competitive salary and bonus program
Meal allowance
Deutschland ticket subsidy
28 vacation days (+2 after 2 years, +3
Work abroad up to 12 weeks/year

Job summary

Solaris is seeking an experienced Cloud Security Engineer to audit and refactor AWS resources into secure Terraform code, while designing and maintaining robust WAF policies to protect applications and APIs. You will enforce guardrails, guide least-privilege IAM practices, and lead security automation across a multi-account AWS setup, aligning with NIST, CIS, and BaFin requirements.

Ideal candidates bring 5+ years in cloud security, strong Terraform skills, and excellent collaboration with

Qualifications

  • Degree in Computer Science, Cloud Computing, Cyber Security, Information Technology, or equivalent professional experience.
  • 5+ years of dedicated professional experience in Cloud Security Engineering with a track record securing complex AWS environments.
  • Deep hands-on experience with AWS WAF, Shield, and CloudFront for public-facing endpoints.
  • Strong Terraform and IaC skills, including auditing templates for security drifts.
  • Mastery of AWS native security tools (IAM, KMS, Security Hub, GuardDuty) and multi-account security architectures.
  • Experience collaborating with established Cloud Architecture or DevOps teams as a security consultant.

Responsibilities

  • Audit current AWS environment with Cloud Architecture and Engineering teams, identify security debt, and plan refactoring into secure Terraform code.
  • Design, deploy, tune, and maintain AWS WAF policies and rulesets to protect applications and APIs from OWASP Top 10 attacks, bots, and zero-days.
  • Establish cloud security guardrails, multi-account structures, and SCPs in partnership with the infrastructure team.
  • Guide IAM strategies toward least privilege and audit legacy roles for security improvements.
  • Manage and optimize cloud-native security monitoring tools (Security Hub, GuardDuty, CloudTrail, Inspector, KMS).
  • Lead incident response for AWS security alerts, perform cloud forensics, and coordinate containment strategies.
  • Ensure compliance with financial regulations, internal policies, and security frameworks (NIST, CIS, BaFin).
  • Lead security automations in the AWS environment.
  • Understand AWS native AI capabilities (Bedrock or Quick).

Job description

Solaris is Europe's leading embedded finance platform. Solaris’ full German banking license and proprietary modular B2B tech stack empowers its partners – from SMEs to large, multinational, non-financial companies – to offer compliant, customer-centric banking services, providing seamless experiences to customers across all industries. Founded in 2016, Solaris pioneered the Banking-as-a-Service market with an unparalleled combination of tech and banking. Solaris is headquartered in Berlin and employs 300 people in Europe.

Your Role
  • Partner closely with the existing Cloud Architecture and Engineering teams to audit the current AWS environment, identify security technical debt, and plan the refactoring of legacy resources into secure Terraform code.
  • Design, deploy, tune, and maintain AWS WAF (Web Application Firewall) policies and rulesets to proactively protect corporate applications and APIs against application-layer attacks (OWASP Top 10, bots, and zero-day exploits).
  • Establish and enforce cloud security guardrails, multi-account structures (AWS Organizations/Control Tower), and Service Control Policies (SCPs) in collaboration with the infrastructure team.
  • Help on define and audit AWS Identity and Access Management (IAM) strategies, guiding engineering teams to transition from over-privileged legacy roles toward the principle of least privilege.
  • Manage and optimize cloud-native security monitoring and detection tools (AWS Security Hub, GuardDuty, CloudTrail, Inspector, or KMS).
  • Help on the incident respond for AWS-specific security alerts, performing cloud forensic analysis and coordinating containment strategies.
  • Ensure the AWS cloud ecosystem remains fully compliant with relevant financial regulations, internal policies, and security frameworks (NIST, CIS, BaFin requirements).
  • Lead the security automatizations on the AWS environment.
  • Understanding of AWS native AI capabilities (e.g., Bedrock or Quick).
We'd love to see
  • A degree in Computer Science, Cloud Computing, Cyber Security, Information Technology, or equivalent professional experience.
  • You have spent 5+ years of dedicated professional experience in Cloud Security Engineering, with a proven track record of securing complex AWS environments.
  • AWS WAF & Edge Security: Deep hands‑on experience designing, implementing, and fine‑tuning AWS WAF, AWS Shield, and CloudFront to protect public‑facing application endpoints.
  • Advanced Terraform & IaC: Strong proficiency in Terraform and auditing IaC templates for security drifts.
  • AWS Security Governance: Mastery of AWS native security tools (IAM, KMS, Security Hub, GuardDuty) and multi‑account security architecture.
  • Collaboration with Engineering: Experience working alongside separate, established Cloud Architecture or DevOps teams, acting as a security consultant rather than a solo administrator.
  • Understands agile workflows and lean principles.
  • Technical leadership, cross‑team collaboration, and cloud governance focus.
  • Business proficient written and spoken English.
  • Highly valued certification: AWS Certified Security - Specialty. AWS Certified Solutions Architect (Associate/Professional) is a strong plus.
  • Exceptional diplomatic and communication skills to align security requirements with the objectives of the existing Architecture and Engineering teams.
  • Thinking: Structured and analytical approach to untangling legacy cloud setups and defining clear, secure milestones.
  • Empathic team player who avoids the "silo" mentality and focuses on enabling other teams to build securely.
  • Proactive peer that helps the growth of the team.
  • Curious, constant learner that is willing to share learning with others.
Benefits
  • Home office budget.
  • Learning & development budget of €1000 per year and a transparent growth framework to support your career goals.
  • Competitive salary and a variable remuneration program.
  • Monthly meal allowance.
  • Deutschland ticket subsidy.
  • 28 vacation days, increasing by 2 days after 2 years and 3 days after 3 years with Solaris.
  • Opportunity to work abroad for up to 12 weeks per year.

While job ads usually paint an ideal picture of a candidate, studies show that most applicants meet an average of 60% of the criteria. Unfortunately, many promising candidates tend to apply only if they meet all the criteria. So if you think you have what it takes, but don't necessarily meet every single item in the job description, please contact us anyway. We'd love to talk with you and find out if you might be a good fit for us.

At Solaris, we are committed to nurturing an inclusive environment, where all Solarians feel valued, respected and ...

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Staff Engineer - Application Security
Cyber Security Staff Engineer - Application Security

Solaris • Sweden

On-site
SEK 1,324,000 - 1,987,000
Home office budget
Learning & development budget €1000/yr
Competitive salary & variable remunera
+3
Principal Engineer
Principal Engineer

Solaris • Sweden

On-site
SEK 1,200,000 - 1,800,000
Home office budget
Learning & development budget of €1000
Competitive salary and variable bonus
+4
Cyber Security Engineer (Vulnerability Management & SecOperations)
Cyber Security Engineer (Vulnerability Management & SecOperations)

Solaris • Sweden

On-site
SEK 662,000 - 883,000
Home office budget
Learning & development budget €1000/yr
Competitive salary with variable pay
+3
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Solaris • Sweden

On-site
SEK 827,000 - 1,049,000
Home office budget
Learning & development budget of €1000
Competitive salary and a variableremun
Senior Software Engineer (f/m/d)
Senior Software Engineer (f/m/d)

Solaris • Sweden

On-site
SEK 849,000 - 961,000
Home office budget
Learning budget €1000 per year
Competitive salary & bonus
+4
Senior Data Protection Manager
Senior Data Protection Manager

Solaris • Stockholms kommun

On-site
SEK 800,000 - 1,200,000
Home office budget
Learning & development budget of €1000
Competitive salary and variable bonus
+4
Senior AI Engineer (f/m/d)
Senior AI Engineer (f/m/d)

Solaris • Sweden

On-site
SEK 882,000 - 1,104,000
Home office budget
Meal allowance
Deutschland ticket
+2
Credit Risk Manager (f/m/d)
Credit Risk Manager (f/m/d)

Solaris • Stockholms kommun

On-site
SEK 772,000 - 1,104,000
Competitive salary
Home office budget
Learning budget
+4
Product Owner - Cards Transactions
Product Owner - Cards Transactions

Solaris • Sweden

Hybrid
SEK 827,000 - 994,000
Home office budget
Learning & development budget €1000/yr
Competitive salary
+4
Sr. Specialist Solutions Architect - Security, Europe North, AWS WWSO EMEA
Sr. Specialist Solutions Architect - Security, Europe North, AWS WWSO EMEA

Amazon Web Services (AWS) • Stockholms kommun

On-site
SEK 1,200,000 - 1,500,000