09 ago
|
Cint
|
Barcelona
Cint is a pioneer in research technology (Res Tech), offering a programmatic marketplace that connects customers with real people to build business strategies, publish research, and measure digital advertising impact. With nearly 300 million respondents in more than 150 countries, Cint’s platform is built on AWS and will gradually expand into GCP.Job DescriptionSenior Cloud Infrastructure Security EngineerOur Vision for the RoleWe are searching for an experienced engineer with a passion for automation and Dev Sec Ops. You will work with a team to secure and scale Cint’s cloud infrastructure across AWS, GCP, and associated services, influencing engineers and managers throughout the organization.ResponsibilitiesWork as part of the Infrastructure team defining and improving our general security posture across legacy and green field resources including data, applications and networksProvide point of expertise on application, data and network security to our wider engineering teams - engaging with them in order to ensure consistent adoption of security policies and best practiceParticipate in the automation of software to our cloud platform and embed security into our methodology, embracing Dev Sec OpsImprove our monitoring and alerting systems to enhance them with specific and relevant security data pointsParticipate in an on‑call rotation and assist with troubleshooting issues that ariseDefining and implementing a Security Incident Response process/policy with regular evolvement,
testing and adherenceRequired QualificationsThree years or more experience in Cloud Infrastructure roles (predominantly AWS) working within teams that practice Dev Sec OpsAbility to interact comfortably with AWS via CLI and/or APIProficient in managing Infrastructure exclusively with TerraformSpecific expertise in threat assessment, attack surface management, data security, the network stack at L4 and L7, DNS, VPC security, IGW, WAF and Cloud FrontExperience designing and managing IAM policies, roles and trust policiesGood knowledge of most of VPN, MFA, SAML, OAuth2, KMS and TLSGood knowledge of some Id P (Okta, One Login, Auth0) frameworks and integrationsExperience building and running Docker images/containers securely, including container orchestration securityExperience of code security audit, static and dynamic analysis, defensive programming techniques and visualisation and measurement of security KPIsExpertise in at least one scripting or programming language (Python, Bash, Ruby, Node, Golang, Java)Plays well with others - we build and ship as a teamAdvantageous QualificationsAWS Certified Security SpecialistHands on experience designing and implementing security controls within GCPExperience defining and operating a Security Incident Response processGood knowledge of monitoring and alerting using one or more of: Graphite, Statsd, Prometheus, Grafana, Open SearchAny experience of ISO27001 certification processesUnderstanding of “cloud native” and 12-Factor applicationsOffensive or defensive penetration testing experience
📌 Senior Cloud Security Engineer (Barcelona)
🏢 Cint
📍 Barcelona