18 ago
|
Happyrobot
|
Madrid
Born in Y Combinator (S23) and backed by a16z, Base10, Prysm Capital and Eurazeo with over $150M raised, we power critical operations for general enterprises worldwide. Our platform is battle-tested in the most demanding environments, where AI has real consequences. We started in logistics, built our own voice stack, models, and orchestration layer from the ground up, and are now bringing that infrastructure to every enterprise that runs the real economy.
We are looking for a Cloud Security Engineer to join our team. You will be the single accountable owner for cloud security posture across AWS, Azure, and GCP — bringing the technical depth and operational discipline to keep our infrastructure hardened, our findings remediated on SLA, and our security baseline consistent across every environment we run.
Cloud Posture Management
Own the CNAPP end-to-end. IaC Security Design and ship policy-as-code gates in the Terraform pipeline that block misconfigurations at PR and plan time, before they reach production. Use OPA/Rego, Checkov, tfsec, or equivalent — and calibrate gates to stop bad patterns without creating friction that causes teams to route around them.
Multi-Cloud Baseline Define, document, and enforce a consistent security baseline across AWS, Azure, and GCP — covering IAM, networking, KMS/encryption, and logging. Own the documentation that supports enterprise customer security reviews and audit evidence requests. Kubernetes & Container Security Harden clusters, images, and admission paths across EKS, AKS, and GKE.
Set and enforce RBAC policies, admission controls, and image scanning standards. Shift-Left Guardrails Grow the share of cloud infrastructure managed via Terraform with active security checks, quarter over quarter. 4–6 years in cloud security or platform/infrastructure security. ~ Expert depth in at least one major cloud provider (AWS, Azure, or GCP): IAM, networking, KMS/encryption,
and logging. ~ Terraform in production plus policy-as-code experience (OPA/Rego, Checkov, tfsec, or similar) integrated in CI/CD. ~ Kubernetes security fundamentals: RBAC, admission control, and image scanning. ~ Scripting proficiency in Python or Go. ~ English B2+ (professional working proficiency). Working experience across 2+ cloud providers — we deploy on AWS, Azure, and GCP.
Cross-cloud and Kubernetes certifications: CCSK, CKA, CKS, AWS Security Specialty, or equivalent. EKS/AKS/GKE hardening and container runtime security experience. TypeScript or Go beyond scripting. SOC 2 / ISO 27001 cloud control evidence experience.
Have ownership and autonomy of projects and are encouraged to ship.
Comprehensive
Benefits including healthcare, dental, vision coverage. No excuses, no blame-shifting. If something needs fixing, we own it. We never settle for "just fine" — whether it's a scoping document, a prototype demo, or a customer conversation.
We're building something ambitious and it's better when we enjoy it together. Ownership goes to those who earn it. It's how we build what others think is impossible. By sending us your CV, you consent to the processing of your personal data for the purpose of evaluating and selecting you as a candidate for the position.
Your personal data will be treated confidentially and will only be used for the recruitment process of the selected job offer. In relation to the period of conservation of your personal data, these will be eliminated after three months of inactivity in compliance with the GDPR and legislation on the protection of personal data. If you wish to exercise your rights of access, rectification, deletion, portability or opposition in relation to your personal data, you can do so through subject to the GDPR.
By submitting your request, you confirm that you have read and understood this clause and that you agree to the processing of your personal data as described. #
📌 Cloud Security Engineer - AWS (Madrid)
🏢 Happyrobot
📍 Madrid