Staff Information Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Staff Information Security Engineer (Cyber Resiliency/AWS-GCP-Azure): Own the operational lifecycle and maturity of 's Cyber Resiliency program, including tool administration, governance, issue triage, and executive reporting with an accent on infrastructure resilience across multi-cloud environments. Focus on driving remediation through engineering engagement, defining prioritization frameworks, and supporting cloud security guardrails, policy-as-code, and CI/CD-based security controls.
Location: Porto, Portugal (Hybrid)
Company
provides cloud contact center software and security programs for cloud infrastructure resilience.
What you will do
- Own the Cyber Resiliency program lifecycle: tool administration, system/resource mapping, criticality tiering, and issue triage workflows.
- Develop and maintain program governance, including process documentation, remediation SLAs, escalation paths, and quarterly review cadences.
- Build executive reporting for security and engineering leadership (resilience score trends, remediation velocity, IaC coverage, and risk exposure by criticality tier).
- Drive program communication and define issue prioritization frameworks balancing criticality, environment, severity, and remediation effort.
- Partner with engineering leads to remediate infrastructure resilience issues, remove blockers, and track progress in Jira.
- Support Cloud Security with architecture reviews, policy development, policy-as-code, automated detection/response, and CI/CD configuration management.
Requirements
- 5+ years of information security experience with demonstrated senior technical ownership.
- Experience operationalizing a security program/service (governance, processes, and reporting), not only executing within an existing framework.
- Deep hands-on experience with at least one major cloud platform (GCP strongly preferred), including IAM, networking, compute, and storage security.
- Strong experience with infrastructure-as-code (Terraform required) and CI/CD pipelines.
- Ability to drive remediation and risk reduction across engineering teams without direct authority.
- Excellent communication skills for presenting program status and risk to engineering, security, and executive audiences.
Nice to have
- Experience with cyber/infrastructure resilience tooling (e.g., Gambit, Wiz, or similar CSPM/CNAPP platforms).
- Risk or security maturity assessments using frameworks such as NIST CSF, ISO 27001, or CMMI.
- Background in Kubernetes security and container workload protection.
- Experience with multi-cloud environments (GCP + AWS + Azure) and Python scripting for automation.
- Security certifications (CISSP, CCSP, SANS, or similar) and mentoring/technical leadership of junior engineers.
Culture & Benefits
- Team-first culture with an inclusive environment and diversity-focused hiring.
- Shares and a Bonus Scheme.
- 10% Flex Benefit, Meal Allowance, Medical Insurance, and Life Insurance.
- 25 days annual leave plus public holidays.
Hiring process
- Interviews focused on security program ownership, cloud security/resilience experience, and cross-team remediation impact.
- Technical evaluation around Terraform/CI/CD and multi-cloud security practices.
- Final discussions covering communication style and executive reporting experience.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →