Cloud Security Engineer

HappyRobot
Madrid, Barcelona
Workplace: HybridFull timeFunction: CybersecurityExperience: 4-6 yearsSkills: ["Ownership","Risk communication","Cross-team collaboration","End-to-end thinking","First-principles thinking"]

Own cloud security posture end-to-end across AWS, Azure, and GCP, triaging Wiz findings by exploitability and driving remediation to SLA. Build shift-left guardrails with Terraform policy-as-code (OPA/Rego, Checkov, tfsec) to block misconfigurations before production. Define and enforce a consistent multi-cloud security baseline, harden Kubernetes (EKS/AKS/GKE) with RBAC/admission controls/image scanning, and lead cross-team fixes with clear risk communication.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
HappyRobot
HappyRobot
1 day ago

Cloud Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 19 hours agoStatus: Live

Job Summary

Own cloud security posture end-to-end across AWS, Azure, and GCP, triaging Wiz findings by exploitability and driving remediation to SLA. Build shift-left guardrails with Terraform policy-as-code (OPA/Rego, Checkov, tfsec) to block misconfigurations before production. Define and enforce a consistent multi-cloud security baseline, harden Kubernetes (EKS/AKS/GKE) with RBAC/admission controls/image scanning, and lead cross-team fixes with clear risk communication.
Location: Madrid, Barcelona
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own CNAPP end-to-end: triage Wiz findings by exploitability/business impact, drive remediation across engineering teams to SLA, and close findings.
  • •Design and ship policy-as-code gates in the Terraform pipeline to block misconfigurations at PR/plan time before production.
  • •Define, document, and enforce a consistent multi-cloud security baseline across AWS, Azure, and GCP (IAM, networking, KMS/encryption, logging) and maintain audit evidence documentation.
  • •Harden Kubernetes and containers across EKS/AKS/GKE by setting and enforcing RBAC, admission controls, and image scanning standards.
  • •Drive remediation leadership through engineering teams without direct authority by tracking SLAs, communicating risk, and escalating when needed.

Pay and Benefits

Perks:Health InsuranceDentalVision

Key Requirements

  • •4–6 years in cloud security or platform/infrastructure security.
  • •Expert depth in at least one major cloud provider (AWS, Azure, or GCP) across IAM, networking, KMS/encryption, and logging.
  • •Hands-on CNAPP/CSPM experience (Wiz strongly preferred) including triage, prioritization, and driving remediation with engineering teams.
  • •Terraform experience in production plus policy-as-code (OPA/Rego, Checkov, tfsec, or similar) integrated in CI/CD.
  • •Kubernetes security fundamentals: RBAC, admission control, and image scanning; scripting proficiency in Python or Go.
Experience:4-6 yearsCloud securityPlatform securityCNAPPCSPMKubernetesMulti-cloud
Skills:OwnershipRisk communicationCross-team collaborationEnd-to-end thinkingFirst-principles thinking
Certifications:CCSKCKACKSAWS Security Specialty
Languages:English
Tech Stack:AWSAzureGCPCNAPPCSPMWizTerraformOPARegoCheckovTfsecKubernetesEKSAKSGKERBACKMSEncryptionLoggingPython

Company Brief

HappyRobot
Builds and manages enterprise AI workers (conversational and document-processing agents) to automate operational workflows for supply chain and logistics companies, integrating with systems to execute tasks, collect real-time data, and drive operational insights.
Industry: Supply Chain Technology
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Valuation: USD 250M to 500M
Funding: Series B
Headquarters: San Francisco, United States
Founded: 2022
WebsiteLinkedInGlassdoor