Senior Security Engineer, AWS Security

2 giorni fa

Monza, Provincia di Monza e Brianza; Lombardia, Italia Docebo Tempo pieno
Overview In this role you will safeguard Docebo's AWS-based platform, partnering with infrastructure, operations and engineering teams to implement strong security controls across the stack. You will drive automated defenses, threat detection, and secure configurations, influencing incident response and risk remediation. Your work protects millions of learners and helps scale a mission-driven, AI-powered learning platform. This is a high-visibility role that rewards ownership and practical security leadership. Retribuzione / Benefits health benefits paid vacation days Own the security posture of multi-account AWS environments, defining secure account structures and baseline configurations Integrate proactive security controls and automated scanning into IaC (Terraform/CloudFormation) workflows and CI/CD pipelines Develop and tune cloud-native threat detection using CloudTrail, GuardDuty and SIEM integrations; participate in incident response on-call Manage vulnerability and configuration management across cloud workloads with CSPM/CNAPP tools and rapid remediation Architect and enforce least privilege through IAM, service accounts, and JIT access where appropriate Create and evangelize cloud security standards, runbooks and policies to foster a security-conscious culture Maintain vendor relationships with security tool providers and handle complex edge cases 5+ years in cybersecurity with hands-on security of high-scale AWS environments (IAM, SCPs, KMS, VPC, CloudTrail) ~ Strong Kubernetes security expertise (RBAC, pod security standards, network policies, container image supply chain risks) ~ Proficiency in Infrastructure as Code and scripting (Python or Bash) for automation and tooling ~ Experience with SIEM, threat hunting and frameworks such as MITRE ATT&CK, CIS Benchmarks, NIST CSF, AWS Well-Architected ~ Ability to work under pressure, participate in on-call rotation, and document risk for cross-functional teams ~ Bonus: multi-cloud experience (Azure/GCP) and cloud/security certifications (AWS or ISC2/SANS/ISACA/CompTIA) ~ collaboration across teams ~ AWS security (IAM, SCPs, KMS, VPC, CloudTrail) ~ Kubernetes security (RBAC, network policies, pod security) ~ IaC (Terraform, CloudFormation)