GCP Cloud Security Engineer

18 ore fa

Torino, Provincia di Torino; Piemonte, Italia Qualcomm Tempo pieno
Company Qualcomm Europe, Inc. Italy Branch Office Job Area Engineering Group, Engineering Group Software Engineering General Summary Arduino's mission is to enable people to enhance their lives through accessible open-source electronics and digital technologies. Since 2005, millions of people from around the world—from young kids to university students and to professionals in diverse fields—have been using Arduino to innovate in music, games and toys, smart homes, farming, autonomous vehicles, and many more. We are looking for a Sr Cloud Security Engineer to join our team of expert professionals eager to share their knowledge and to be part of this vibrant company's journey toward the democratization of technology. The role includes ensuring the security of Arduino Software and Cloud platforms and fostering awareness inside the company about security best practices. A challenging career path in a rapidly growing company with a modern vision and talented teams. A competitive salary (and benefits) that values people's skills and experience. A young and inspiring work environment that encourages diversity and cultural exchange. Individual growth objectives with a dedicated budget for learning/training. Flexible

working hours
and working locations; Ping pong and football tournaments (sport or gym benefit is also included for everyone). Seasonal celebrations, happy hours, and everyday drinks and snacks at the office. What You'll Work On Ensure that the data we are trusted to protect is secured to the highest standards. Help the Development and Dev Ops teams with Security Best Practices. Provide security guidance on a constant stream of new projects and technologies. Provide subject‐matter expertise on architecture, authentication, and system security. Design, implement, and manage security solutions for AWS environments through Ia C technologies. Implement and manage standard AWS security tools, including AWS Security Hub, Guard Duty, Inspector, Cloud Trail, WAF, KMS, Config, and IAM Access Analyzer. Build secure CI/CD pipelines adopting Dev Sec Ops principles and AI Security Agent technologies. Build internal tools for detecting and responding to security problems and incidents. Monitor cloud environments for security incidents and anomalies, and respond to suspected incidents in a timely manner. Collaborate with Infrastructure and Application development teams to integrate security controls in the cloud using standardized configuration tools. Work with product development teams to implement security controls that comply with recognized regulatory, compliance, and standards such as R2, EN18031, and CRA. Make informed prioritization decisions by assessing risk across vulnerability management activities, including CVE triage, CVSS scoring, coordinated disclosure, and collaboration with external reporters. Ensure alignment and compliance with ISO27001 and provide the definition of Security policy for the organization, including training of company employees on security policy. Bachelor's degree in Engineering, Information Systems, Computer Science, or related field and 6+ years of Software Engineering or related work experience. Master's degree in Engineering, Information Systems, Computer Science, or related field and 5+ years of Software Engineering or related work experience. Ph D in Engineering, Information Systems, Computer Science, or related field and 4+ years of Software Engineering or related work experience. 3+ years of work experience with a programming language such as C, C++, Java, Python, etc. Bachelor or Master Degree in Computer Science or related field, or equivalent experience. 5+ years of experience in security engineering or comparable experience (Dev Ops, SRE). Experience in containerisation / orchestration with Docker and Kubernetes. Strong, well‐rounded background in host, network, and cloud security. Experience in designing and defining secure cloud native systems. Experience with applied cryptography including PKI, TLS, and key management. Expertise with modern programming languages and software versioning tools (GIT/Git Hub). Knowledge of relevant security compliance, standards and regulations (ISO, SOC, NIST, GDPR, CIS, CRA). Knowledge of internet security issues and the threat landscape (OWASP, STRIDE, MITRE ATT& CK, CWE). Experience with security monitoring, incident detection and response to suspected incidents in a timely manner. Good experience with Vulnerability Management, Threat modeling, Risk Assessment and Risk Mitigation in cloud, web or Io T ecosystems. Good written and oral communication skills in English. Ability to work with cross‐functional teams (including developers, engineers, and IT) and to explain technical concepts to non‐technical audiences (e.g., training for employees). Bonus Points Previous experience working with Infrastructure and Dev Ops. Working experience with cloud providers like AWS or GCP. Experience with Arduino or other microcontrol