At a Glance
- Tasks: Secure and enhance our cloud infrastructure while embracing DevSecOps practices.
- Company: Join Cint, a leader in research technology with a vibrant tech culture.
- Benefits: Competitive salary, great perks, and opportunities for professional growth.
- Other info: Collaborative team atmosphere with exciting challenges and career advancement.
- Why this job: Make a real impact on cloud security in a fast-growing tech environment.
- Qualifications: 3+ years in Cloud Infrastructure, AWS expertise, and a passion for security.
The predicted salary is between 70000 - 90000 £ per year.
Cint is a pioneer in research technology (ResTech). Our customers use the Cint platform to post questions and get answers from real people to build business strategies, confidently publish research, accurately measure the impact of digital advertising, and more. The Cint platform is built on a programmatic marketplace, which is the world's largest, with nearly 300 million respondents in over 150 countries who consent to sharing their opinions, motivations, and behaviours.
Our vision for the role
We are searching for an experienced Senior Cloud Infrastructure Security Engineer with an unquenchable thirst for automation and a passion for DevSecOps methodology. You'll be working with a team of other engineers to build out and secure our expanding cloud infrastructure in AWS. While this is a hands-on engineering position (not a CISO or a consulting role), you will need the confidence and gravitas to heavily influence engineers and managers across a wide technical function. The team holds itself accountable to a high standard of build quality. We have recently completed the first major phase of a completely green-field infrastructure and platform rebuild that is designed to underpin Cint’s business applications for the next decade, while scaling to support a 10-fold growth in revenue.
We are compulsive about infrastructure as code (nothing in our platform is created or deployed unless via a code change) and driven to achieve a full end to end continuous deployment pipeline. Major elements of our platform include AWS (we make significant use of S3, RDS, Kinesis, EC2, EMR, ElastiCache, ElasticSearch and EKS). Elements of the platform will start to expand into GCP (Compute Engine, Cloud Storage, Google Kubernetes Engine and BigQuery). Other significant tools of the platform include Linux, Terraform, Kubernetes, Docker, Packer, Ansible and Jenkins. We support applications and services written in Golang, Python, Java, Scala and .Net. We monitor and alert on everything we deploy via Grafana, Prometheus, Graphite and ELK stacks.
You will be someone that shares our values and ambitions and can bring security best practices and specific cloud security expertise to the party. You will additionally be the kind of person that is energized by complex challenges, teamwork and problem solving. In return, we can offer a great tech culture, highly competitive compensation packages and employment benefits.
Qualifications Responsibilities
- Work as part of the Infrastructure team defining and improving our general security posture across legacy and green field resources including data, applications and networks.
- Provide point of expertise on application, data and network security to our wider engineering teams - engaging with them in order to ensure consistent adoption of security policies and best practice.
- Participate in the automation of software to our cloud platform and embed security into our methodology, embracing DevSecOps.
- Improve our monitoring and alerting systems to enhance them with specific and relevant security data points.
- Participate in an on-call rotation and assist with troubleshooting issues that arise.
- Defining and implementing a Security Incident Response process/policy with regular evolvement, testing and adherence.
Required Qualifications
- Three years or more experience in Cloud Infrastructure roles (predominantly AWS) working within teams that practice DevSecOps.
- Ability to interact comfortably with AWS via CLI and/or API.
- Proficient in managing Infrastructure exclusively with Terraform.
- Specific expertise in threat assessment, attack surface management, data security, the network stack at L4 and L7, DNS, VPC security, IGW, WAF and CloudFront.
- Experience designing and managing IAM policies, roles and trust policies.
- Good knowledge of most of VPN, MFA, SAML, OAuth2, KMS and TLS.
- Good knowledge of some IdP (Okta, OneLogin, Auth0) frameworks and integrations.
- Experience building and running Docker images/containers securely, including container orchestration security.
- Experience of code security audit, static and dynamic analysis, defensive programming techniques and visualisation and measurement of security KPIs.
- Expertise in at least one scripting or programming language (Python, Bash, Ruby, Node, Golang, Java).
- Plays well with others - we build and ship as a team.
Advantageous Qualifications
- AWS Certified Security Specialist.
- Hands on experience designing and implementing security controls within GCP.
- Experience defining and operating a Security Incident Response process.
- Good knowledge of monitoring and alerting using one or more of: Graphite, Statsd, Prometheus, Grafana, OpenSearch.
- Any experience of ISO27001 certification processes.
- Understanding of 'cloud native' and 12-Factor applications.
- Offensive or defensive penetration testing experience.
Senior Cloud Security Engineer employer: Cint AB
Cint is an exceptional employer, offering a vibrant tech culture that fosters innovation and collaboration among its engineers. With a strong commitment to employee growth, Cint provides competitive compensation packages and benefits, alongside opportunities to work on cutting-edge cloud infrastructure projects in a dynamic environment. Located in a thriving industry, employees are empowered to embrace complex challenges while contributing to the company's ambitious vision for the future.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Cloud Security Engineer
✨Tip Number 1
Network like a pro! Attend industry meetups, webinars, or conferences related to cloud security. It's a great way to meet potential employers and get your name out there. Plus, you might just learn something new that could give you an edge in interviews!
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your projects, especially those involving AWS, Terraform, or DevSecOps practices. This gives you a tangible way to demonstrate your expertise and passion for cloud security to potential employers.
✨Tip Number 3
Prepare for technical interviews by brushing up on your knowledge of cloud infrastructure and security best practices. Be ready to discuss your experience with tools like Docker, Kubernetes, and monitoring systems. Practice common interview questions to boost your confidence!
✨Tip Number 4
Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining our team. Tailor your application to highlight how your skills align with our needs, and let your enthusiasm shine through!
We think you need these skills to ace Senior Cloud Security Engineer
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Senior Cloud Security Engineer role. Highlight your experience with AWS, Terraform, and DevSecOps practices. We want to see how your skills align with our needs!
Showcase Your Projects:Include specific projects where you've implemented security measures or automated processes in cloud environments. This gives us a clear picture of your hands-on experience and problem-solving abilities.
Be Clear and Concise:When writing your cover letter, be clear and concise about why you’re a great fit for the role. Use language that matches our job description to show you understand what we’re looking for.
Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. We can’t wait to hear from you!
How to prepare for a job interview at Cint AB
✨Know Your Cloud Security Inside Out
Make sure you brush up on your knowledge of AWS and GCP security features. Be ready to discuss specific tools like IAM policies, WAF, and VPC security. The interviewers will want to see that you can confidently navigate the cloud security landscape.
✨Show Off Your DevSecOps Passion
Since this role is all about embedding security into the development process, be prepared to share examples of how you've implemented DevSecOps practices in previous roles. Talk about your experience with automation and how it has improved security in your projects.
✨Demonstrate Team Collaboration Skills
Cint values teamwork, so highlight your ability to work well with others. Share stories of how you've engaged with engineering teams to promote security best practices and how you’ve influenced decisions across technical functions.
✨Prepare for Technical Challenges
Expect to face some complex scenarios during the interview. Brush up on your problem-solving skills and be ready to tackle hypothetical situations related to cloud security incidents or infrastructure challenges. This will show your analytical thinking and readiness for the role.