Senior Security Engineer

Senior Security Engineer

Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
Docebo Inc.

At a Glance

  • Tasks: Secure Docebo's cloud infrastructure and enhance AWS security controls.
  • Company: Join a leading AI-powered learning platform transforming workplace training.
  • Benefits: Competitive pay, health benefits, flexible work, and generous time off.
  • Other info: Collaborative culture with opportunities for growth and innovation.
  • Why this job: Make a real impact on cloud security while shaping the future of learning.
  • Qualifications: 5+ years in cybersecurity with a focus on AWS cloud security.

The predicted salary is between 63000 - 77000 £ per year.

Artificial Intelligence. Actual Impact. At Docebo, we're using AI to change how people learn at work—and we mean actually change it. We're an AI-powered learning platform that helps organizations create, deliver, and manage training all in one place. But our real mission goes deeper: we help teams move faster, work smarter, and focus on the work that truly matters. Our platform is built with intelligent, time-saving tools that personalize learning, eliminate busywork, and turn training from a checkbox into a superpower. The result? Better experiences for learners and real results for businesses. We're shaping the future of learning with a team that isn't afraid to challenge the status quo. If you're excited by the idea of using AI to make work-life better for real people—you'll feel right at home here.

Role Overview: The Senior Security Engineer will play a central role in securing Docebo's cloud infrastructure, with a primary focus on AWS environments. Working closely with Cloud Infrastructure & Operations, Engineering, and other security teams, this role is responsible for designing, implementing, and continuously improving cloud security controls across all layers of the stack - from infrastructure provisioning and container orchestration to runtime detection and compliance enforcement. This is a hands‑on, high‑ownership role for someone who thinks in terms of risk and moves quickly to reduce it. The role also includes participation in an on‑call rotation for security incidents affecting Docebo systems.

Responsibilities (including but not limited to):

  • Cloud Security Architecture & Hardening: Own the security posture of Docebo's AWS environments. Define and enforce secure account structures, service control policies (SCPs), guardrails, and baseline configurations across multi‑account setups. Evaluate and improve network segmentation, IAM boundaries, and data protection controls. Identify and remediate misconfigurations using CSPM tooling and manual review.
  • Infrastructure as Code Security: Partner with Cloud Infrastructure to integrate security controls into IaC workflows. Define guardrails to catch insecure configurations before deployment. Own security scanning in CI/CD pipelines and promote a shift‑left approach to cloud security across engineering teams.
  • Incident Response & On-Call: Participate in the on‑call rotation for security incidents, including triage, containment, and escalation for after‑hours events. Lead investigation and root cause analysis for cloud security incidents with clear written post‑mortems. Leverage automation and AI tooling to reduce mean time to detect and respond.
  • Cloud Detection & Threat Monitoring: Build and maintain detection coverage for cloud‑native threats (privilege escalation, unusual API activity, lateral movement, data exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud.
  • Vulnerability & Configuration Management: Own vulnerability management for cloud workloads - prioritising findings from cloud configuration assessments, and runtime protection tools. Drive remediation with Engineering and Infrastructure teams, and build automated enforcement where manual review doesn't scale.
  • Identity & Access Management: Define and enforce least‑privilege principles across AWS IAM, service accounts, and federated identity. Review and improve IAM policies, permission boundaries, cross‑account roles, and access patterns. Reduce standing access and enforce JIT access where appropriate.
  • Development of Security Best Practices: Develop and document best practices, policies, and procedures for cloud security. Provide guidance and training to engineering and infrastructure teams to promote a security‑aware culture.
  • Vendor relationships: Maintain relationships with security vendors for technical issues, ensure smooth operations of security tools and services, and elevate or expose vendor issues when needed.

What it takes to be successful: You're a cloud security practitioner who operates with a builder's mindset. You understand AWS deeply - not just its security services, but how misconfigurations and design decisions create real risk. You're comfortable reading IaC, reviewing IAM policies, and diving into CloudTrail logs to reconstruct what happened. You know how to work with engineering and infrastructure teams as a partner, not a gatekeeper - and you can communicate risk clearly to stakeholders who don't live in the cloud console. You're comfortable being on‑call and making decisions under pressure. Additionally, holding security‑related certifications such as those from ISC2, ISACA, SANS, or CompTIA, and having Cloud Architecture certifications (AWS Security Specialty, AWS Solutions Architect, or equivalent) will significantly enhance your effectiveness in this role.

Requirements:

  • 5+ years of relevant work experience in cybersecurity, with a strong focus on cloud security in production AWS environments.
  • Deep hands‑on experience with AWS security services: IAM, SCPs, CloudTrail, GuardDuty, Config, KMS, VPC security, and more.
  • Good knowledge of Kubernetes security - including RBAC, pod security standards, network policies, admission controllers, and secrets management.
  • Experience with cloud security posture management (CSPM) and cloud workload protection (CWPP/CNAPP) tools.
  • Experience securing IaC pipelines (Terraform, CloudFormation) and integrating security scanning into CI/CD workflows.
  • Good experience with container and image security - scanning, runtime protection, supply chain risk.
  • Experience with SIEM and detection engineering - building and tuning cloud‑native detection rules, threat hunting across CloudTrail and application logs.
  • Familiarity with automation platforms and AI‑driven security tools to streamline detection, enrichment, and response.
  • Experience with Infrastructure as Code (IaC) and scripting (Python, Bash, or similar) to develop custom security tooling and automate workflows.
  • Strong IAM fundamentals: least privilege, cross‑account roles, permission boundaries, federated identity, and privileged access management.
  • Comfortable working across Azure/GCP in addition to AWS - multi‑cloud exposure is a plus.
  • In‑depth knowledge of information security principles and cybersecurity frameworks relevant to cloud environments: MITRE ATT&CK for Cloud, CIS Benchmarks, AWS Well‑Architected Security Pillar, NIST CSF, SOC 2, ISO 27001.
  • Willingness and ability to participate in an on‑call rotation, including after‑hours response.
  • Ability to produce clear, comprehensive, and well‑structured documentation (e.g. incident reports, architecture reviews, runbooks, and security standards) and to communicate complex technical issues effectively to non‑technical stakeholders.

Our Hybrid Work Philosophy: Great work can happen anywhere but coming together helps us go further. Our team spends three days a week in the office (Tuesday-Thursday) to collaborate, solve problems, and learn from each other. With flexibility the rest of the week, it’s a balance designed to help everyone do their best work and keep growing.

Our Total Rewards Philosophy: Our Total Rewards Philosophy centres around three core areas to reward and care for our People: Rewarding Impact, Fostering Holistic Wellbeing, Empowering Our Talent Culture.

Our Promise to You: Financial Wellness, Your Well-Being, Covered, Rest, Relax, Repeat, Family First, Connections That Count.

About Docebo: At Docebo, we create seamless, AI‑powered learning experiences for over 3,000 customers worldwide. We have successfully achieved two IPOs (TSX: DCBO & NASDAQ: DCBO), been recognised as a top SaaS e-learning solution, and are growing exponentially in the process. We're a global company, with offices across North America, EMEA, APAC, and beyond. Our team is guided by five core values—Grow Together Win Together, Build with Our Customer, Clear is Kind, Own Outcomes, Progress Over Perfection—that shape everything we do. If this resonates with you, now is the perfect time to join one of the fastest‑growing learning technology companies in the world. Docebo is an Equal Employment Opportunity employer. We are committed to diversity and inclusion in our workforce.

Senior Security Engineer employer: Docebo Inc.

At Docebo Inc., we pride ourselves on fostering a dynamic and inclusive work culture that empowers our employees to thrive. As a Strategic Technical Account Manager, you will benefit from ongoing professional development opportunities and the chance to work with cutting-edge AI technologies in a collaborative environment. Our commitment to innovation and customer success ensures that you will play a pivotal role in shaping the future of learning platforms while enjoying a flexible work-life balance.

Docebo Inc.

Contact Details:

Docebo Inc. Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Security Engineer

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Docebo Inc., love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Docebo Inc.

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Docebo Inc.. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Senior Security Engineer

AWS Security Services
Cloud Security Architecture
Infrastructure as Code (IaC)
Incident Response
Vulnerability Management
Identity and Access Management (IAM)
Cloud Security Posture Management (CSPM)

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Docebo Inc. insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Docebo Inc. that you’re committed to staying ahead in the game.

How to prepare for a job interview at Docebo Inc.

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Docebo Inc. to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Docebo Inc..

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.