About the job
Ebury empowers forward-thinking businesses to achieve global expansion, mirroring our commitment to enhance the career growth of our employees. We nurture an innovative and collaborative atmosphere that promotes teamwork and problem-solving, ensuring that every individual feels valued, supported, and equipped to excel.
If you are a team player eager to revolutionize the way businesses operate internationally, we invite you to connect with us. Ebury is ready to accelerate your career and help you shape the future.
Senior Cloud Infrastructure Security Engineer
Hybrid (4 days in office) in Málaga
At Ebury, we are making substantial investments in our cloud infrastructure security capabilities to uphold the trust and safety of our global financial services. As a Senior Security Engineer focusing on Cloud Infrastructure, you will be responsible for enhancing and managing the security posture of our cloud environments across AWS and GCP, prioritizing network security, perimeter defense, and attack surface management.
This hands-on role demands extensive knowledge of cloud-native security controls, network architecture, and defensive security operations. You will be tasked with designing, implementing, and maintaining security infrastructure that identifies and mitigates threats proactively, ensuring they do not affect our operations. Collaborating closely with platform, infrastructure, and security operations teams, you will embed security best practices into our cloud foundations.
Key Responsibilities
- Manage cloud security posture and attack surface: Ensure comprehensive visibility and control across AWS and GCP environments. Implement cloud-native security monitoring, detection, and alerting to proactively identify and address threats before they affect customers or the business. Define and enforce security baselines through policy-as-code.
- Design and manage web application firewall infrastructure: Oversee WAF configurations across AWS and GCP, developing and fine-tuning detection rules in alignment with application threat models and evolving attack patterns. Establish operational processes for rule lifecycle management and incident response integration, collaborating with application teams to implement protections that do not compromise availability.
- Architect network segmentation and isolation: Design and execute network security strategies ensuring appropriate separation between development, staging, and production environments. Define consistent patterns across multi-cloud infrastructure, applying zero-trust principles to workload communication and documenting reference architectures for engineering teams.
