Senior Cloud Security Engineer
Endava View all jobs
- Dublin
- Permanent
- Full-time
- Define and maintain cloud security policies, standards, reference architectures, and baseline control frameworks across AWS, Azure, and/or GCP environments.
- Design secure cloud landing zones, including IAM models, network segmentation, encryption standards, key management, and secrets management.
- Implement and govern Cloud Security Posture Management (CSPM) capabilities, including risk-based remediation workflows and exception handling.
- Partner with Cloud Operations and Platform Engineering teams to embed policy-as-code, automated guardrails, and infrastructure-as-code security controls.
- Standardize logging and monitoring requirements to ensure effective threat detection, investigation, and response across cloud platforms.
- Conduct security architecture reviews for new cloud services and major platform changes.
- Support cloud-related incident response activities, including root cause analysis and containment strategies.
- Contribute to secure development enablement by providing reusable security blueprints, patterns, and anti-pattern guidance.
- Collaborate with Cyber Defence/SOC teams to ensure cloud telemetry is integrated into SIEM and detection engineering workflows.
- Support third-party SaaS risk assessments and multi-cloud security risk evaluations where required.
- Minimum 8-10 years of experience in IT, with at least 5 years in cloud security, cyber engineering, or cloud architecture roles.
- Proven hands-on experience securing cloud environments using native controls (IAM, networking, encryption, logging, and monitoring).
- Experience implementing and operating Cloud Security Posture Management (CSPM) tools and remediation programs.
- Demonstrated ability to work with Cloud Operations and DevOps teams to operationalize security controls within delivery pipelines.
- Experience designing secure landing zones and enterprise-scale cloud governance frameworks.
- Strong understanding of shared responsibility models across major cloud providers.
- Relevant certifications such as AWS Security Specialty, CCSP, Azure Security Engineer Associate, or equivalent are desirable.
- Deep expertise in at least one major cloud platform (AWS, Azure, or GCP); multi-cloud exposure preferred.
- Strong knowledge of:
- Identity and Access Management (IAM) design
- Network security architecture (segmentation, private connectivity, zero trust principles)
- Data protection (encryption at rest/in transit, KMS, secrets management)
- Secure cloud logging and monitoring patterns
- Experience with CSPM platforms such as Prisma Cloud, CrowdStrike CSPM, Defender for Cloud, or similar.
- Familiarity with Infrastructure-as-Code (Terraform, ARM, CloudFormation) and policy-as-code approaches.
- Experience integrating cloud telemetry into SIEM platforms and supporting SOC operations.
- Working knowledge of DevSecOps tooling and CI/CD security integration.
- Understanding of resilience, availability, and secure architecture design principles.
- Finance: Competitive salary package, share plan, company performance bonuses, value-based recognition awards, referral bonus;
- Career Development: Career coaching, global career opportunities, non-linear career paths, internal development programmes for management and technical leadership;
- Learning Opportunities: Complex projects, rotations, internal tech communities, training, certifications, coaching, online learning platforms subscriptions, pass-it-on sessions, workshops, conferences;
- Work-Life Balance: Hybrid work and flexible working hours, employee assistance programme;
- Health: Global internal wellbeing programme, access to wellbeing apps;
- Community: Global internal tech communities, hobby clubs and interest groups, inclusion and diversity programmes, events and celebrations.