Senior Cloud Security Engineer
Hybrid in Republic of Lithuania, Latvia
Security.Cloud& 12 others
Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobChoose an option
We are seeking a Senior Cloud Security Engineer to ensure the secure operations of our cloud infrastructure, platforms, and software, including the installation, maintenance, and improvement of cloud computing environments and monitoring solutions. This role also involves developing new designs and security strategies across cloud-based applications, spanning both infrastructure and platform layers.
Responsibilities
- Review existing Kubernetes environments, workloads, and security configurations
- Identify Kubernetes security risks, misconfigurations, and gaps against industry best practices
- Collaborate with the Platform team to embed security controls into Kubernetes deployment workflows
- Apply Helm knowledge to review and secure Kubernetes package management, including Helm charts, values files, release configurations, and deployment templates
- Design, configure, and deploy Falco on Kubernetes environments, customizing rules to detect suspicious activity, policy violations, and runtime threats
- Configure Falco outputs and integrations with existing logging, monitoring, SIEM, or alerting platforms
- Define alert severity levels, escalation paths, and response guidance for Falco-generated alerts
- Validate Falco detections through testing and controlled simulation of relevant security events
- Maintain Falco configuration, rules, and deployment documentation, and support the creation of playbooks and runbooks for common Kubernetes security events
- Assist with triage and investigation of Kubernetes runtime security alerts where required
- Produce clear technical documentation covering Falco configuration, alerting logic, operational procedures, and Kubernetes security recommendations
- Deliver knowledge-sharing sessions to the Cloud Security team and relevant Platform team members, explaining Falco concepts, Kubernetes runtime security principles, and alert investigation approaches
Requirements
- 3+ years of experience in technical IT or security roles
- Background in securing Kubernetes deployments
- Familiarity with SIEM tools such as Splunk, Rapid7, ELK, QRadar, etc.
- Comprehensive knowledge of standard security products and technologies
- Understanding of Linux operating systems and hands-on system administration experience
- Proficiency in command line interfaces and scripting, especially Lambda, Python, Bash, or PowerShell
- Capability to triage, investigate, analyse, and contain information security events
- Strong analytical and problem-solving skills, with the ability to assimilate and correlate large amounts of data from various networks, operating systems, applications, security devices, logs, and alerts
- Confident, driven, and dynamic professional with a results-oriented mindset
- Self-motivated, enthusiastic, and collaborative team player with strong co-working skills
- Conflict resolution skills and the ability to build trustworthy relationships with internal and external stakeholders
- Empathy, communication, and the ability to provide constructive feedback
- Proficiency in English at an Upper-Intermediate level (B2) or higher
Nice to have
- Experience with security services in the AWS environment
- Understanding of incident response and digital forensic techniques
- Hands-on experience with centrally managed information security tools such as Anti-Virus, EDR, SIEM, or SOAR
- Skills in Infrastructure as Code using Terraform, along with a DevSecOps mindset
- Certifications such as Certified Kubernetes Security Specialist, Certified Kubernetes Administrator, AWS Security, AWS Solutions Architect, AWS DevOps Engineer, or CompTIA Security+ or equivalent
