Job Overview
We are looking for a hands-on Cloud Security Engineer to strengthen the security, resilience, and operational reliability of our infrastructure, CI/CD pipelines, cloud environments, and internal platforms.
This role goes beyond day-to-day security operations. You will help design and implement practical guardrails, tools, and processes that reduce vulnerabilities, prevent key leakage, improve security hygiene, and support broader governance and compliance goals across the organization.
In addition to owning core security responsibilities, this role should be broad enough in systems and operations to support cross-team collaboration and share workload when needed across cloud infrastructure, CI/CD, platform reliability, and other high-priority TechOps initiatives.
The Environment
You will work in and help secure a modern multi-cloud and platform environment, with a primary focus on AWS, GCP, Cloudflare, and BytePlus, along with the internal platforms, CI/CD systems, and observability tooling that support our engineering ecosystem.
Key Responsibilities
- Identifying, classifying, tracking, and helping resolve security findings across cloud environments, clusters, container images, endpoints, CI/CD pipelines, and related systems, focusing on high and critical risks.
- Designing, implementing, and continuously improving security controls in CI/CD pipelines, including secret detection, CVE scanning, and policy-based gates, while standardizing rollout patterns across engineering teams.
- Improving security across AWS and GCP environments, Kubernetes clusters, and registries by deploying scanning, sensing, and guardrail solutions to reduce attack surface at the runtime and infrastructure layers.
- Proposing and implementing controls such as key rotation, access policies, RBAC, and fit-for-purpose authentication to remediate risks related to credential leakage, IAM misconfigurations, and excessive permissions.
- Conducting periodic assessments, participating in incident handling, and building documentation or dashboards that improve security visibility and cross-team collaboration with TechOps, SRE, and stakeholders.
Required Qualifications
You'll be an experienced Cloud Security Engineer who enjoys solving complex technical challenges. You'll ideally have experience with:
- GCP Security & Operations: Proven hands-on experience securing and managing GCP environments, including IAM, Service Accounts, GKE, Security Command Center, and Artifact Registry.
- DevSecOps & Infrastructure: Strong background in SRE or Infrastructure Security, with expertise in CI/CD (GitLab, ArgoCD), Kubernetes, container security, and infrastructure-as-code.
- AI/LLM Integration & Governance: Experience implementing security controls for AI platforms (Vertex AI, Gemini), model-access governance, securing LLM-based application workflows, AI security testing, prompt injection assessment, LLM red-teaming, and governance controls for GenAI platforms in production environments.
- Security Tooling & Remediation: Proficiency in automated scanning (CVE, secrets, images) and a track record of driving complex vulnerability remediation plans in production environments.
- Automation & Observability: Skilled in Python or Bash scripting and leveraging observability stacks (Datadog, Honeycomb) to build proactive security monitoring and reporting.
- Core Fundamentals: Deep understanding of Linux systems, networking, RBAC, and zero-trust security patterns in a multi-cloud context (AWS experience is a plus).
Benefits & Compensation
When you join this role, you will work on real-world security challenges across cloud, CI/CD, internal platforms, and AI workloads. You will create visible impact on infrastructure reliability, security hygiene, and governance maturity, helping TechOps build safer, more scalable, and more operationally effective platforms and controls.
At Amanotes, you will enjoy a dynamic working environment with a unique music culture. Alongside a competitive salary based on experience, a 13th-month salary, and a year-end bonus, you'll receive:
- Flexible working time.
- Personal learning and well-being budget.
- Team-building budget.
- Lunch and parking allowance.
- Various learning activities, including internal training & sharing, international conferences, and e-learning (Udemy, LinkedIn Learning...).
- Engaging music events: Music Night, Amasing Night, Music schools…
- Employee Assistance Program to support mental health & well-being.
- Minimum 12 days of paid annual leave, plus 10 days of paid sick leave.
- 12 days working from home per year.
Important Information
Consent Notice for Personal Data Processing: By applying to any position at Amanotes, you acknowledge and agree that your personal data will be collected and processed for recruitment purposes.