Principal Cloud Security Engineer
Damia Group PortugalTech recruitment experts on a mission to provide the best recruitment exper
Skills
Remote details
To apply for this job you must be willing to work in the time zone London.
Remote from Portugal
Description
<!--block-->Role description and responsibilities<!--block-->Damia Group is an international tech recruitment agency with 3 decades of experience. Our arrival in Portugal, 7 years later, was set on a mission to transform IT recruitment experiences and, through them, achieve better results. We believe in long-term relationships with a transparent and relaxed mindset. In a short period, we have reached the hearts of both scale-ups and larger organisations by delivering spot-on curated candidate shortlists, increased job offer acceptance rates and shorter time-to-fill.
About the role: As a Principal Cloud Security Engineer, the successful candidate will partner with DevOps and CI/CD engineers and their Architects team to ensure security best practices are embedded across the company's cloud infrastructure.
<!--block-->The Cloud Security team is a collaborative group of talented cloud security engineers working in close partnership with the engineering, platform, and trust & security teams. They are on a mission to safeguard the privacy and security of the company and its users' data, embedded directly in the heart of product development.
<!--block-->Responsibilities:
<!--block-->Requirements
Nice to have:
About the role: As a Principal Cloud Security Engineer, the successful candidate will partner with DevOps and CI/CD engineers and their Architects team to ensure security best practices are embedded across the company's cloud infrastructure.
<!--block-->The Cloud Security team is a collaborative group of talented cloud security engineers working in close partnership with the engineering, platform, and trust & security teams. They are on a mission to safeguard the privacy and security of the company and its users' data, embedded directly in the heart of product development.
<!--block-->Responsibilities:
- <!--block-->Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organisation
- <!--block-->Use their knowledge of security architecture to help engineers build and securely operate products and services from the ground up
- <!--block-->Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements
- <!--block-->Perform proactive research to identify new threats and attack vectors
- <!--block-->Partner with engineering teams to embed shift-left security practices throughout the software development lifecycle
- <!--block-->Implement and manage cloud and Kubernetes security posture management tooling to continuously monitor and reduce risk across containerised workloads
<!--block-->Requirements
- <!--block-->Proven experience working with AWS and AWS security services in a secure production environment, including IAM, Config, KMS, Secrets Manager, CloudWatch, CloudTrail, and GuardDuty
- <!--block-->Proven experience working closely with engineering teams and supporting them on their path to shifting security left
- <!--block-->Background with infrastructure as code (AWS CDK, CloudFormation, or Terraform), version control and CI tools such as GitLab and GitLab CI
- <!--block-->Hands-on experience with Kubernetes (AWS EKS), containers (Docker, AWS ECS), K8s admission controllers and Supply Chain Security
- <!--block-->Solid understanding of internet and computer network protocols, including TCP/IP, TLS, and VPN
- <!--block-->Good written and verbal communication skills in English
- <!--block-->Collaborative team player with a hands-on, can-do approach to problem-solving
- <!--block-->Currently living in Portugal and legally authorized to work in the country
Nice to have:
- <!--block-->AWS Certified Security – Specialty certification or similar
- <!--block-->General familiarity with AI tools and large language models (e.g., Claude by Anthropic, AWS Bedrock)



