Faster chat, better deals — Get the App

Cloud Security Engineer

Indeed

Company

Job typeFull-time
Workplace typeOnsite
Experience levelNo experience limit
Education levelNo degree limit

Description

Job Summary: The Cloud Security Engineer will implement and strengthen cloud infrastructure defenses, ensuring data integrity, confidentiality, and availability through automated security controls and identity management. Key Highlights: 1. Promote financial inclusion and security by design 2. Focus on cloud security automation and continuous improvement 3. Culture of trust, purpose, and appreciation for creativity Hello! We are Cashea, and our mission is to restore Venezuelans' access to credit through a **BNPL** (buy now, pay later) business model. Since our launch in 2022, we have dedicated ourselves to advancing **financial inclusion**. Today, we serve over 9 million active users — both consumers and merchants — and have become a trusted brand in Venezuela, winning the hearts and minds of people. #### **Role Summary** The Cloud Security Engineer will be responsible for implementing and hardening cloud infrastructure defenses. Their objective is to ensure data integrity, confidentiality, and availability through automated security controls, identity management, and defensive perimeter implementation — guaranteeing that every deployment is secure by default (Security by Design). #### **Responsibilities** ##### **Architecture and Defensive Perimeter** * Perimeter Control (WAF/NGFW): Optimize Google Cloud Armor, Cloud Firewall, and next-generation firewalls to mitigate DDoS attacks and Layer 7 attacks (OWASP Top 10\). * Secure Landing Zones: Enforce organizational hierarchy using "Guardrails" and "Organization Policies" to prevent widespread misconfigurations. * Workload Hardening: Secure critical environments such as GKE (Kubernetes) by implementing Network Policies, Workload Identity, and Binary Authorization. ##### **Security Across the Lifecycle (DevSecOps)** * Automated Scanning: Integrate vulnerability scanning tools (SAST/DAST) and container scanning tools (Artifact Analysis) directly into CI/CD pipelines. * Secure Infrastructure as Code (IaC): Develop Terraform modules with embedded security controls and perform code audits (Checkov, Terrascan). * Secrets Management: Manage the lifecycle of non-human identities, SSL certificates, and secrets using Secret Manager or HashiCorp Vault. ##### **Governance and Automated Remediation** * Policy as Code (PaC): Write automated compliance rules (Sentinel, OPA) to block insecure resources in real time. * Detection and Response: Configure ingestion of critical logs (VPC Flow Logs, Audit Logs) into the SIEM and develop "Auto\-remediation scripts" to close security gaps without human intervention. * Posture Management (CSPM): Administer Security Command Center to prioritize risks and reduce attack surface. ##### **Cloud Vulnerability Management** * End\-to\-end process: Lead the full cloud vulnerability management lifecycle across cloud infrastructure, containers, and IaC: discovery, triage, prioritization (CVSS \+ business context/exploitability), assignment, remediation, and closure verification. * SLA/SLO definition and enforcement: Establish, maintain, and report remediation SLAs and SLOs by severity (Critical / High / Medium / Low), ensuring traceability from detection to closure (MTTD, MTTR) and tracking compliance per asset owner team. * Metrics and executive reporting: Build vulnerability posture dashboards (open volume, aging, SLA breaches, re-opening rate, scan coverage) for technical and leadership stakeholders. * Engineering team governance: Coordinate with product/infrastructure teams to unblock remediations, define formal exceptions (with expiration dates and compensating controls), and escalate SLA violations per risk process. * Continuous improvement: Identify recurring vulnerabilities or systemic patterns and translate them into preventive controls (PaC, IaC baselines, hardening) to reduce findings at the source. #### **Requirements** * **Experience:** +2 years in cloud infrastructure security (preferably GCP). * **Tools:** Terraform, Kubernetes (K8s), Docker, CI/CD (GitLab, GitHub Actions or Cloud Build), Cloudflare Access \& WAF * **Networking:** Deep understanding of protocols (TCP/IP, TLS, DNS) and Zero Trust architectures. * **Security:** Familiarity with control frameworks such as CIS Benchmarks, NIST, or ISO 27001\. #### **Programming and Scripting Skills** This role requires a developer mindset applied to security: * **Python / Go:** Ability to build custom security tools, interact with cloud APIs, and develop "Serverless functions" to automate incident response. * **Bash Scripting:** Proficiency in OS hardening, log manipulation, and Linux system task automation. * **API Integration:** Ability to connect tools (e.g., integrate JumpCloud with Google SecOps) via scripts that transform and normalize JSON data. * **Version Control:** Use of Git to manage infrastructure and security policies as code. #### **We Value** * **Certifications:** Google Professional Cloud Security Engineer or AWS Certified Security – Specialty. * **Contributions:** Participation in open-source security projects or development of personal scripts on GitHub. * **SOCless Mindset:** Focus on eliminating manual SOC work through infrastructure automation. #### **Why You’ll Love Working at Cashea** At Cashea, we foster a culture built on trust and purpose. If you’d like to know why we’re the ideal place for you, here are our core values: * **We don’t operate on autopilot.** Everything we do and share — internally and externally — is intentional. We’re passionate about creating ideas with full awareness of their impact on our users. * Your creativity and curiosity are your most valuable assets. * **Your voice matters.** We listen and create space for ideas and feedback. Everyone belongs here; what’s important to you is important to us. * **We value transparency.** Clarity keeps us connected and grounded. * Last but not least, **we focus on real impact.** Everything we do is designed to make a difference. Do you identify with this? **Apply now — we’d love to meet you!**

Source: indeed
Some content was automatically translated

Posted by

Sofía González

Indeed · HR

Location

Sofía González

Indeed · HR

Similar jobs

Cloud Security Engineer job by Indeed in 2026 | ok.com