Auf einen Blick
- Aufgaben: Leite komplexe Sicherheitsprojekte in einer Multi-Cloud-Umgebung und verbessere das Schwachstellenmanagement.
- Unternehmen: Nasuni, ein innovatives SaaS-Unternehmen für Datenspeicherung und -sicherheit.
- Vorteile: Wettbewerbsfähiges Gehalt, flexible Arbeitszeiten und Möglichkeiten zur beruflichen Weiterentwicklung.
- Weitere Informationen: Dynamisches Umfeld mit großartigen Wachstumschancen und einem starken Fokus auf Teamarbeit.
- Warum dieser Job: Gestalte die Cloud-Sicherheit und arbeite an spannenden, zukunftsweisenden Projekten.
- Qualifikationen: 6-9 Jahre Erfahrung in der Sicherheits- oder Cloud-Sicherheitsengineering.
Das prognostizierte Gehalt liegt zwischen 60000 - 80000 € pro Jahr.
ABOUT THE ROLE
We are looking for a Senior Security Engineer with deep cloud security expertise to own complex security workstreams across our multi‑cloud environment and drive our vulnerability management program to the next level of maturity.
This is a senior individual contributor role for a security engineer who independently leads complex technical initiatives, influences security decisions across engineering teams, and serves as a trusted cloud security subject matter expert.
The role combines deep technical execution with cross‑functional influence, while partnering with Security leadership and the Principal Security Architect on broader security strategy and architecture direction.
You will operate across cloud security posture management, infrastructure hardening, vulnerability program leadership, and secure Dev Ops practices, with the seniority to make independent technical judgments, lead cross‑functional security initiatives, and mentor colleagues.
This role partners closely with the Principal Security Architect to operationalize cloud security standards, implement security controls, and execute security initiatives across Nasuni’s cloud environments.
You are equally comfortable diving deep into cloud configurations, reviewing security architecture, and advising engineering teams on security trade‑offs.
- Success In This Role Looks Like
- Improved cloud security posture across key cloud platforms
- Increased vulnerability remediation effectiveness and SLA attainment
- Expanded visibility and coverage of cloud security controls
- Reduced recurring security findings through automation and systemic improvements
- Increased adoption of secure‑by‑default cloud engineering practices
WHAT YOU WILL DO
- Cloud Security Engineering and Posture Management
- Lead initiatives that continuously improve Nasuni’s cloud security posture across AWS, Azure, and GCP, including workload security, IAM hardening, network segmentation, encryption, and least‑privilege enforcement.
- Lead cloud security assessments and configuration reviews, identifying and remediating misconfigurations and security gaps using Wiz and cloud‑native tools.
- Drive zero‑trust initiatives and cloud‑native security controls across our multi‑cloud infrastructure.
- Partner closely with the security leadership to translate architectural standards into enforceable, operational controls, and provide ground‑level feedback to shape those standards.
- Evaluate and implement security controls for container and Kubernetes workloads, CI/CD pipelines, and Infrastructure as Code.
- Contribute to cloud security architecture and design reviews by providing implementation guidance, operational security expertise, and risk assessments for new technologies and infrastructure changes.
- Vulnerability Management Program Ownership
- Lead execution and continuous improvement initiatives within Nasuni’s vulnerability management program, partnering with Security leadership to influence strategy, tooling direction, prioritization frameworks, and program maturity across AWS, Azure, and GCP.
- Assess and enforce vulnerability SLAs and risk‑based prioritization frameworks aligned to business risk appetite.
- Analyze vulnerability data across environments, synthesize trends, and produce executive‑ready reporting on exposure, remediation velocity, and risk posture.
- Drive systemic remediation through collaboration with Dev Ops, SRE, IT/infrastructure, and engineering teams, moving beyond ticket‑by‑ticket fixes toward structural improvements.
- Continuously tune and optimize scanning coverage, detection fidelity, and platform configuration across all vulnerability management tooling.
- Identify program gaps, define improvement roadmaps, and present recommendations to security leadership.
- Dev Sec Ops and Infrastructure Hardening
- Partner with Dev Ops and SRE teams to embed security controls into CI/CD pipelines, Ia C templates, and cloud provisioning workflows.
- Drive adoption of security‑as‑code practices including policy‑as‑code, automated misconfiguration detection, and runtime security controls.
- Define and enforce secure configuration baselines across cloud workloads, operating systems, and network infrastructure.
- Assess and harden container and Kubernetes environments; support secrets management and workload identity practices.
- Incident Response
- Support the Sec Ops team by contributing to complex and high‑severity incident responses within your domain.
- Advise the Sec Ops team on the development and improvement of incident response playbooks and runbooks for cloud and infrastructure‑related security events.
- Conduct threat hunting in cloud environments and contribute to detection engineering efforts in collaboration with the Sec Ops team.
- Participate in post‑incident reviews and systemic improvements that reduce recurrence of cloud security events or incidents.
- Compliance and Governance
- Partner with GRC to ensure the vulnerability management and cloud security controls align with compliance requirements.
- Own technical evidence preparation and control documentation within your workstreams for audit and compliance activities.
- Advise engineering and business teams on security considerations for new technologies, integrations, and infrastructure decisions.
- Mentorship and Team Contribution
- Mentor colleagues and peers, guiding technical decisions, sharing expertise, and improving the team’s overall cloud security capabilities.
- Lead security tooling evaluations and contribute to decisions on platform investments and program improvements.
- Design, improve, and scale repeatable AI‑assisted security workflows that enhance vulnerability analysis, cloud security assessments, remediation prioritization, and operational efficiency while maintaining strong validation, security, and risk‑management practices.
- WHAT YOU WILL BRING
Experience
- 6–9 years of experience in security engineering, cloud security, or a closely related discipline.
- Demonstrated ownership of complex cloud security workstreams in a multi‑cloud or cloud‑native environment.
- Proven experience leading or significantly contributing to a vulnerability management program, including tool operation, process design, and stakeholder engagement.
- Experience securing cloud‑native Saa S products or operating within complex cloud‑first technology environments.
- Experience designing or operationalizing repeatable AI‑assisted workflows that improve security engineering, vulnerability management, security analysis, automation, or operational efficiency.
- Cloud Security Depth
- Deep hands‑on expertise with AWS security, including IAM, VPC/networking, Guard Duty, Security Hub, Cloud Trail, KMS, and AWS‑native hardening practices.
Additional Azure and GCP experience a plus.
- Strong working knowledge of CSPM tools; direct experience with Wiz is highly advantageous.
- Experience with container security, Kubernetes security, and Ia C security tooling (Terraform, Cloud Formation, or equivalent).
- Familiarity with CI/CD security integration and Dev Sec Ops practices.
- Technical Foundations
- Strong understanding of network security, protocols, and infrastructure security fundamentals (TCP/IP, DNS, TLS, VPN, firewall design).
- Working knowledge of IAM, Zero Trust principles, secrets management, and authentication protocols (OAuth 2.0, OIDC, SAML).
- Experience with scripting or automation for security workflows (Python, Bash, or equivalent).
- Demonstrated ability to validate AI‑generated outputs using security expertise, testing, data analysis, or other structured review mechanisms before applying recommendations in production environments.
- Frameworks and Compliance
- Familiarity with NIST CSF, CIS Benchmarks, and OWASP frameworks.
- Strong command of vulnerability severity frameworks (CVSS, EPSS) and risk‑based prioritization methodologies.
- Experience conducting technical risk assessments and security design reviews.
- Communication and Influence
- Ability to explain complex security risks and trade‑offs clearly to both engineering and IT/infrastructure peers and non‑technical leadership.
- Strong written communication skills for producing vulnerability reports, security assessments, and architectural recommendations.
- Collaborative working style; you influence through expertise and build trust across teams.
Education and Certifications
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field; or equivalent practical experience.
- Certifications preferred: AWS Security Specialty, CISSP, CCSP, GIAC GCSA, or equivalent cloud security credentials.
- About Nasuni
Nasuni is the unstructured data foundation for enterprise teams—and the AI that supports them.
We manage, protect, and activate the world’s unstructured data so organizations can work smarter, spend wisely, and create safely without limits.
As a Vista‑backed Saa S data infrastructure company, Nasuni is transforming how enterprises manage file data with a next‑generation, AI‑ready platform—turning massive file stores into secure, actionable, and AI‑ready data for intelligent automation, analytics, and global collaboration.
Why Work Here — Europe / Warsaw
At Nasuni, you’ll work at the intersection of cloud infrastructure, enterprise data, cybersecurity, and AI readiness.
You’ll help build and operate modern systems that support global teams and customers while contributing to a company backed by Vista Equity Partners and connected to a broader ecosystem of software leadership and operational excellence.
This is an opportunity to bring hands‑on cloud expertise to a collaborative, high‑growth environment where reliable infrastructure, automation, and secure access directly enable business scale.
Nasuni is an equal opportunity employer.
The equal employment opportunity policy at Nasuni protects employees and job applicants from discrimination on the bases of race, religion, color, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, family medical history or genetic information, political affiliation, military service, or other non‑merit based factors.
These protections extend to all management practices and decisions, including recruitment and hiring practices, appraisal systems, promotions, and training and career development programs.
#J-18808-Ljbffr
Senior Security Engineer - Cloud Security Arbeitgeber: Nasuni
Nasuni ist ein hervorragender Arbeitgeber, der Ihnen die Möglichkeit bietet, in einem dynamischen und kollaborativen Umfeld zu arbeiten, das sich an der Schnittstelle von Cloud-Infrastruktur, Unternehmensdaten und Cybersicherheit befindet. Mit einem starken Fokus auf Mitarbeiterentwicklung und einer Kultur der Zusammenarbeit profitieren Sie von umfangreichen Wachstumschancen und der Möglichkeit, Ihre Expertise in einem innovativen Unternehmen einzubringen, das von Vista Equity Partners unterstützt wird. In Warschau haben Sie die Chance, an modernen Systemen zu arbeiten, die globale Teams unterstützen und gleichzeitig zur Sicherheit und Effizienz des Unternehmens beitragen.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Senior Security Engineer - Cloud Security erhalten könntest
✨Werde sichtbar in der IT-Sicherheits-Community
In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Nasuni kennenzulernen!
✨Kollaboriere an Open-Source-Projekten
Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.
✨Nutze spezielle Jobportale für IT-Sicherheit
Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Nasuni zu bewerben!
✨Halte deine Skills up-to-date
In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Nasuni.
Wir glauben, dass du diese Fähigkeiten brauchst, um Senior Security Engineer - Cloud Security mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.
Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.
Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!
Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!
Wie man sich auf ein Vorstellungsgespräch bei Nasuni vorbereitet
✨Sicherheitsprotokolle dominiert!
Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Nasuni könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!
✨Praktische Erfahrung zählt!
Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Nasuni sucht nach jemandem, der die Theorie auch anwenden kann!
✨Teamarbeit nicht vergessen!
IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!
✨Motivation und Lernbereitschaft zeigen!
Da es sich um eine Vollzeitstelle handelt, wird Nasuni auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!