Cloud Security Engineer

Flowaccount โ€” Thailand ยท Posted ~1 day ago

๐Ÿ”“ Log in to save this job, tailor your resume & track your apply process โ€” 7 days free, no card needed.

Log in to add to target list

Description

Role Overview This is a builder-operator position requiring a combination of technical engineering and operational excellence. Success in this role is defined by a fully managed and secured endpoint environment, the implementation of short-lived credentialing for engineering workflows, and the establishment of robust monitoring and alerting systems. You will ensure that ISO 27001 controls are integrated into daily operations, facilitating efficient evidence collection for audits. Working alongside external security partners and our internal DevOps team, you will serve as the primary technical lead for security implementation. Key Responsibilities Endpoint Security Management โ€” Direct the deployment and optimization of the security stack across the Mac and Windows fleet. Manage MDM baselines, EDR configuration, and the triage of escalations from managed detection services.Cloud Security Operations โ€” Maintain least-privilege IAM principles across AWS and GCP environments. Implement SSO, hardware-based MFA, and manage service account hygiene, secrets, and cloud governance guardrails.Detection Engineering โ€” Centralize telemetry from cloud audit logs, endpoints, and networks. Develop and maintain high-fidelity alerting for critical security events, including unauthorized IAM changes and anomalous data egress.Incident Response โ€” Serve as the primary responder for security incidents. Conduct investigations, execute containment strategies, and produce comprehensive post-incident reviews while maintaining updated runbooks.ISMS Operations โ€” Operationalize ISO 27001 controls through automation. Facilitate evidence collection, conduct periodic access reviews, and manage corrective actions to support internal and external audits.Security SDLC Integration โ€” Collaborate with engineering teams to integrate security into the development lifecycle. Implement secret scanning, dependency analysis, and conduct security reviews for high-risk architectural changes.Security Culture & Advocacy โ€” Lead security awareness initiatives and phishing simulations. Act as a subject matter expert and accessible resource for security-related inquiries across the organization. What We're Looking For Required: 3+ years hands-on security or DevOps/infrastructure experience with meaningful security ownership โ€” title matters less than what you've operatedWorking proficiency with at least one major cloud (AWS or GCP): IAM, audit logging, and security tooling (GuardDuty, Security Command Center, or equivalents)Experience deploying or administering endpoint management/EDR tooling across a fleet (any of: Intune, Jamf, Kandji, CrowdStrike, SentinelOne, Defender)Scripting ability for automation (Python, Bash, or PowerShell) โ€” enough to glue systems together and automate evidence collectionYou can investigate an incident: read logs, build a timeline, distinguish evidence from assumption, and write it up clearlyThai and English working proficiency Nice to have: ISO 27001 exposure from the inside โ€” you've lived through an audit, owned controls, or closed nonconformitiesPDPA familiarity, or GDPR experience that translatesExperience at a SaaS or fintech companyInfrastructure-as-code experience (Terraform) for codifying security baselinesCertifications like AWS Security Specialty, ISO 27001 LA/LI, GIAC, or CISSP โ€” valued, never required What We Offer Build products used by tens of thousands of businesses.Ship code that reaches customers quickly.High ownership with minimal bureaucracy.Learn from experienced engineers and product leaders.Flexible work hours and 45 days/year work from anywhere.Competitive compensation, health & accident insurance from day one.17โ€“19 public holidays, 12 personal leave days, and 8 annual leave days.A friendly, collaborative team that genuinely enjoys building together.Clear opportunities to grow your career as the company scales. Location BKK BangRak Office (MRT Samyan or BTS Saladaeng) Why join us: ๐Ÿš€ Work with a modern tech stack | ๐Ÿ’ก Impact thousands of users | ๐Ÿค Collaborative, growth-oriented team