Cloud Security Engineer - Platform and Infrastructure

Naviss — Unknown · Posted ~1 week ago

Senior Full-time Hybrid Visa Sponsored

Skills

Kubernetes security AWS security Amazon EKS Container security IAM KMS Cloud networking GuardDuty Security Hub Terraform Security automation CSPM Least-privilege access SSO SAML Vulnerability management Security incident response ISO 27001 SOC 2 Kubernetes AWS Wiz Helm GitOps CI/CD

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary

A hands-on cloud security engineering role focused on protecting Kubernetes platforms, cloud infrastructure, and containerized workloads. You will design security guardrails, enforce least-privilege access, automate hardening and detection, integrate controls into infrastructure delivery pipelines, manage vulnerabilities, support incident response, and contribute to ISO 27001 and SOC 2 compliance efforts. The role offers hybrid flexibility and comprehensive international relocation and visa support.

Highlights

Hands-on cloud security role with significant ownership over Kubernetes and AWS security. Benefits include 30 days of paid time off, flexible hybrid work, full visa and relocation support, wellness and transportation benefits, local language support, and a competitive compensation package.

Description

THE OPPORTUNITY As a Cloud Security Engineer-Platform & Infrastructure at NavVis, you will play a critical role in strengthening our cloud security posture, with a strong focus on Kubernetes and AWS environments. You will own and optimize our Wiz platform, implement security automation, and ensure compliance with ISO 27001 and SOC 2 standards. This is a hands-on role where you will collaborate closely with engineering teams to embed security into our infrastructure and processes. How You Will Make An Impact Take ownership of Kubernetes security across our EKS clusters: design and enforce RBAC, admission controllers, network policies, and pod security standards Harden container workloads through image scanning, runtime threat detection, and workload identity best practices Own and continuously improve our cloud security posture using Wiz, AWS native services and internal monitoring Drive security automation and hardening across AWS, EKS and on-prem infrastructureIntegrate security controls into CI/CD pipelines (Terraform, Helm, GitOps) to prevent misconfigurations early Design and maintain guardrails and detection rules for identity, network and workload security Design and enforce least-privilege IAM and support SSO and SAML workflows Partner closely with engineering teams to secure new services and architectural changes Lead vulnerability management and remediation across cloud assets, containers and applications Support risk assessments, internal security reviews and compliance initiatives (ISO 27001, SOC 2) Investigate and respond to security incidents, driving follow-up improvements Contribute to internal security standards, playbooks and documentation What Will Help You Succeed In The Role Strong hands-on Kubernetes security experience you are comfortable with being the go-to person for Kubernetes security decisions.Experience hardening containerized workloads, including image scanning, runtime security and workload identityStrong hands-on experience with AWS security (IAM, KMS, networking, GuardDuty, Security Hub)Strong Terraform skills and an automation-first mindsetExperience with CSPM and cloud monitoring tools (Wiz is a strong plus)Familiarity with ISO 27001 and SOC 2 control environmentsExperience designing and enforcing least-privilege access models and SSO integrationsConfidence handling security incidents, investigations and documentationExcellent communication and cross-team collaboration skills How We Will Know We Are a Perfect Match Your recruiting partner for this role is Sylvie (she/her). You can expect to go through a screening call, and up to 4 rounds of interviews, where we would love to discover your passion and interests, introduce you to who we are and what drives us, and finally understand how we can potentially add value to each other's growth. How We Will Keep You Smiling It's important to take a break from work! We offer 30 days of paid time off per yearAffordable access to a vast network of fitness and wellness facilities through EGYM Wellpass subsidyDeutschlandticket subsidy to support sustainable travel using public transportWe offer flexible working hours and a hybrid work setup, enabling you to plan your work around your life, and not your life around work!We offer full visa and relocation support for international candidatesAn attractive bike leasing model through JobRad, in line with our commitment towards sustainable mobilityA competitive compensation package that values the skills and experience you bringUp to 4000 EUR employee referral bonus Financial support for local language classes to help you in your journey of integrating into the culture! We derive our strength from our diversity. NavVis’ unwavering commitment to fostering an inclusive and diverse workplace has laid the foundation for our incredible growth. We thrive on the collective strength of our people who come from diverse backgrounds. We respect and value every experience associated with race, gender identity, sexual orientation, nationality, religion and disability. We do not discriminate on the basis of any of these, or other identities, and strongly encourage everyone to apply. Together with you, we build NavVis! If you need assistance at any stage of the recruiting process due to a disability, please reach out to your recruiting partner(s) for this position.