Senior Security Engineer

Bloomreach · Slovakia · Engineering

Posted 2026-10-01

Apply for this role →

About the Role

You will serve as a trusted security partner to Engineering, DevOps, and IT, designing and hardening secure AWS environments, securing our containerized and Linux-based workloads, and protecting our corporate infrastructure and identity/access tooling — while partnering closely with our dedicated SOC team on detection and response.

You will act as a key member of the Cloud Security team, owning cloud and corporate infrastructure security architecture, vulnerability remediation, and Splunk administration and data integration, in close partnership with the SOC team, which owns detection content, alerting, playbooks, and incident triage/response.

Your Job Will Be (but not limited to)

Design, implement, and monitor security controls across our AWS cloud infrastructure, applying platform-native services (e.g., IAM, GuardDuty, Security Hub, KMS, VPC/Security Groups, Config) and secure architecture patterns to protect production environments.

Maintain deep working knowledge of the AWS security service landscape, evaluating new and existing services to close coverage gaps and strengthen our security architecture.

Secure our Linux server fleet and containerized workloads (Docker, Kubernetes), including host hardening, image and runtime security, and Kubernetes cluster and workload configuration.

Own the security of our corporate infrastructure, including security configuration and administration of identity and access tooling such as JumpCloud and zero-trust network access tooling such as Twingate.

Administer and integrate Splunk as a data platform — onboarding new log sources, maintaining data pipelines, and supporting platform health and licensing — in partnership with the SOC team, which owns detection content, alerting logic, and playbooks.

Identify, triage, and drive remediation of infrastructure and web application vulnerabilities, partnering with engineering teams to reduce MTTR and improve remediation rates.

Lead CVE lifecycle management and patching efforts, performing root cause analysis and tracking remediation metrics across cloud, corporate, and on-prem systems.

Build and maintain secure automation and tooling for vulnerability remediation and infrastructure hardening using Python, Go, or Bash or similar scripting languages.

Implement security guardrails and policy-as-code within Infrastructure as Code (IaC) and CI/CD pipelines, performing static IaC scanning and enforcing security baselines prior to deployment.

Define logging and telemetry requirements for cloud, container, and corporate infrastructure assets, ensuring the SOC team has the data coverage needed for effective detection.

Develop, document, and operationalize security architecture standards for cloud, container, and corporate infrastructure, partnering with engineering pillars and IT to drive adoption across the organization.

Partner with the SOC team on incident response as a technical subject-matter expert for cloud, container, and corporate infrastructure

Mentor junior security engineers and prioritize security initiatives based on risk and business impact, driving continuous improvement of the organization's cloud and corporate infrastructure security posture.

Professional Experience and Skills Requirements

6+ years of hands-on experience in cybersecurity engineering, with a focus on cloud security, infrastructure security, and system hardening.

Deep, hands-on experience securing AWS environments, including secure architecture design, IAM, and applying native AWS security services (e.g., GuardDuty, Security Hub, KMS, Config, Inspector).

Strong working knowledge of Linux system administration and hardening, and hands-on experience securing containerized environments (Docker and Kubernetes).

Experience securing corporate infrastructure and identity/access tooling, such as JumpCloud, Twingate, or comparable zero-trust/IAM platforms.

Experience administering and integrating Splunk (or comparable data/SIEM platforms) as a log and data pipeline, including onboarding data sources and maintaining platform health.

Demonstrated ownership of the vulnerability and CVE lifecycle, including triage, root cause analysis, patching, and MTTR/remediation-rate reporting.

Proficiency in scripting and automation (Python, Go, or Bash) to build or extend security tooling for hardening and remediation.

Experience implementing policy-as-code and security guardrails within CI/CD pipelines, including static IaC scanning and pre-deployment security baselines.

Working knowledge of common security frameworks (CIS, NIST) and typical weaknesses exploited in infrastructure, containers, and web applications.

Strong cross-functional communication skills, with experience partnering closely with SOC, engineering, and IT teams on shared security outcomes.

Experience mentoring junior engineers and prioritizing security work based on risk and business impact.

Relevant certifications preferred: AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, or CCSK.

Your Success Story Will Be

In the First 30 Days

Develop a foundational understanding of Bloomreach's AWS environment, corporate infrastructure, and existing security controls, including JumpCloud and Twingate configurations.

Become familiar with the Cloud Security team's tooling, current Splunk data integrations, and how the team partners with the SOC on detection coverage.

Review current CVE/vulnerability management processes, IaC pipelines, and security baselines for cloud, container, and Linux environments.

Establish working relationships with Engineering, DevOps, IT, and the SOC team.

Identify quick-win opportunities to strengthen existing hardening, IaC guardrails, or corporate infrastructure configurations.

In the First 60 Days

Independently triage and drive remediation of infrastructure, container, and web vulnerabilities identified through scanning and assessments.

Onboard at least one new data source into Splunk and contribute to maintaining existing data pipelines.

Contribute to IaC security scanning and policy-as-code enforcement within CI/CD pipelines.

Partner with Engineering and IT to close CVE and patching gaps, tracking MTTR and remediation-rate metrics.

Begin mentoring junior team members on cloud and infrastructure security fundamentals.

In the First 90 Days

Own end-to-end security architecture reviews for at least one major AWS workload or corporate infrastructure system, independently identifying risks and driving mitigations.

Demonstrate hands-on ownership of Linux, container, and Kubernetes security hardening for at least one environment.

Propose improvements to security architecture standards or automation based on observed gaps.

Demonstrate consistent ownership of vulnerability and CVE lifecycle management with minimal supervision.

Actively mentor junior engineers and contribute to prioritization of the team's security roadmap.

#LI-HO1

The pay range actually offered will take into account a variety of potential factors considered in compensation, including but not limited to skills, qualifications, geographic location, accomplishments, experience, credentials, internal equity and business needs, and may vary from the range listed above.

Base Salary Range

€38.095—€47.619 EUR

Apply for this role →

← Back to all jobs