Senior Cloud Security Engineer
Hello, let’s meet!
Xebia is a global AI-first, digital transformation, and engineering partner. With over 25 years of experience and a team of 5,000 professionals across 16 countries, we help organizations design and build scalable products, platforms, and data-driven solutions.
We specialize in Artificial Intelligence, Data and Cloud, Intelligent Automation, and Digital Products, combining deep technical expertise with a strong focus on engineering excellence and a people-first culture.
In the CEE region, we’re a team of nearly 1,000 experts delivering modern applications, data platforms, and AI solutions for clients such as Millennium, ING, Play, Edenred, Arabian Drilling, FedEx, Leroy Merlin, Truecaller, Volotea, Schmitz Cargobull, and many, many more.
You will be:
- assessing and documenting the security posture of cloud-based SaaS and on-premises services,
- organizing and coordinating penetration tests, code scanning, cloud infrastructure scanning, and pipeline security assessments,
- identifying security gaps and helping teams prioritize and remediate security risks,
- establishing standardized minimum security requirements across products and development teams,
- driving the adoption of Security by Design principles across cloud and application environments,
- defining and improving cloud security practices for Azure-based and hybrid environments,
- integrating security controls and scanning practices into development and CI/CD processes,
- supporting the development of a security roadmap and driving continuous security improvements across the organization.
Your profile:
- strong experience in Cloud Security and Application Security,
- practical experience using AI-powered assistants (e.g. Claude Code, GitHub Copilot, Cursor) to improve productivity, quality, or decision-making in software delivery,
- strong hands-on experience securing Microsoft Azure environments and workloads,
- experience securing hybrid infrastructure, particularly on-premises environments integrated with Azure,
- good understanding of AWS security services and best practices,
- experience with cloud security architecture and governance, including Azure Cloud Adoption Framework (CAF) and Well-Architected Framework (WAF),
- a good understanding of Windows-based environments and enterprise infrastructure,
- hands-on experience with vulnerability management, security assessments, security scanning, penetration testing coordination, threat modelling, and risk assessment,
- experience implementing Security by Design principles across cloud and application environments,
- experience integrating security controls and scanning into CI/CD and DevSecOps processes,
- familiarity with Azure DevOps, GitHub Actions, and GitLab CI/CD,
- strong knowledge of modern security frameworks and best practices,
- excellent communication and stakeholder management skills and can translate technical security topics into business language,
- strong workshop facilitation and consulting mindset and can influence teams without direct authority,
- experience creating security strategies or operating models at organizational level as an advantage,
- experience with .NET environments, Terraform or other Infrastructure as Code tools, and container/Kubernetes security as a plus,
- relevant certifications such as CISSP, CCSP, AZ-500, SC-100, or AWS Security Specialty as an advantage,
- fluent English (at least B2 level).
Work from the European Union region and a work permit are required.
Recruitment Process:
CV review – HR call – Interview – Team / Client Interview – Decision
Create a Job Alert
Interested in building your career at Poland and Middle-Eastern Europe? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field
.png?1773750017)