This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Aurora’s Cloud Security team’s mission is to design and build security capabilities for Aurora infrastructure and services. Aurora makes extensive use of public cloud infrastructure (AWS), Kubernetes and infrastructure-as-code technologies. This role requires a deep, hands-on understanding of cloud security principles and architecture, particularly within AWS and Kubernetes (EKS). As a Senior Engineer, you will own the design and implementation of key security infrastructure, serving as a key technical contributor and mentor within the security team and across engineering.
Job Responsibility:
Design, implement, and maintain the next generation of security infrastructure, controls, and primitives natively within AWS and across our Kubernetes (EKS) platform
Define Security as Code: Drive the adoption of Infrastructure as Code (IaC) principles (e.g., Terraform) to codify, deploy, and continuously monitor security controls and policies in an auditable and scalable manner
Strategic Threat Modeling: Lead threat modeling exercises for critical systems and architectures, translating risks into prioritized security requirements and verifiable controls
Architectural Guidance: Provide security guidance and consulting for product and platform engineering teams, conducting in-depth security design reviews and providing pragmatic, hands-on recommendations for securing complex microservice architectures
Automate Remediation: Identify systemic security weaknesses and create robust, scalable automation (e.g., Python/Go-based tools, Lambda functions, EKS controllers) to eliminate classes of vulnerabilities at the source
Requirements:
5+ years of progressive experience in software, platform, or security engineering
Minimum of 3+ years focusing exclusively on public cloud security (AWS required)
Experience in identifying and managing security risk
Expert-level, hands-on experience securing and operating complex environments in AWS, including expertise with IAM, VPC Networking, Security Hub, Config, GuardDuty, and KMS
Proven ability to design and implement security controls for Kubernetes (EKS), including strong knowledge of authorization models, admission controllers, and security best practices
Expertise in one or more Identity and Access Management (IAM) standards and technologies: PKI, OAuth2/OIDC, SAML, and commercial solutions like Okta
Strong proficiency in at least one modern programming/scripting language (e.g., Python or Go) for building security automation, tools, and remediation services
Experience writing, reviewing, and scaling infrastructure with Terraform
Nice to have:
Deep fundamental understanding of enterprise-level network security, operating system security (Linux), and application security principles
Experience implementing DevSecOps practices, including integration of security testing (SAST/DAST/SCA) into CI/CD pipelines (e.g., GitLab, Jenkins)
Familiarity with compliance frameworks (e.g., SOX, SOC 2, ISO 27001)