This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for a top-tier Enterprise Cloud Security Engineer to design and secure the cloud infrastructure supporting the next phase of sustainable air mobility. You are a collaborative, hands-on professional with excellent communication skills and the ability to see the big picture. In this role, you will be responsible for securing our cloud-native environments (AWS/Azure) and ensuring that our telemetry, flight operations, and enterprise systems are protected against advanced persistent threats. You will connect DevOps and Security by incorporating "secure-by-design" principles into our Infrastructure as Code (IaC) and CI/CD pipelines, while ensuring compliance with aviation and federal standards (NIST CSF, 800-53, FedRAMP, DO-326A).
Job Responsibility:
Design, implement, and maintain secure cloud architectures across AWS and Azure
Lead the security review and automated scanning of IaC templates (Terraform, CloudFormation, Helm)
Secure containerized workloads and orchestration platforms (EKS/AKS)
Map cloud security controls to industry frameworks, including NIST SP 800-53, ISO 27001, and aviation-specific standards like DO-326A
Build high-fidelity detection rules for cloud threats using SIEM/SOAR platforms
safeguard critical flight telemetry and sensitive data pipelines through robust encryption, key management (KMS/HSM), and data loss prevention (DLP) strategies
Requirements:
5+ years of experience in Cloud Security, DevSecOps, or Infrastructure Engineering, with at least 3 years focused on public cloud (AWS, Azure, and GCP)
Deep hands-on expertise with Terraform, Kubernetes, and Linux environments
Proficiency in Python, Go, or Bash for automating security tasks and building custom tooling
Experience implementing and tuning CSPM/CNAPP tools (e.g., Wiz, Prisma Cloud, Orca, Sysdig) and SIEM platforms (Tenex, Splunk, Datadog Security)
Working knowledge of NIST CSF, NIST 800-53, or FedRAMP requirements
Nice to have:
Familiarity with DO-326A (Airworthiness Security), ITAR regulations, or safety-critical systems