This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Bloomreach is building the world’s premier agentic platform for personalization. We’re revolutionizing how businesses connect with their customers, building and deploying AI agents to personalize the entire customer journey. We're taking autonomous search mainstream, making product discovery more intuitive and conversational for customers, and more profitable for businesses. We’re making conversational shopping a reality, connecting every shopper with tailored guidance and product expertise — available on demand, at every touchpoint in their journey. We're designing the future of autonomous marketing, taking the work out of workflows, and reclaiming the creative, strategic, and customer-first work marketers were always meant to do. And we're building all of that on the intelligence of a single AI engine — Loomi AI — so that personalization isn't only autonomous…it's also consistent. From retail to financial services, hospitality to gaming, businesses use Bloomreach to drive higher growth and lasting loyalty. We power personalization for more than 1,400 global brands, including American Eagle, Sonepar, and Pandora.
Job Responsibility:
owns current and target-state data architectures and reporting
designing, implementing, and monitoring cloud (AWS/GCP) infrastructure security controls
deploying, securing, configuring, and operating SIEM and other security resources
identifying, triaging, and remediating infrastructure and web vulnerabilities
leading incident triage and external-researcher engagement
mentoring junior staff
Requirements:
6+ years of relevant experience
proficiency in cloud security, network security, URL filtering, common security frameworks, and CVE lifecycle management
practical IaC and scripting for automation
strong cross-functional and external communication
experience mentoring junior staff
Hands-on cloud security for AWS and GCP: design secure architectures, perform threat modeling, apply platform-native controls, and build/validate secure IaC
SIEM ownership and detection engineering: deploy, configure, tune, and maintain SIEM
author and test detection rules and playbooks
integrate data sources
and operate with SLA-driven alerting and incident workflows
Vulnerability and incident lifecycle ownership: identify, triage, and remediate infrastructure and web vulnerabilities
Drive CVE lifecycle management and patching: perform root cause analysis and measure MTTR and remediation rates
Network, web, and endpoint protections: design and manage firewalls, WAFs, cloud network controls, URL/web filtering, with demonstrable operational experience
Secure automation and tooling: author automation for detection, alert enrichment, and remediation
build or extend security tooling using scripting or languages such as Python, Go, or Bash
Infrastructure as code and secure CI pipelines: implement guardrails and policy-as-code in CI/CD pipelines, perform static IaC scanning, and enforce security baselines before deployment
Detection, telemetry, and observability: define logging and telemetry requirements, ensure coverage for critical assets, and validate detection efficacy and alert fidelity
Security standards, playbooks, and enforcement: develop, document, and operationalize organization-wide security standards, runbooks, and playbooks
partner with engineering pillars to ensure adoption
Threat-informed defensive engineering: apply threat modeling and adversary-focused testing to guide controls, detection, and resilient designs
Cross-functional and external communication: communicate clearly with engineering teams, leadership, external researchers, and customers
lead vulnerability disclosure and researcher engagement
Mentorship and prioritization: mentor junior engineers, prioritize security projects based on risk and business impact, and drive continuous improvement of infrastructure security posture
Familiarity with frameworks and common weaknesses: working knowledge of CIS/NIST, common security libraries and controls, and typical flaws exploited in infrastructure and web applications
Nice to have:
AWS Certified Security
Google Professional Cloud Security Engineer
Splunk Certified Admin or Splunk Certified Enterprise Security Admin
CISSP (Certified Information Systems Security Professional)
Certified Cloud Security Professional (CCSP)
Cloud Security Alliance CCSK
What we offer:
A great deal of freedom and trust
flexible working hours
work virtual-first with several Bloomreach Hubs available across three continents
company events
5 paid days off to volunteer
People Development Program
communication coach
Leader Development Program
$1,500 professional education budget
Employee Assistance Program
Subscription to Calm
‘DisConnect’ days
sports, yoga, and meditation opportunities
extended parental leave up to 26 calendar weeks for Primary Caregivers