Cloud Security Engineer (DevSecOps)
⚲ Kraków
14 000 - 18 000 PLN brutto (UoP)
Wymagania
- Security
- Cloud
- Firewall
- Linux
- Docker
- Kubernetes
- CI/CD
- Scripting
- CNAPP
Opis stanowiska
The position is part of our Core Platforms & Services (CPS) Cybersecurity organization which operates and manages MSI’s Cloud Public Safety Application SaaS platform. You will be part of a team that is responsible for the security of these mission critical systems that are used everyday by public safety and government agencies across multiple countries. In this role, you will also be working in a world-class team that uses state of the art technologies and techniques. This team is part of Motorola Solutions’ Software Enterprise division, which offers secure, reliable and efficient team communications, workflow and operational intelligence solutions for mission critical public safety and enterprise markets throughout the world.
We are seeking a Cloud Security Engineer / DevSecOps to join our team in protecting organizational cloud assets through robust automated security services. This role focuses on managing cloud security across Motorola Solutions product cloud environments. You will implement proactive vulnerability and threat detection systems while ensuring seamless regulatory compliance across our cloud ecosystem. In this role, you will also be working in a world-class team that uses state of the art technologies and techniques.
Key Responsibilities
• Security Posture Management: Serve as a member of the team responsible for monitoring and assessing the security posture of cloud infrastructure and deployments across AWS, Azure, and GCP.
• Infrastructure Protection: Deploy and maintain security capabilities, including CNAPP, Vulnerability detection, WAF, and firewalls.
• Automation: Develop tools for automated self-verification of security functions and support automated inventory and security alerting.
• Compliance: Support compliance assessments for various industry standards, including NIST 800-53, OWASP, GDPR, ISO, and SOC 2.
• Incident Collaboration: Collaborate on detection rules and assist with incident response, occasionally serving as an Incident Coordinator.
• Continuous Improvement: Stay abreast of security technology evolution and provide recommendations to enhance the overall security posture.
Basic Requirements
• Experience: 3 years of professional experience in software engineering, DevOps, or security engineering within virtualized systems
• Good interpersonal skills and ability to collaborate with a variety of work partners.
• Cloud Platforms: Good understanding of AWS, Azure, and GCP is required, though deep domain expertise is not a prerequisite.
• Cybersecurity: Understanding of cybersecurity and compliance concepts and framework adherence (e.g., NIST, ISO, FedRAMP).
• Containers & Orchestration: Experience with Containerization (Docker) and orchestration using Kubernetes.
• Software Engineering: Ability to develop code and automation scripts in Python, JavaScript/NodeJS, Bash, or Azure CLI.
• CI/CD & DevOps: Knowledge of containerized software deployments using AzureDevOps Pipelines or GitHub Actions.
• Version Control: Knowledge of version control practices (GIT).
• Systems & Monitoring: Basic Linux system administration skills and familiarity with the Elastic stack.
• Network Security: Understanding of network protocols, topologies, and firewall/WAF configuration and use.
• Quick learning: Curiosity and ability to quickly learn new technologies and security practices as the cloud landscape evolves.
Additional Preferred Skills
• Familiarity with tools used to secure cloud and containerized deployments such as Wiz or Prisma Cloud
• Experience with Kyverno policy management.
• Education: A Bachelor's or Master’s degree in computer science, software engineering or a related field
In return for your expertise, we’ll support you in this new challenge with coaching & development every step of the way. Also, to reward your work, you’ll get the following:
• Contract of Employment (UoP)
• IP Tax Relief (up to 40%)
• Private medical coverage, Multisport
• Life insurance (two annual incomes),
• Employee Stock Purchase Plan – 15% discount for buying Motorola’s Stock units,
• Employee Pension Plan – 3,5 % of the month’s salary gross, which goes to the retirement account
• Yearly salary increase (depends on individual performance)
• Yearly bonus (depends on company performance)
• 8 hours working day (30 minutes lunch break included).
• Hybrid work / remote work
We are seeking a Cloud Security Engineer / DevSecOps to join our team in protecting organizational cloud assets through robust automated security services. This role focuses on managing cloud security across Motorola Solutions product cloud environments. You will implement proactive vulnerability and threat detection systems while ensuring seamless regulatory compliance across our cloud ecosystem. In this role, you will also be working in a world-class team that uses state of the art technologies and techniques.
Key Responsibilities
• Security Posture Management: Serve as a member of the team responsible for monitoring and assessing the security posture of cloud infrastructure and deployments across AWS, Azure, and GCP.
• Infrastructure Protection: Deploy and maintain security capabilities, including CNAPP, Vulnerability detection, WAF, and firewalls.
• Automation: Develop tools for automated self-verification of security functions and support automated inventory and security alerting.
• Compliance: Support compliance assessments for various industry standards, including NIST 800-53, OWASP, GDPR, ISO, and SOC 2.
• Incident Collaboration: Collaborate on detection rules and assist with incident response, occasionally serving as an Incident Coordinator.
• Continuous Improvement: Stay abreast of security technology evolution and provide recommendations to enhance the overall security posture.
Basic Requirements
• Experience: 3 years of professional experience in software engineering, DevOps, or security engineering within virtualized systems
• Good interpersonal skills and ability to collaborate with a variety of work partners.
• Cloud Platforms: Good understanding of AWS, Azure, and GCP is required, though deep domain expertise is not a prerequisite.
• Cybersecurity: Understanding of cybersecurity and compliance concepts and framework adherence (e.g., NIST, ISO, FedRAMP).
• Containers & Orchestration: Experience with Containerization (Docker) and orchestration using Kubernetes.
• Software Engineering: Ability to develop code and automation scripts in Python, JavaScript/NodeJS, Bash, or Azure CLI.
• CI/CD & DevOps: Knowledge of containerized software deployments using AzureDevOps Pipelines or GitHub Actions.
• Version Control: Knowledge of version control practices (GIT).
• Systems & Monitoring: Basic Linux system administration skills and familiarity with the Elastic stack.
• Network Security: Understanding of network protocols, topologies, and firewall/WAF configuration and use.
• Quick learning: Curiosity and ability to quickly learn new technologies and security practices as the cloud landscape evolves.
Additional Preferred Skills
• Familiarity with tools used to secure cloud and containerized deployments such as Wiz or Prisma Cloud
• Experience with Kyverno policy management.
• Education: A Bachelor's or Master’s degree in computer science, software engineering or a related field
In return for your expertise, we’ll support you in this new challenge with coaching & development every step of the way. Also, to reward your work, you’ll get the following:
• Contract of Employment (UoP)
• IP Tax Relief (up to 40%)
• Private medical coverage, Multisport
• Life insurance (two annual incomes),
• Employee Stock Purchase Plan – 15% discount for buying Motorola’s Stock units,
• Employee Pension Plan – 3,5 % of the month’s salary gross, which goes to the retirement account
• Yearly salary increase (depends on individual performance)
• Yearly bonus (depends on company performance)
• 8 hours working day (30 minutes lunch break included).
• Hybrid work / remote work
🔍 Dekoder Ogłoszenia
🟡
world-class team that uses state of the art technologies and techniques
Może oznaczać zarówno faktycznie innowacyjny zespół, jak i po prostu standardowe narzędzia i metodyki stosowane w branży.
🟡
robust automated security services
Może oznaczać zaawansowane rozwiązania, ale też po prostu podstawowe skrypty automatyzujące powtarzalne zadania.
🟡
seamless regulatory compliance
Może oznaczać łatwe i bezproblemowe spełnianie wymogów, ale też po prostu konieczność ciągłego monitorowania i dostosowywania się do zmieniających się przepisów.
🟡
proactive vulnerability and threat detection systems
Może oznaczać zaawansowane systemy wykrywania, ale też standardowe narzędzia skanujące i monitorujące.