Unlock Full Resume Report

New offer - be the first one to apply!

September 21, 2026

Cloud Security Engineer

Senior • Hybrid

Prague, Czech Republic

Quick Facts

  • Hands-on build-and-run cloud security posture role (identity, endpoint, workloads, data)
  • Focus on hardening against CIS benchmarks, closing posture findings, and producing audit evidence
  • Collaborates with Security Architect and SOC

Description

Build-and-run Cloud Security Engineer responsible for implementing and operating the group’s cloud security posture across identity, endpoint, cloud workloads, and data. You will harden subscriptions and the productivity tenant against CIS benchmarks, deploy and tune controls and compliance baselines, and close security posture-management findings while providing evidence for NIS2 audits. The role reports to the Detection and Response Lead and works with Security Architecture and SOC.

Responsibilities

  • Harden cloud subscriptions and the productivity tenant against CIS benchmarks and an internal baseline
  • Triage and close cloud security posture management recommendations; track exceptions and risk acceptances
  • Operate and tune conditional access, privileged identity management, and identity-protection policies
  • Deploy and maintain endpoint compliance policies, security baselines, and patch automation across the managed fleet
  • Implement attack-surface-reduction rules and manage the audit-to-block lifecycle
  • Review Infrastructure-as-Code for security; rotate keys and enforce secret hygiene
  • Provide evidence for NIS2 audits (control state, configuration history, exception register)
  • Convert approved designs (ADRs) into deployed, working controls; provide feedback for adjustments
  • Partner with the SOC to onboard new data sources and respond to control-related findings from incidents

Requirements

  • 4+ years in cloud security engineering on a major cloud stack
  • Hands-on depth in cloud identity (conditional access, PIM), endpoint management, cloud security posture management, and CIS benchmark application
  • Comfort with Infrastructure-as-Code (Terraform, Bicep, or equivalent) and at least one scripting language (PowerShell, Python)
  • Demonstrable experience closing security posture findings at scale with measured posture-score improvement
  • Practical understanding of NIS2 obligations or an equivalent regulatory regime
  • English at least B2
  • Methodical and detail-oriented with rigorous exception and evidence tracking
  • Automation-minded; prefers code over click-ops
  • Good documentation habits to maintain an audit trail others can follow
  • Collaborative working style with IT Operations and the Security Architect

Benefits

  • Flexible working hours and working from home
  • Full flexibility and ownership/accountability
  • 25 days of holiday per year and 6 sick days per year
  • 13th salary possibility after probation
  • Meal vouchers; cafeteria/pension scheme; MultiSport card
  • Language courses and transportation allowance
  • Relocation package for former field employees; possibility of sabbatical/missions once per 3 years
  • Free refreshments, dog/baby friendly office, and team/family events

Similar jobs you might like