Role description and responsibilities
Damia Group is an international tech recruitment agency with 3 decades of experience. Our arrival in Portugal, 7 years later, was set on a mission to transform IT recruitment experiences and, through them, achieve better results. We believe in long-term relationships with a transparent and relaxed mindset. In a short period, we have reached the hearts of both scale-ups and larger organisations by delivering spot-on curated candidate shortlists, increased job offer acceptance rates and shorter time-to-fill.
About the role: As a Principal Cloud Security Engineer, the successful candidate will partner with DevOps and CI/CD engineers and their Architects team to ensure security best practices are embedded across the company's cloud infrastructure.
The Cloud Security team is a collaborative group of talented cloud security engineers working in close partnership with the engineering, platform, and trust & security teams. They are on a mission to safeguard the privacy and security of the company and its users' data, embedded directly in the heart of product development.
Responsibilities:
- Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organisation
- Use their knowledge of security architecture to help engineers build and securely operate products and services from the ground up
- Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements
- Perform proactive research to identify new threats and attack vectors
- Partner with engineering teams to embed shift-left security practices throughout the software development lifecycle
- Implement and manage cloud and Kubernetes security posture management tooling to continuously monitor and reduce risk across containerised workloads
Requirements
- Proven experience working with AWS and AWS security services in a secure production environment, including IAM, Config, KMS, Secrets Manager, CloudWatch, CloudTrail, and GuardDuty
- Proven experience working closely with engineering teams and supporting them on their path to shifting security left
- Background with infrastructure as code (AWS CDK, CloudFormation, or Terraform), version control and CI tools such as GitLab and GitLab CI
- Hands-on experience with Kubernetes (AWS EKS), containers (Docker, AWS ECS), K8s admission controllers and Supply Chain Security
- Solid understanding of internet and computer network protocols, including TCP/IP, TLS, and VPN
- Good written and verbal communication skills in English
- Collaborative team player with a hands-on, can-do approach to problem-solving
- Currently living in Portugal and legally authorized to work in the country
Nice to have:
- AWS Certified Security – Specialty certification or similar
- General familiarity with AI tools and large language models (e.g., Claude by Anthropic, AWS Bedrock)