All remote jobs

Senior Cloud Security Engineer (f/m/d)

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Remote from
Austria
Salary
Undisclosed
Department
Cybersecurity
Employment
Full Time
Experience
Senior
Published
Apply before
5 Nov 2026
Listing views
42
Application actions
1
Application toolkit

Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

The role, at a glance.

ecosio is seeking a senior cloud security engineer to improve the security posture of AWS, Kubernetes, infrastructure-as-code, and microservices environments. The role combines hands-on implementation of security tooling and controls with threat modeling, misconfiguration remediation, and security automation. It also supports audits, compliance initiatives, and certifications such as ISO 27001 and SOC 2 while partnering with engineering teams and the Security Chapter. Strong practical experience with AWS, Kubernetes, Terraform, GitLab CI, ArgoCD, and a scripting or programming language is central to success.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

4/5
GuidedFull ownership

Communication Load

4/5
IndependentCollaborative
AI insightThis is a senior-level security engineering role requiring deep cloud-native expertise across AWS, Kubernetes, CI/CD, infrastructure automation, and compliance. The engineer must independently identify and mitigate security risks while translating security requirements for varied technical stakeholders.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$165,000
US market range$140k–$195k
AI insightNo actual salary is disclosed, so these are estimated US-market annual base-salary figures in USD for a senior cloud security engineer. Actual compensation may differ substantially based on location, level calibration, company pay practices, and total-rewards structure.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you improve the security posture of an AWS-based Kubernetes platform?

I would begin with an inventory and risk assessment covering IAM, network segmentation, logging, encryption, cluster access, workload identities, image provenance, and secrets management. I would prioritize high-impact controls such as least-privilege IAM, private endpoints where appropriate, admission controls, image scanning, runtime monitoring, centralized audit logs, and policy-as-code integrated into deployment pipelines.

Describe how you would embed security checks into a GitLab CI and Terraform workflow.

I would add automated checks at merge-request and deployment stages, including secret detection, dependency and container scanning, IaC scanning, policy validation, and Terraform plan review. Findings should have clear severity thresholds, block releases only for agreed critical risks, and create actionable remediation guidance so controls support delivery rather than becoming a manual bottleneck.

How do you approach threat modeling for a new microservice?

I define the system boundaries, assets, data flows, identities, trust boundaries, and external dependencies with the engineering team. I then identify likely threats using a structured method such as STRIDE, prioritize them by likelihood and impact, document mitigations, and convert the highest-value controls into design requirements and automated verification where possible.

What evidence would you prepare to support ISO 27001 or SOC 2 audits?

I would maintain evidence showing that controls are designed and operating effectively, such as access reviews, change-management records, vulnerability-management reports, security training records, incident-response exercises, logging configurations, backup tests, and policy attestations. I would automate evidence collection where practical and map each artifact to the relevant control requirements.

How would you explain a critical cloud misconfiguration to both engineers and non-technical stakeholders?

For engineers, I would provide the affected resource, attack path, risk severity, recommended configuration change, and validation steps. For non-technical stakeholders, I would summarize the business impact, likelihood, remediation timeline, ownership, and any residual risk in plain language without unnecessary implementation detail.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.
Opportunity details

About this role.

Company Description

ecosio is a fast-growing, innovative service company and a leading provider of B2B integration, specialising in electronic data interchange (EDI), Web EDI and e-invoicing. ecosio is part of Vertex, Inc., a leading global provider of indirect tax solutions listed on Nasdaq (VERX).

Our brand slogan is Connections That Work as we believe strong connections are central to successful business relationships – both external and internal. At ecosio, we hire individuals from all backgrounds and are committed to creating an inclusive work environment. We are technology lovers, set the highest standards for our solutions, and put innovative ideas first.

Job Description

You’ll connect with the role if you enjoy…

  • Identifying, implementing, and integrating security tools and controls to strengthen AWS and Kubernetes security posture and support threat modelling
  • Identifying and mitigating security issues and misconfigurations across infrastructure and microservices
  • Supporting audits, compliance initiatives, and security certifications
  • Collaborating with cross-functional teams and the Security Chapter to implement and maintain security standards
  • Working with technologies such as:
    • Infrastructure: Kubernetes, AWS, ArgoCD, Helm, Terraform, HAProxy, GitLab CI
    • Data storage and querying: MongoDB, Redis, Elasticsearch
    • Monitoring and observability: Prometheus


Qualifications

To connect with ecosio it is important to have…

  • Several years of experience as a Cloud Security Engineer, Security Engineer, or in a similar role
  • Strong hands-on experience with cloud security, preferably in AWS environments
  • Experience with at least one programming language such as Bash, Python, Go, Rust, or Java
  • Experience with automation and infrastructure tools such as Docker, Kubernetes, GitLab CI, ArgoCD, and Terraform
  • Up-to-date knowledge of modern cybersecurity threats, risk assessment techniques, security best practices, and compliance frameworks such as ISO 27001 and SOC 2
  • Strong communication skills with the ability to explain concepts such as scalability, automation, and security to different audiences

Additional information

By connecting with us you will experience…

  • Our remote-first culture lets you work remotely from one of our designated countries
  • Flexible working hours to suit your schedule and priorities
  • Annual personal development budget to invest in conferences, courses, or career coaching
  • Home office allowance to create a workspace that fits your needs
  • Regular events and trips to connect, celebrate, and have fun with the team
  • Workations of up to 90 days per year within the EU, combining travel and productivity
  • Wellbeing support, including mental health resources and employee assistance programs
  • Additional country-specific benefits based on your location

Sounds like a connection that works? Then apply now and we will get in touch soon!

As part of our hiring process at ecosio, we conduct standard background checks. You can find more information about them by clicking HERE.

Our mission is to build Connections That Work by fostering a diverse and inclusive team. We are committed to making everyone feel valued and empowered to contribute their unique skills, experiences and perspectives. And now we want to connect with you.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. .

Log in to save
One quick step before you apply

Sign in to continue.

Sign in or create a free account to continue to the employer's application.

Applying is free. After signing in, return to this job and select Apply Now.
Add alert
Jobs Talent AI Tools Salaries
Menu