Lead Cloud Security Engineer
23
5758 - 7792 €/mėn.
Prieš mokesčius
Darbo aprašymas:
We are building a new team for a new digital bank from scratch! The new security team will ensure resilience of the bank.
As a Lead Cloud Security Engineer, You will secure our Azure cloud platform and k8s environments. We are Azure-first and operate in a regulated financial-services environment, so secure-by-default, auditability, and resilience are baseline expectations.
Every day, you’ll be #closer and:
Cloud platform security
- Secure-by-default Azure landing zones: network segmentation, private endpoints, Entra ID identity and least-privilege/entitlement management (CIEM), and secrets management (Key Vault).
- Cloud posture and workload protection via CNAPP / CSPM (Microsoft Defender for Cloud and/or Wiz, Orca, Prisma Cloud) — continuous misconfiguration detection and remediation.
Kubernetes & container security
- Harden AKS and the cluster surface: RBAC, Pod Security Standards, admission control (OPA Gatekeeper/Kyverno), network policies, and namespace isolation.
- Secure the container supply chain: image scanning, signing and provenance, trusted registries, and hardened base images.
- Runtime workload protection and secure secrets handling in-cluster.
Cross-cutting
- Get cloud, cluster, and application signals into the SIEM (e.g., Microsoft Sentinel) and support incident response — partnering with detection/IR rather than owning the SOC.
- Secure vendor and integration architecture (API gateways, Zero Trust boundaries) for our external ecosystem.
- DORA and regulatory assurance — ICT risk, ICT third-party / supply-chain risk, resilience and threat-led penetration testing (TLPT) support — and clear risk communication to engineering, leadership, and auditors.
Reikalavimai:
- Hands-on Azure cloud security in production — not just reviewing environments.
- Strong Kubernetes and container security: AKS hardening, RBAC, Pod Security Standards, admission control, network policies, and image/supply-chain security.
- Infrastructure as Code and scripting (Python, PowerShell, or similar) — you automate guardrails rather than enforce them by hand.
- Identity, least privilege, and secrets management in Entra ID; CNAPP / CSPM tooling experience.
- Ability to communicate cloud and pipeline risk to technical and non-technical stakeholders, including auditors.
Privalumai
- Multi-cloud awareness (AWS / GCP) beyond Azure.
- SIEM and cloud detection experience (Microsoft Sentinel).
- Application security awareness — OWASP Top 10, OAuth2 / OIDC, FAPI 2.0 — enough to partner with product security.
- Financial services / fintech / open-banking background.
- DORA or equivalent financial-regulatory familiarity (NIS2, PCI DSS, ISO 27001, NIST CSF).
Įmonė siūlo:
- The green light for your ideas. Your suggestions will be heard — we value independence, curiosity, and initiative.
- A manager who helps you grow. You’ll get clear direction and support while having plenty of freedom to act, learn, and develop.
- An organisation that is changing. Joining Artea means more than just a new name — it means new ideas, perspectives, and opportunities to help shape our culture from within.
- Achievements rooted in Lithuania. We’re especially proud to be a Lithuanian bank. We believe our country and our people are unique, and we do everything we can every day to help them realise their potential.
- A personal benefits package. Health insurance, a pension savings programme, additional days off, flexible working hours, modern infrastructure — and that’s far from the complete list of benefits!
- Performance bonuses. Our employees can earn bonuses based on the performance of the bank, their team, and their own individual performance.
Miestas:
Vilnius
Nuotolinis darbas:
Ne
Laikas:
Visa darbo diena
Galioja iki:
2026.11.02
Kandidatavimas vyks Artea bankas, AB įmonės puslapyje
Persiųsti