InfoSec - Application & Cloud Security Engineer (L2)
Core
Hybrid Application and Cloud Security Engineer supporting secure SDLC, code reviews, threat modeling, AWS account security, and Kubernetes hardening for a cross-border payment infrastructure.
Role type
L2 Application & Cloud Security Engineer
Builds
Secure fintech payment infrastructure and cloud-native services
Domain
Fintech / Cross-border payments / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security fundamentals (OWASP Top 10, TLS/PKI, OAuth/JWT), Cloud security fundamentals (AWS/GCP/Azure), Manual and automated code review, SAST/DAST tooling, Threat modeling, IAM policy analysis, Kubernetes hardening (OPA/Gatekeeper, RBAC), WAF tuning, Vulnerability scanning, Scripting (Python/Go/Bash), Incident triage
Preferred skills
Kubernetes production experience, Infrastructure as Code (Terraform), Bug bounty participation, CTF experience, Security certifications (AWS Security Specialty, OSCP, CKS, CEH)
Technologies
AWS, Kubernetes, OPA, Gatekeeper, Kyverno, AWS WAF, Cloudflare, Python, Go, Bash, Terraform, SAST, DAST, Config, SCPs, GuardDuty, Security Hub
Responsibilities
Perform manual and automated code reviews; Triage and remediate security findings from SAST/DAST/bug bounties; Support threat-modeling sessions; Tune AppSec tooling in CI/CD; Review IAM policies and enforce least privilege; Harden Kubernetes clusters; Tune WAF rules; Run vulnerability scans; Contribute to security automation scripts; Monitor cloud security findings and escalate; Participate in on-call rotation
Seniority
Junior to Mid-level, hands-on IC