SlipstreamJobsFresh Startup & VC-Backed Jobs

Cloud Security Engineer

HappyRobot - Madrid, Spain - In-office - posted 2026-08-06

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

HappyRobot is an AI infrastructure platform backed by a16z and Y Combinator (S23) that enables enterprises to build and orchestrate autonomous AI workforces. The company has raised over $150M and operates across AWS, Azure, and GCP to power critical operations for global enterprises. As Cloud Security Engineer, you will own the complete cloud security posture across all three major cloud providers. This is a hands-on, outcome-focused role where you drive real remediation and hardening—not advisory work. Key responsibilities include: - Cloud Posture Management: Own the CNAPP (Cloud-Native Application Protection Platform) end-to-end using Wiz. Triage findings by exploitability and business impact, drive remediation across engineering teams to SLA, and prevent backlog accumulation. - Infrastructure-as-Code Security: Design and deploy policy-as-code gates in the Terraform pipeline using OPA/Rego, Checkov, tfsec, or equivalent tools. Block misconfigurations at PR and plan time before production deployment, while calibrating gates to avoid friction that causes teams to bypass controls. - Multi-Cloud Baseline: Define and enforce consistent security baselines across AWS, Azure, and GCP covering IAM, networking, KMS/encryption, and logging. Own documentation supporting enterprise security reviews and audit evidence. - Kubernetes & Container Security: Harden EKS, AKS, and GKE clusters. Set and enforce RBAC policies, admission controls, and image scanning standards. - Remediation Leadership: Drive fixes through engineering teams without direct authority. Track SLAs, communicate risk clearly to technical and non-technical stakeholders, and escalate when needed. - Shift-Left Guardrails: Grow Terraform-managed infrastructure with active security checks quarter-over-quarter. Trend critical misconfigurations reaching production toward zero. Required: 4–6 years cloud or platform/infrastructure security experience; expert depth in at least one major cloud provider; hands-on CNAPP/CSPM experience (Wiz preferred); production Terraform and policy-as-code experience; Kubernetes security fundamentals; Python or Go scripting; B2+ English. Nice-to-have: Multi-cloud experience; CCSK, CKA, CKS, or AWS Security Specialty certifications; EKS/AKS/GKE hardening; TypeScript or Go; SIEM/detection exposure; SOC 2/ISO 27001 experience.

Similar roles