SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: EUR 38,095 - 47,619 / annual
BloomReach is building an agentic platform for personalization, using AI agents to personalize the entire customer journey. The company powers personalization for over 1,400 global brands including American Eagle, Sonepar, and Pandora.
You will serve as a trusted security partner to Engineering, DevOps, and IT, designing and hardening secure AWS environments, securing containerized and Linux-based workloads, and protecting corporate infrastructure and identity/access tooling. You will act as a key member of the Cloud Security team, owning cloud and corporate infrastructure security architecture, vulnerability remediation, and Splunk administration in close partnership with the SOC team.
Key responsibilities include:
- Design, implement, and monitor security controls across AWS cloud infrastructure using platform-native services (IAM, GuardDuty, Security Hub, KMS, VPC/Security Groups, Config)
- Maintain deep knowledge of the AWS security service landscape and evaluate new services to close coverage gaps
- Secure Linux server fleet and containerized workloads (Docker, Kubernetes) including host hardening, image and runtime security
- Own security of corporate infrastructure including JumpCloud and Twingate configurations
- Administer and integrate Splunk as a data platform, onboarding log sources and maintaining data pipelines
- Identify, triage, and drive remediation of infrastructure and web application vulnerabilities
- Lead CVE lifecycle management and patching efforts with root cause analysis
- Build and maintain secure automation using Python, Go, or Bash
- Implement security guardrails and policy-as-code within Infrastructure as Code and CI/CD pipelines
- Define logging and telemetry requirements for cloud, container, and corporate infrastructure
- Develop and operationalize security architecture standards
- Partner with SOC team on incident response as a technical subject-matter expert
- Mentor junior security engineers and prioritize security initiatives based on risk and business impact
First 30 days: develop foundational understanding of BloomReach's AWS environment, corporate infrastructure, and existing security controls; become familiar with Cloud Security team tooling and Splunk integrations; review CVE/vulnerability management processes and IaC pipelines; establish working relationships with Engineering, DevOps, IT, and SOC teams; identify quick-win opportunities.
First 60 days: independently triage and drive remediation of infrastructure vulnerabilities; onboard new data sources into Splunk; contribute to IaC security scanning and policy-as-code enforcement; partner on CVE and patching gaps; begin mentoring junior team members.
First 90 days: own end-to-end security architecture reviews for major AWS workloads; demonstrate hands-on ownership of Linux, container, and Kubernetes security hardening; propose improvements to security architecture standards; demonstrate consistent ownership of vulnerability and CVE lifecycle management; actively mentor junior engineers.
**Requirements:**
- 6+ years of hands-on experience in cybersecurity engineering with focus on cloud security, infrastructure security, and system hardening
- Deep, hands-on experience securing AWS environments including secure architecture design, IAM, and native AWS security services (GuardDuty, Security Hub, KMS, Config, Inspector)
- Strong working knowledge of Linux system administration and hardening, and hands-on experience securing containerized environments (Docker and Kubernetes)
- Experience securing corporate infrastructure and identity/access tooling such as JumpCloud, Twingate, or comparable zero-trust/IAM platforms
- Experience administering and integrating Splunk or comparable data/SIEM platforms as a log and data pipeline, including onboarding data sources and maintaining platform health
- Demonstrated ownership of vulnerability and CVE lifecycle including triage, root cause analysis, patching, and MTTR/remediation-rate reporting
- Proficiency in scripting and automation (Python, Go, or Bash) to build or extend security tooling
- Experience implementing policy-as-code and security guardrails within CI/CD pipelines, including static IaC scanning and pre-deployment security baselines
- Working knowledge of common security frameworks (CIS, NIST) and typical weaknesses exploited in infrastructure, containers, and web applications
- Strong cross-functional communication skills with experience partnering with SOC, engineering, and IT teams
- Experience mentoring junior engineers and prioritizing security work based on risk and business impact
- Preferred certifications: AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, or CCSK