SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: CZK 858,667 - 1,073,333 / annual
BloomReach is building an agentic platform for personalization, using AI agents to personalize the entire customer journey. The company powers personalization for over 1,400 global brands including American Eagle, Sonepar, and Pandora.
You will serve as a trusted security partner to Engineering, DevOps, and IT, designing and hardening secure AWS environments, securing containerized and Linux-based workloads, and protecting corporate infrastructure and identity/access tooling. You will act as a key member of the Cloud Security team, owning cloud and corporate infrastructure security architecture, vulnerability remediation, and Splunk administration and data integration, in close partnership with the SOC team.
Key responsibilities include:
- Design, implement, and monitor security controls across AWS cloud infrastructure using platform-native services (IAM, GuardDuty, Security Hub, KMS, VPC/Security Groups, Config)
- Maintain deep working knowledge of the AWS security service landscape and evaluate new services to close coverage gaps
- Secure Linux server fleet and containerized workloads (Docker, Kubernetes), including host hardening, image and runtime security
- Own security of corporate infrastructure, including JumpCloud and zero-trust network access tooling like Twingate
- Administer and integrate Splunk as a data platform, onboarding log sources and maintaining data pipelines in partnership with the SOC team
- Identify, triage, and drive remediation of infrastructure and web application vulnerabilities
- Lead CVE lifecycle management and patching efforts with root cause analysis and remediation metrics tracking
- Build and maintain secure automation and tooling for vulnerability remediation using Python, Go, or Bash
- Implement security guardrails and policy-as-code within Infrastructure as Code (IaC) and CI/CD pipelines
- Define logging and telemetry requirements for cloud, container, and corporate infrastructure assets
- Develop and operationalize security architecture standards for cloud, container, and corporate infrastructure
- Partner with the SOC team on incident response as a technical subject-matter expert
- Mentor junior security engineers and prioritize security initiatives based on risk and business impact
First 30 days: Develop foundational understanding of BloomReach's AWS environment, corporate infrastructure, and existing security controls. Become familiar with Cloud Security team tooling and Splunk integrations. Review CVE/vulnerability management processes and IaC pipelines. Establish working relationships with Engineering, DevOps, IT, and SOC teams. Identify quick-win opportunities.
First 60 days: Independently triage and drive remediation of infrastructure, container, and web vulnerabilities. Onboard at least one new data source into Splunk. Contribute to IaC security scanning and policy-as-code enforcement. Partner with Engineering and IT on CVE and patching gaps. Begin mentoring junior team members.
First 90 days: Own end-to-end security architecture reviews for major AWS workloads or corporate infrastructure systems. Demonstrate hands-on ownership of Linux, container, and Kubernetes security hardening. Propose improvements to security architecture standards. Demonstrate consistent ownership of vulnerability and CVE lifecycle management. Actively mentor junior engineers.
**Requirements:**
- 6+ years of hands-on experience in cybersecurity engineering, with focus on cloud security, infrastructure security, and system hardening
- Deep, hands-on experience securing AWS environments, including secure architecture design, IAM, and native AWS security services (GuardDuty, Security Hub, KMS, Config, Inspector)
- Strong working knowledge of Linux system administration and hardening, and hands-on experience securing containerized environments (Docker and Kubernetes)
- Experience securing corporate infrastructure and identity/access tooling such as JumpCloud, Twingate, or comparable zero-trust/IAM platforms
- Experience administering and integrating Splunk (or comparable data/SIEM platforms) as a log and data pipeline, including onboarding data sources and maintaining platform health
- Demonstrated ownership of vulnerability and CVE lifecycle, including triage, root cause analysis, patching, and MTTR/remediation-rate reporting
- Proficiency in scripting and automation (Python, Go, or Bash) to build or extend security tooling for hardening and remediation
- Experience implementing policy-as-code and security guardrails within CI/CD pipelines, including static IaC scanning and pre-deployment security baselines
- Working knowledge of common security frameworks (CIS, NIST) and typical weaknesses exploited in infrastructure, containers, and web applications
- Strong cross-functional communication skills, with experience partnering closely with SOC, engineering, and IT teams
- Experience mentoring junior engineers and prioritizing security work based on risk and business impact
- Preferred certifications: AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, or CCSK