Cloud Security Engineer
ROLE SUMMARY
Cloud Security Engineering
- Implement and enhance security controls across AWS, Azure and/or GCP following established engineering patterns and standards.
- Build and maintain secure Infrastructure as Code using Terraform, OpenTofu or similar tools.
- Contribute to development of reusable secure cloud modules, guardrails and reference architectures.
- Assist in designing secure, scalable and resilient cloud environments aligned to enterprise best practices.
Automation & Tooling
- Develop and maintain security automation workflows using Python or other scripting languages.
- Support CI/CD and IaC security automation using platforms such as Spacelift, GitHub Actions or equivalent tools.
- Help embed scanning, secret protection and policy checks into developer pipelines.
Operations & Compliance
- Implement guardrails, policies and controls to ensure secure and compliant cloud platforms.
- Monitor security posture, system health and platform reliability using cloud-native and third-party tooling.
- Triage security findings, troubleshoot infrastructure issues and collaborate with senior engineers on root cause analysis.
Collaboration & Continuous Improvement
- Work with application teams, SRE, security and architecture groups to deliver end-to-end secure cloud solutions.
- Contribute to platform modernization initiatives, identifying opportunities to automate, optimize or simplify.
- Share knowledge, documentation and best practices to uplift security engineering maturity.
Cyber Security Applications & Platforms in Scope
The role engineers, secures and operates the cloud infrastructure underpinning Pfizer's core cyber security application estate, including:
- Ping - enterprise identity and access management / federation and single sign-on.
- SailPoint - identity governance and administration, access certification and lifecycle management.
- CyberArk - privileged access management, secrets management and credential vaulting.
- CrowdStrike Falcon LogScale running on Amazon EKS - large-scale security log ingestion, retention and threat hunting.
Cutting-Edge & Agentic Cloud Security Capabilities
This role sits at the front edge of AI-enabled security engineering. You will work with, evaluate, and operationalise emerging agentic capabilities that are reshaping how cloud security is delivered, including:
- Developer-embedded secret and credential protection - preventing credentials and secrets from ever reaching a repository, using GitHub Advanced Security (GHAS) push protection, secret scanning, code scanning and dependency review.
- Autonomous security agents for offensive testing - agent-driven penetration testing (black-box against external cloud estates and white-box against our own accounts) and continuous AI-assisted source code security review.
- AI red team and blue team agents within our cloud-native application protection tooling - using agentic red teaming to continuously probe cloud configurations and workloads, and blue team agents to accelerate detection, triage and response.
- AI-assisted vulnerability remediation - evaluating and adopting emerging code-repair models that generate and validate security fixes rather than only reporting findings.
- Hyperscaler-native security agents - early access and alpha programmes from AWS, Microsoft and Google that bring agentic reasoning to cloud security posture, threat detection and automated remediation.
- Agentic security engineering at scale - building the guardrails, evaluation harnesses, and human-in-the-loop controls that let autonomous agents operate safely against a regulated, global pharmaceutical cloud estate.
BASIC QUALIFICATIONS
- Bachelor's Degree in Computer Science, Engineering, IT, or equivalent experience.
- 2+ years of hands-on cloud, platform or security engineering experience.
- Proficiency in at least one major cloud provider (AWS, Azure, or GCP).
- Infrastructure as Code experience (Terraform preferred).
- Experience with automation and scripting (Python strongly preferred).
- Solid understanding of networking, identity, encryption and security fundamentals in a cloud-native context.
- Ability to collaborate in global, cross-functional engineering environments.
- Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
PREFERRED QUALIFICATIONS
- Multi-cloud familiarity (AWS + Azure or GCP).
- Exposure to CSPM/CNAPP, SIEM or log analytics, vulnerability management or application security scanning tools.
- Knowledge of containerization and orchestration security (Docker, Kubernetes, EKS, AKS or GKE).
- Exposure to IAM/SSO, identity governance or privileged access management platforms.
- Interest in AI / agentic security tooling.
- Experience with Spacelift, OpenTofu or similar IaC automation platforms.
- Familiarity with compliance frameworks (NIST, CIS, ISO 27001) or regulated environments.
- Relevant cloud or security certifications (AWS/Azure/GCP Security, Security+, CCSP).
- Curious, self-driven and committed to continuous skill development, particularly around emerging AI security capabilities.
- Strong problem-solving and analytical mindset, especially for complex cloud systems.
- Comfortable operating with high ownership and autonomy.
- Customer-focused mindset with the ability to balance engineering excellence, security and business outcomes.
Please apply by sending your CV in English.
Work Location Assignment: Hybrid
Purpose
Breakthroughs that change patients' lives
Not included in the source posting: about the role, what you'll do, benefits.
Skills
Who can apply
The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.
Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.