Skip to content

Open nowPosted 8 days ago

Cloud Security Engineer (NXJ-208)

Newxel10 open roles

Where
Poland (Hybrid/Entity)
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCloud Security Engineer (NXJ-208)Newxel · Poland (Hybrid/Entity)
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Newxel's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Newxel postings stay open a median of 13 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 8 days ago

Newxel median: 13 days open

The posting

THE ROLE

As the sole security engineer across the entire company, you will take full ownership of the end-to-end cloud security architecture and strategy. The core challenge is not gatekeeping, but designing policy-as-code guardrails and proactive security baselines that embed natively into automated pipelines. You will work directly with DevOps, MLOps, and engineering teams to maintain high software delivery velocity while securing scalable cloud and AI infrastructure.

ABOUT THE PRODUCT

The platform transforms live sports broadcasts into personalized, publication-ready highlight packages while games are actively in progress. Operating at continuous scale, it automatically ingests, analyzes, and tags video streams to identify key moments. The system processes massive data volumes with zero tolerance for latency, directly powering downstream consumer-facing media products.

Technology Stack: The core cloud infrastructure relies on Azure (with AWS/GCP workloads), provisioned through Terraform and automated CI/CD pipelines. Workloads run on Kubernetes (AKS) with policy enforcement via OPA, Sentinel, and Azure Policy. Vulnerability management and runtime monitoring are driven through a CNAPP platform, while Python is utilized for automation and custom security integrations.

WHAT YOU’LL BE DOING

- Architect and enforce the unified multi-cloud security strategy across Azure, AWS, and GCP covering IAM, network security, and secrets management

- Embed automated guardrails in Terraform and CI/CD pipelines using policy-as-code (OPA, Sentinel, Azure Policy) to block misconfigurations before deployment

- Own Kubernetes (AKS) cluster security, establishing RBAC, network policies, pod security standards, and admission control controls

- Drive end-to-end vulnerability and posture management through the CNAPP platform, managing findings to closure under strict SLAs

- Integrate automated SAST, DAST, SCA, and secret scanning into CI/CD workflows, partnering with engineering teams on remediation

- Lead cloud security incident response procedures, conducting post-mortems and implementing preventive preventive measures

- Collaborate with DevOps, MLOps, and FinOps teams to embed security baselines directly into development workflows without impacting delivery velocity

- Manage customer security assessments and technical questionnaires in coordination with Sales and Legal stakeholders

WHAT WE EXPECT

MUST-HAVE

- 4+ years of hands-on experience in Cloud Security or Security Engineering within multi-cloud environments • Deep expertise in Azure security architecture and cloud-native controls

- Strong practical knowledge of Kubernetes security, including RBAC, network policies, admission controllers, and image scanning

- Hands-on proficiency with Terraform and Infrastructure as Code using policy-as-code principles • Proven background integrating security controls (SAST/DAST/SCA/secret scanning) into CI/CD pipelines alongside DevOps teams

- Clear communication skills with experience partnering directly with engineering and management stakeholders

- Familiarity with security requirements for LLM and AI infrastructure

NICE-TO-HAVE

- Proficiency in Python for developing custom security tooling and automation

- Working experience with SOC2 compliance frameworks and audit readiness

- Prior experience serving as a security lead or hands-on technical lead

- Exposure to modern container security practices including image signing, SBOMs, and runtime protection

WHY THIS ROLE IS WORTH YOUR TIME

- You have complete autonomy and ownership as the single security authority shaping the security roadmap for a fast-growing AI platform

- You are building practical, developer-friendly guardrails rather than acting as a traditional gatekeeper, directly embedding security into high-velocity engineering workflows

- The role provides broad multi-cloud exposure across modern Kubernetes, policy-as-code, and emerging LLM/AI infrastructure domains

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Newxel's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Newxel's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Newxel's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.