{"id":1523508,"url":"https://alion.io/job/newxel-cloud-security-engineer-nxj-208","title":"Cloud Security Engineer (NXJ-208)","company":{"id":679539,"name":"Newxel","domain":"newxel.com","url":"https://alion.io/company/newxel-2","size_band":"51-200","is_staffing_agency":true,"employer_type":"agency","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Warsaw, Poland"],"countries":["PL"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":50000,"max_usd":89000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":9},"experience_years_min":4,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Azure AKS","optional":false},{"name":"CI/CD","optional":false},{"name":"FinOps","optional":false},{"name":"GCP","optional":false},{"name":"IAM","optional":false},{"name":"Kubernetes","optional":false},{"name":"LLM","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"Python","optional":false},{"name":"Terraform","optional":false},{"name":"SOC 2","optional":true}],"status":"live","first_seen_at":"2026-09-30T12:56:31Z","employer_posted_date":"2026-09-30","last_verified_at":"2026-10-01T09:45:00Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"The Role\nAs the sole security engineer across the entire company, you will take full ownership of the end-to-end cloud security architecture and strategy. The core challenge is not gatekeeping, but designing policy-as-code guardrails and proactive security baselines that embed natively into automated pipelines. You will work directly with DevOps, MLOps, and engineering teams to maintain high software delivery velocity while securing scalable cloud and AI infrastructure.\nAbout the Product\nThe platform transforms live sports broadcasts into personalized, publication-ready highlight packages while games are actively in progress. Operating at continuous scale, it automatically ingests, analyzes, and tags video streams to identify key moments. The system processes massive data volumes with zero tolerance for latency, directly powering downstream consumer-facing media products.\nTechnology Stack: The core cloud infrastructure relies on Azure (with AWS/GCP workloads), provisioned through Terraform and automated CI/CD pipelines. Workloads run on Kubernetes (AKS) with policy enforcement via OPA, Sentinel, and Azure Policy. Vulnerability management and runtime monitoring are driven through a CNAPP platform, while Python is utilized for automation and custom security integrations.\nWhat You’ll Be Doing\nArchitect and enforce the unified multi-cloud security strategy across Azure, AWS, and GCP covering IAM, network security, and secrets management\n\nEmbed automated guardrails in Terraform and CI/CD pipelines using policy-as-code (OPA, Sentinel, Azure Policy) to block misconfigurations before deployment\n\nOwn Kubernetes (AKS) cluster security, establishing RBAC, network policies, pod security standards, and admission control controls\n\nDrive end-to-end vulnerability and posture management through the CNAPP platform, managing findings to closure under strict SLAs\n\nIntegrate automated SAST, DAST, SCA, and secret scanning into CI/CD workflows, partnering with engineering teams on remediation\n\nLead cloud security incident response procedures, conducting post-mortems and implementing preventive preventive measures\n\nCollaborate with DevOps, MLOps, and FinOps teams to embed security baselines directly into development workflows without impacting delivery velocity\n\nManage customer security assessments and technical questionnaires in coordination with Sales and Legal stakeholders\n\nWhat We Expect\nMust-have\n4+ years of hands-on experience in Cloud Security or Security Engineering within multi-cloud environments\nDeep expertise in Azure security architecture and cloud-native controls\n\nStrong practical knowledge of Kubernetes security, including RBAC, network policies, admission controllers, and image scanning\n\nHands-on proficiency with Terraform and Infrastructure as Code using policy-as-code principles\nProven background integrating security controls (SAST/DAST/SCA/secret scanning) into CI/CD pipelines alongside DevOps teams\n\nClear communication skills with experience partnering directly with engineering and management stakeholders\n\nFamiliarity with security requirements for LLM and AI infrastructure\n\nNice-to-have\nProficiency in Python for developing custom security tooling and automation\n\nWorking experience with SOC2 compliance frameworks and audit readiness\n\nPrior experience serving as a security lead or hands-on technical lead\n\nExposure to modern container security practices including image signing, SBOMs, and runtime protection\n\nWhy This Role Is Worth Your Time\nYou have complete autonomy and ownership as the single security authority shaping the security roadmap for a fast-growing AI platform\n\nYou are building practical, developer-friendly guardrails rather than acting as a traditional gatekeeper, directly embedding security into high-velocity engineering workflows\n\nThe role provides broad multi-cloud exposure across modern Kubernetes, policy-as-code, and emerging LLM/AI infrastructure domains","description_format":"text","description_chars":3938,"description_truncated":false,"requirements":{"experience_years_min":4,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Poland","iso":"PL","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cloud Security"],"lifecycle":[{"event":"open","at":"2026-09-30T13:02:44Z"}],"liveness":{"score":54,"band":"ok","label":"Likely open","p_open":1,"p_active":0.542,"p_room":1,"age_days":0,"expected_fill_days":35,"reasons":["conf:7","agency","velocity","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/newxel-cloud-security-engineer-nxj-208","json_url":"https://alion.io/job/newxel-cloud-security-engineer-nxj-208.json","meta":{"generated_at":"2026-10-01T12:27:46Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3877,"day_limit":5000,"remaining_today":1123,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}