
Truecaller · Sweden
Join Truecaller – The place where innovation meets impact! Truecaller's mission is to build trust in communication by making it safer, smarter, and more effici...
Join Truecaller – The place where innovation meets impact!
Truecaller's mission is to build trust in communication by making it safer, smarter, and more efficient. Born in Sweden, trusted
We always look for people who take initiative, own their work, and keep raising the bar. An entrepreneurial mindset matters here,
especially when it turns bold ideas into real actions. We stay collaborative and focused, always searching for smarter paths
forward. If you want to make an impact and grow with a team that inspires millions, you’ll fit right in.
As a Senior Cloud Security Engineer, you will act as a technical leader in safeguarding our core cloud infrastructure. You will
take ownership of maintaining the highest standards of security controls for our critical systems within Google Cloud Platform
(GCP). We're looking for someone who thrives in complex environments, can solve infrastructure security problems where no
established patterns exist, and isn't afraid to get their hands dirty. You won't just advise; you will actively build, configure,
and fix security controls. You'll leverage your expert understanding of cloud services, infrastructure-as-code, and container
security to architect robust security measures and drive systemic improvements across the organization.
infrastructure. You will look beyond immediate fixes to architect long-term, scalable solutions for networking, compute,
storage, and GKE.
Requests, and apply configurations to resolve security issues, harden infrastructure, and deploy tooling (e.g., EDR, Identity
proxies) in production environments.
and drive organizational change to eliminate them, rather than just patching individual issues.
to continuously monitor, assess, and improve the security posture of our cloud environment.
balancing strict security requirements with operational velocity.
engineering standards by guiding colleagues on advanced security concepts and architecture.
security reviews into automated policy-as-code checks and high-fidelity alerts.
leading technical designs and influencing decisions across multiple squads.
landscape, emerging vulnerabilities, and attack vectors, translating this knowledge into proactive defense strategies.
comfortable defining security standards for experimental technologies where internal patterns may not yet exist.
including successful stakeholder alignment and management of external dependencies.
directly configuring infrastructure, writing production-grade code, and debugging complex systems. Once an issue has been
identified you have the experience applying the fix either yourself or through collaboration with stakeholders.
delivery with long-term maintainability and business value.
solutions and evaluate trade-offs in GCP services (GCE, GKE, VPC, IAM, SCC).
business impact (e.g., financial loss, brand reputation) to secure buy-in.
We support growth through learning resources, leadership programs, mentoring, and real hands-on work. People can move between
teams and projects to build new skills and keep things interesting. We offer clear internal mobility and a transparent path for
progression, with leaders who stay involved and provide guidance throughout the year. In addition, you will benefit
parental leave top-up, pension, and wellness contributions.
efficiently.
offices offer a vibrant environment with opportunities to learn, connect, and recharge, from breakfast, lunch, and well-stocked
snack stations and quiet spaces to team activities such as movie nights, tech meetups, and cultural events. There's something
for everyone.
tasks to explore new, bold ideas and build things they’ve always wanted to. It’s a space where curiosity leads the way, and
prototypes take shape. Some concepts even make it into production, and a few have grown into real features used by millions
today. Lab Days allow you to be creative, learn fast, and help shape Truecaller's future.
Truecaller is committed to building a diverse and inclusive team. We believe that a wide range of backgrounds, perspectives, and
experiences strengthens our products and our culture. No matter where you're from, what language you speak, or how you identify,
we value what makes you unique and would love to get to know you.
Check out Life at Truecaller - Behind the code: https://www.instagram.com/lifeattruecaller/
Sounds like a great opportunity?
We will fill the position as soon as we find the right candidate, so please send your application as soon as possible. As part of
the recruitment process, we will conduct a background check.
We only accept applications in English.
Thought Machine's mission is bold – to properly and permanently rid the world's banks of legacy technology. To achieve this, we have developed the foundations of modern banking through core and payments technology which run natively in the cloud. What we are attempting is hard and means we need great people working together to build great technology. We have grown rapidly in the past few years – growing our team to more than 550 individuals across offices in London, New York, Singapore, Sydney and our newly established Engineering Hub in Lisbon. We have raised more than £500m in funding and our investors include Molten Ventures, Eurazeo, Intesa Sanpaolo, Temasek, Nyca Partners, JPMorgan Chase Strategic Investments, Standard Chartered Ventures, and more. We have created a culture that enables our team to produce the best work in the industry while ensuring we have fun along the way. We're regularly cited as having a fantastic workplace culture and have been recognised by Sifted magazine as having one of the highest Glassdoor ratings for a UK fintech company and the industry's most generous employee share package. Named one of the world's most innovative fintechs by Global Finance Magazine, we were also recognised by the Financial Times as one of Europe's fastest-growing companies for two consecutive years—and a UK Best Employer for 2026. This is a full-time, permanent position based in our Lisbon office, requiring four days a week onsite. A Senior Cloud Security Engineer is a part of the larger Security Engineering team. We desire engineers who are able to lead the engineering, design, and delivery of solutions to security problems. We have a passion for exploring unique solutions and sharing differing perspectives that leads to the development of leading solutions to complex security problems. The Security Engineering team is cross-functional and made up of diverse people who bring their own unique expertise in either (or both) application security and infrastructure (cloud) security. We allow team members to move from project to project, subject to subject based on their skills, experience, and interests. Each team member brings their own expertise to bear in ways that are collaborative and designed to find the best solutions to complex problems. The team covers the following areas, and individuals contribute to any of them based on their own expertise: * Designs of secure products and platforms * Reviews of engineering designs, threat models, and coding practices * Threat modelling to identify relevant areas of focus * Define the best in class protective and detective security controls * Development of security tooling and automation * Implement and maintain cutting-edge tools and measures A large part of the Thought Machine security function is greenfield; we are building the bank of tomorrow with cutting edge technology. To achieve this we need innovative thinking to create security solutions in our products and our infrastructure. We look for people who think outside the box, and outside of traditional silos to find unique solutions and approaches to security that lead the industry. DUTIES * Provide security expertise and mentorship to Thought Machine engineering teams through the stages of planning, design, and testing of new solutions. * Lead the design and delivery of cloud native preventative and detective controls that operate at scale * Build and maintain automation to actively audit and assess infrastructure-as-code and in-place infrastructure * Develop (in code) security tooling, contribute to third-party security products, and develop updates for existing tooling that is in use in our environment * Co-develop threat models with engineering teams that identify relevant threats and relevant strategies for mitigation * Work with cloud engineering and operations teams to develop tooling that maintains our secure operating state in production * Perform security reviews and security testing * Lead complex projects to develop security capabilities, tooling, and functionality. * Contribute to the overall security strategy, security tooling selection and creation * Operate collaboratively with other Thought Machine teams with trust and influence REQUIREMENTS Essential * Familiarity with building and deploying containerised applications in public cloud using CI/CD frameworks and infrastructure automation * Knowledge of cloud networking architecture, cloud operations, security, automation and orchestration * Familiarity with performing security threat modelling and design reviews * Knowledge of security in distributed systems * Familiarity with good security practices with containers and Kubernetes * Experience with languages such as Go, Python, or other modern programming languages * Coding experience in the creation, automation, and integration of security tools * Experience in version control systems such as Git * Experience with designing, developing, and maintaining security in public cloud environments such as AWS and GCP * Ability to lead and encourage good design skills including creative and critical thinking, collaboration, full evaluation of options, and objective decision making to find a preferred solution. * Strong interpersonal and communication skills to support collaboration with other personnel and teams Desirable * Existing experience building and operating distributed systems at scale * Awareness and experience with “well-architected” cloud security frameworks or CSA-CCM * Contributions to the security community (public research, blogging, presentations, etc) * Experience in performing penetration testing and security testing * Experience developing tools and interacting with cloud provider API Benefits * Highly competitive salary * Voluntary Pension Plan (match up to 5%) * Private Healthcare Insurance * Comprehensive Life Insurance * 25 days holiday plus public holidays * Two charity days a year * Daily Meal Allowance * Access to outstanding learning materials and courses * Sports and hobby clubs, subsidised by Thought Machine * All the latest tech you need * Huge range of healthy (and not-so-healthy) snacks, smoothies and drinks * A talented and experienced team as your colleagues * An environment where we encourage learning and progress We actively hire candidates who demonstrate technical excellence in their field and welcome people of all ages and backgrounds, providing everyone with equal access to professional development. You are encouraged to apply even if your experience doesn't accurately match the job description. We also encourage applications from those with different abilities, including candidates with ADHD, autism, dyslexia or dyspraxia.
WORUM ES GEHT Als Cloud Solution Architect (CSA) übernimmst du eine seniore Gestaltungsrolle an den Schnittstellen von Cloud Security, Identity & Access Management und Cloud Governance. Du siehst das große Ganze – und bringst technische Tiefe, strategisches Denken und Beratungskompetenz zusammen. In enger Zusammenarbeit mit Kunden aus dem Mittelstand und Enterprise-Umfeld entwickelst du ganzheitliche Cloud-Architekturen, die Sicherheit, Compliance und Betreibbarkeit in Einklang bringen. Du verantwortest architektonische Entscheidungen, steuerst technische Workstreams und bist Anlaufstelle für komplexe Fragestellungen rund um Microsoft-basierte Cloud-Lösungen. Du arbeitest in einem erfahrenen Team, übernimmst Verantwortung für die Qualität und Konsistenz von Architekturkonzepten und begleitest Kunden von der Strategie bis zur nachhaltigen Umsetzung. DAS BEGEISTERT DICH * Konzeption und Verantwortung ganzheitlicher Cloud-Architekturen mit Fokus auf Microsoft Azure – unter Berücksichtigung von Security, IAM,Governanceund Compliance * Entwicklung und Bewertung von Cloud-Security-Architekturen im Kontext von Zero Trust, Least Privilege und Defence-in-Depth * Design und Weiterentwicklung von Identity- und Access-Management-Konzepten auf Basis von Microsoft Entra ID, inkl.ConditionalAccess, PIM und IdentityGovernance * Beratung zu CloudGovernanceFrameworks: Aufbau von LandingZones, Azure Policy, Management Groups undSubscription-Strukturen * Entwicklung von Compliance- und Sicherheitskonzepten im Einklang mit regulatorischen Anforderungen (z. B. ISO 27001, BSI IT-Grundschutz, NIS2, DORA) * Technische Führung in Projekten: Steuerung vonWorkstreams, Code- und Architektur-Reviews sowie Qualitätssicherung * Enge Zusammenarbeit mit CISO-Organisationen, Cloud- und Security-Teams auf Kundenseite sowie internen Consultants * Erstellung von Architekturkonzepten, Entscheidungsvorlagen und technischer Dokumentation auf Entscheider- wie Umsetzungsebene Das bringst du mit * Mindestens 5 Jahre Berufserfahrung in der IT-Beratung oder in vergleichbaren technischen Rollen, idealerweise mit Fokus auf Cloud, Security oder IAM * Fundierte, praktische Kenntnisse der Microsoft Azure Plattform – insbesondere in den Bereichen Identity (Entra ID), Security (DefenderforCloud, Sentinel) undGovernance(Azure Policy, Management Groups) * Erfahrung in der Konzeption und Umsetzung von IAM-Architekturen: SSO,Federation(SAML, OAuth2, OIDC),PrivilegedIdentity Management, Identity Lifecycle Management * Verständnis von Cloud-Compliance-Frameworks und regulatorischen Anforderungen sowie deren Übertragung in technische Steuerungsmaßnahmen * Ausgeprägtes konzeptionelles Denkvermögen: Fähigkeit, komplexe technische Zusammenhänge strukturiert zu analysieren, zu dokumentieren und verständlich zu kommunizieren * Erfahrung in der Arbeit mit Kunden auf Entscheider- und Fachebene – sicheres Auftreten, Präsentationsstärke und Kommunikationsgeschick * Sehr gute Deutsch- und Englischkenntnisse in Wort und Schrift Nice to have * Microsoft-Zertifizierungen,insbesondere: AZ-305 (Azure Solutions Architect Expert), SC-100 (Cybersecurity Architect Expert), SC-300 (Identity and Access Administrator Associate)oderAZ-500 (Azure Security Engineer Associate) * Erfahrung mit MicrosoftPurview(InformationProtection& Compliance) sowie Microsoft Sentinel als SIEM/SOAR-Plattform * Kenntnisse in weiteren Cloud-Plattformen (AWS, GCP) oder Multi-Cloud-Governance-Ansätzen * Erfahrung mit Infrastructure-as-Code (Terraform,Bicep,ARM Templates) undDevSecOps-Praktiken * Kenntnisse in ITIL, TOGAF oder anderen Enterprise-Architecture-Frameworks * Erfahrung in regulierten Branchen (z. B. Finanzdienstleistungen, Gesundheitswesen, öffentliche Verwaltung) Typische Technologien & Themen * Microsoft Azure: Entra ID, Azure Policy, Management Groups, Landing Zones, Defender for Cloud, Microsoft Sentinel * Identity & Access Management: SSO, Federation (SAML, OIDC, OAuth2), PIM, Conditional Access, Identity Governance * Cloud Security Architecture: Zero Trust,Defence-in-Depth, CSPM, CIEM * Cloud Governance & Compliance: Azure Policy, Regulatory Compliance Dashboards, ISO 27001, NIS2, DORA, BSI IT-Grundschutz * Microsoft Purview (Information Protection & Data Governance) * Infrastructure-as-Code: Bicep, Terraform, ARM Templates * Active Directory / Microsoft Entra ID Connect (Hybrid Identity * DevSecOps, CI/CD-Integration von Security-Controls WARUM WIR? Dein Onboarding bei Comma Als Senior Consultant bringst du fundierte Expertise und fachliche Expertise mit - darauf bauen wir auf. Deshalb konzentriert sich dein Onboarding auf das Wesentliche: die richtigen Kontakte, ein tiefes Verständnisunserer Kultur und Arbeitsweise sowie Orientierung in unseren Strukturen und Entscheidungswegen. Ein strukturierter Austausch mit erfahrenen Kolleg unterstützt dich dabei, schnell die relevanten Netzwerke aufzubauen und dich im Unternehmen zu verorten. Gleichzeitig lernst du unsere Methoden, Prozesse und Comma-spezifischen Arbeitsweisen kennen. So findest du schnell die Hebel, mit denen du bei Comma und in Kundenprojekten wirksam werden kannst. Unsere Benefits * Du arbeitest an vielfältigen Projekten bei DAX-Konzernen und führenden Mittelständlern. * Innovative, interdisziplinäre Themen verbinden wissenschaftlichen Tiefgang mit echter Hands-on-Mentalität. * Du hast viel Platz für eigene Ideen und kannst eigenverantwortlich gestalten und handeln. * Flexible Arbeitszeiten, freie Standortwahl, Überstundenausgleich und Reisezeit, die als Arbeitszeit zählt, geben dir die Freiheit, Beruf und Privatleben nach deinen Vorstellungen zu gestalten. * Ein faires Fixgehalt plus Bonus, Jobrad, Top-Ausstattung und viele weitere Benefits runden dein Paket ab. * Individuelle Weiterbildungs- und Laufbahnprogramme begleiten dich während deiner gesamten Zeit bei Comma Soft. * Erfahrene Profis und Newbies arbeiten direkt zusammen – unterstützt durch ein strukturiertes Mentoring. * Ob Gipfelis (monatliche Mitarbeitertreffen), Grillen auf der Dachterrasse, GamesNights oder Sommerfeste mit deinen Liebsten – wir feiern gerne und oft zusammen.
회사 소개 쿠팡은 고객 감동 실현을 위해 존재합니다. 고객들이 "쿠팡 없이 그동안 어떻게 살았을까?" 라고 말할 때, 비로소 우리의 미션을 실현하고 있음을 알 수 있습니다. 고객들의 쇼핑과 식사, 생활 전반을 편하게 만들겠다는 유일한 집념으로 쿠팡은 수억 달러 규모의 커머스 산업 전반의 혁신을 이끌고 있습니다. 쿠팡은 가장 빠르게 성장하는 리테일 기업 중 하나로, 국내 커머스 업계에서의 독보적인 입지와, 고객 신뢰를 구축했습니다. 쿠팡은 스타트업 문화를 기반으로 한 글로벌 대형 상장사라고 자부합니다. 이것이 창립 당시의 기민함을 유지하며, 신규 서비스를 끊임없이 출시하며 비즈니스를 확장해 나가는 우리의 성장 동력입니다. 쿠팡의 모든 임직원에게는 기업가 정신을 갖추고 새로운 혁신과 이니셔티브를 추진할 수 있는 기회가 주어집니다. 주저없이 일에 뛰어들어 성과를 이루고자 하는 과감성이, 바로 쿠팡이 일하는 방식의 본질입니다. 쿠팡에서는 여러분 자신, 동료, 팀 그리고 회사 전체가 매일 성장하는 모습을 목격할 것입니다. 쿠팡의 모든 직원은 커머스의 미래를 만들겠다는 쿠팡의 미션에 진심입니다. 우리는 고객의 문제를 해결해 나가고, 전통적인 관념과 통념에 맞서며 실현가능한 한계를 뛰어넘고 있습니다. 고가용성(Always-on) 과 최첨단의 앞선 기술(High-tech), 초연결사회(Hyper-connected world) 에서의 놀라운 업무 경험을 원하신다면, 지금 바로 쿠팡에 합류하세요. 직무 소개 Cloud Infrastructure Security 팀의 주요 역할은 기술적 문제 해결방안을 찾는 데 집중하는 것입니다. 이를 위해, 관련기술을 연구 및 테스트하고 보안 솔루션을 직접 기획하거나 구현할 수 있으며, 이러한 작업은 언제든지 프로젝트로 확장될 수도 있습니다. 또한 각자 자신만의 전문적인 보안 엔지니어링 스킬을 보유함으로써 회사가 소유한 Cloud platform의 다양한 보안 기능을 테스트하거나, 보안 평가 및 개선활동을 수행할 수 있습니다. Security 유관부서, IT 인프라 및 개발조직과 긴밀하게 협업하여 업무를 수행합니다. 업무 내용 * AWS 기반 퍼블릭 클라우드 환경에서 워크로드 및 플랫폼 보안 요구사항 정의 * IAM, 네트워크(SG/NACL/AWS Network Firewall), 접근 제어, 인증/인가 중심의 클라우드 인프라 보안 설계 및 리뷰 * Terraform Sentinel Policy 기반 IaC(Infrastructure as Code) 보안 정책 수립 및 운영 * CSPM(Cloud Security Posture Management)을 활용한 리스크 기반 정책 설계 및 오구성(Misconfiguration) 개선 * Kubernetes(K8s), EKS, Service Mesh 환경에서의 컨테이너 보안 설계 및 운영 자격 요건 * 정보기술, 정보보안, 컴퓨터 과학 또는 관련 분야 학사 학위 이상을 보유하신 분 * 최소 4년 이상의 정보보안 업무 경력을 보유하신 분 * 정보보안 시스템 기획, 구축, 운영 및 모니터링 경험을 보유하신 분 * 정보보안, IT, 인프라, 네트워크 기반 기술에 대한 이해도가 높으신 분 * 유관 부서와의 협업 및 유연한 커뮤니케이션 스킬을 보유하신 분 우대 사항 * Cloud Computing (SaaS, PaaS, IaaS)에 대한 이해와 보안 검토 경험을 보유하신 분 * 보안 아키텍처 설계 및 직접 Hands-on 하여 구현한 경험을 보유하신 분 * 정보통신망법, 전자금융거래법, 개인정보보호법 등 Compliance에 대한 이해도가 있으신 분 * e-Commerce 및 물류 비즈니스에 대한 이해도가 있으신 분 * 영어 커뮤니케이션 역량을 보유하신 분 * CISA, CISSP, ISO/IEC 27001 등 정보보안 관련 자격증을 보유하신 분 전형 절차 및 안내 사항 * 전형 절차 * 서류전형 - 1차 면접 - 2차 면접 - 최종 합격 * 전형절차는 직무별로 다르게 운영될 수 있으며, 일정 및 상황에 따라 변동될 수 있습니다. * 전형 일정 및 결과는 지원서에 등록하신 이메일로 개별 안내 드립니다. * 참고 사항 * 본 공고는 모집 완료 시 조기 마감될 수 있습니다. * 지원서 내용 중 허위사실이 있는 경우에는 합격이 취소될 수 있습니다. * 취업 보호 대상자(보훈대상자, 장애인 등)는 관련 법률에 따라 채용우대를 받을 수 있습니다. * 직급과 담당 업무 범위는 후보자의 전반적인 경력과 경험 등 제반사정을 고려하여 변경될 수 있습니다. 이러한 변경이 필요할 경우, 최종 합격 통지 전 적절한 시기에 후보자와 커뮤니케이션 될 예정입니다. * 채용 및 업무 수행과 관련하여 요구되는 법령상 자격이 갖추어지지 않은 경우 채용이 제한될 수 있습니다. 개인정보 처리방침 * 쿠팡 그룹은 입사지원자 개인정보 처리방침(아래 링크)에 따라 귀하의 개인정보를 수집하여 처리합니다. https://www.coupang.jobs/kr/privacy-policy 서류 반환 정책 1. 본 고지는 『채용절차의공정화에관한법률』 제11조제6항에 따른 것 입니다. 2. 당사 채용에 응시한 구직자 중 최종 합격이 되지 못한 구직자는 『채용절차의 공정화에 관한 법률』에 따라 제출한 채용서류의 반환을 청구할 수 있음을 알려 드립니다. 다만, 홈페이지 또는 전자우편으로 제출된 경우나 구직자가 당사의 요구 없이 자발적으로 제출한 경우에는 그러하지 아니하며, 천재지변이나 그 밖에 당사에게 책임 없는 사유로 채용서류가 멸실된 경우에는 반환한 것으로 봅니다. 3. 위2항 본문에 따라 채용 서류 반환 청구를 하는 구직자는 채용 서류 반환 청구서 [채용절차의 공정화에 관한 법률 시행규칙 별지 제 3 호 서식]를 작성하여 이메일 (recruitingops@coupang.com) 로 제출하면, 제출이 확인된 날로부터 14 일 이내에 지정한 주소지로 등기우편을 통하여 발송해 드립니다. 이 경우 등기우편요금은 수신자 부담으로 하게 되오니 유념하시기 바랍니다. 4. 당사는 위2항 본문에 따른 구직자의 반환 청구에 대비하여 채용 여부가 확정된 날로부터 180 일간 구직자가 제출한 채용서류 원본을 보관하게 되며, 그때까지 채용서류의 반환을 청구하지 아니할 경우에는 『개인정보 보호법』에 따라 지체 없이 채용서류 일체를 파기할 예정입니다. 5. 단, 위 1항 내지 4항의 내용은 대한민국의 노동 관계 법령이 적용되는 경우에만 적용됩니다. 그 이외의 경우에는 적용되지 않습니다.