Principal Cloud Security Engineer

Role description and responsibilities
Damia Group is an international tech recruitment agency with 3 decades of experience. Our arrival in Portugal, 7 years later, was set on a mission to transform IT recruitment experiences and, through them, achieve better results. We believe in long-term relationships with a transparent and relaxed mindset. In a short period, we have reached the hearts of both scale-ups and larger organisations by delivering spot-on curated candidate shortlists, increased job offer acceptance rates and shorter time-to-fill.

About the role: As a Principal Cloud Security Engineer, the successful candidate will partner with DevOps and CI/CD engineers and their Architects team to ensure security best practices are embedded across the company's cloud infrastructure.

The Cloud Security team is a collaborative group of talented cloud security engineers working in close partnership with the engineering, platform, and trust & security teams. They are on a mission to safeguard the privacy and security of the company and its users' data, embedded directly in the heart of product development.

Responsibilities:
  • Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organisation
  • Use their knowledge of security architecture to help engineers build and securely operate products and services from the ground up
  • Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements
  • Perform proactive research to identify new threats and attack vectors
  • Partner with engineering teams to embed shift-left security practices throughout the software development lifecycle
  • Implement and manage cloud and Kubernetes security posture management tooling to continuously monitor and reduce risk across containerised workloads

Requirements
  • Proven experience working with AWS and AWS security services in a secure production environment, including IAM, Config, KMS, Secrets Manager, CloudWatch, CloudTrail, and GuardDuty
  • Proven experience working closely with engineering teams and supporting them on their path to shifting security left
  • Background with infrastructure as code (AWS CDK, CloudFormation, or Terraform), version control and CI tools such as GitLab and GitLab CI
  • Hands-on experience with Kubernetes (AWS EKS), containers (Docker, AWS ECS), K8s admission controllers and Supply Chain Security
  • Solid understanding of internet and computer network protocols, including TCP/IP, TLS, and VPN
  • Good written and verbal communication skills in English
  • Collaborative team player with a hands-on, can-do approach to problem-solving
  • Currently living in Portugal and legally authorized to work in the country

Nice to have:
  • AWS Certified Security – Specialty certification or similar
  • General familiarity with AI tools and large language models (e.g., Claude by Anthropic, AWS Bedrock)

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available