Senior Cloud Security Engineer
Job Summary
Career Category
Information SystemsJob Description
Join our team at AMGEN Capability Center Portugal the #1 company in Best Workplaces (201500 employees category) in 2024 by the Great Place to Work Institute. With over 400 talented individuals from more than 40 nationalities our Lisbon center thrives at the intersection of innovation excellence and inspiration. This is your opportunity to explore the future of healthcare through technology and digital innovation supporting our mission To Serve Patients.
Senior Cloud Security Engineer
At Amgen technology is more than an enablerit is a catalyst for discovery transformation and better patient outcomes. Every innovation you help deliver contributes to improving and saving lives.
If youre passionate about cloud security automation and solving complex security challenges at enterprise scale wed love to hear from you.
Live
What you will do
Amgen is seeking a Senior Cloud Security Engineer to join our Cloud Security Organization within the Global Cybersecurity and Digital Trust team. Based at our Lisbon Capability Center you will play a key role in securing Amgens global cloud platforms by designing implementing and continuously improving cloud security capabilities across AWS and other cloud environments.
Working closely with engineering infrastructure DevOps and security teams you will strengthen Amgens cloud security posture through automation secure-by-design architectures and operational excellence. You will also help drive the responsible adoption of AI technologies to enhance cloud security engineering accelerate risk identification and continuously improve the security posture of Amgens cloud environments.
Key Responsibilities
- Design implement and continuously improve secure cloud architectures across public private and hybrid cloud environments aligned with enterprise security frameworks Zero Trust principles regulatory requirements and industry best practices.
- Design and implement cloud network security architectures including Zero Trust networking micro-segmentation Web Application Firewalls (WAF) API security secure hybrid connectivity and network segmentation to protect cloud-native and hybrid workloads.
- Design engineer implement and maintain cloud security controls including Identity and Access Management (IAM) Privileged Access Management (PAM) network segmentation encryption key management (KMS/HSM) secrets management and certificate lifecycle management to protect cloud-native applications and infrastructure.
- Implement and optimize cloud security posture management (CSPM) cloud workload protection (CWPP) vulnerability management and automated compliance solutions to continuously identify prioritize and remediate security risks.
- Design develop and maintain secure Infrastructure as Code (IaC) solutions using Terraform CloudFormation and policy-as-code frameworks to automate cloud provisioning and enforce security guardrails.
- Develop and maintain cloud governance frameworks security baselines guardrails and landing zones across AWS Azure and Google Cloud Platform.
- Design and implement cloud-native logging monitoring and detection capabilities by integrating services such as AWS CloudTrail Azure Monitor GCP Cloud Logging and cloud-native security tools into centralized SIEM and SOC platforms to improve threat detection incident response and operational visibility.
- Collaborate with Application Security DevOps Platform Engineering and Application Development teams to embed security throughout the Software Development Lifecycle (SDLC) by integrating automated security testing Infrastructure as Code scanning secrets management dependency analysis and container security into CI/CD pipelines.
- Design and implement security controls for containerized Kubernetes serverless and cloud-native application environments ensuring secure deployment runtime protection and policy enforcement.
- Partner with Security Operations (SOC) and Incident Response (IR) teams to investigate analyze and respond to cloud security incidents perform forensic analysis root cause investigations and threat hunting and implement corrective and preventive security controls to enhance cloud security posture detection capabilities and operational resilience.
- Lead cloud security architecture reviews for cloud-native platforms Kubernetes environments managed cloud services APIs AI services and enterprise applications ensuring alignment with enterprise security standards regulatory requirements and secure-by-design principles.
- Conduct threat modeling and cloud security risk assessments to identify security threats design appropriate mitigations and validate security controls for new cloud solutions services and architectures.
- Evaluate emerging cloud AI and cybersecurity technologies to drive continuous improvement automation innovation and operational efficiency across cloud security capabilities.
- Design and implement security controls for cloud-native AI and machine learning services including Generative AI LLM integrations AI orchestration platforms and AI development pipelines ensuring secure access data protection governance and regulatory compliance.
- Partner with Data Engineering AI and Platform Engineering teams to secure enterprise AI platforms (e.g. Databricks) AI workflows and AI automation solutions while evaluating emerging AI technologies to drive innovation automation and continuous improvement.
- Develop and automate cloud security capabilities using scripting APIs Infrastructure as Code and security orchestration to improve operational efficiency consistency and scalability.
- Develop maintain and continuously improve cloud security standards reference architectures technical documentation operational procedures and security runbooks to support secure engineering and operational excellence.
- Provide technical leadership mentoring and subject matter expertise to engineering operations architecture and product teams promoting cloud security best practices and secure-by-design principles.
- Support internal and external security audits compliance assessments and regulatory initiatives by providing evidence of cloud security controls and ensuring adherence to applicable standards and policies.
- Participate in after-hours support activities as required and travel occasionally.
Win
What we expect of you
We value diverse perspectives and believe that every employee brings unique strengths to our mission of serving patients. The ideal candidate is a collaborative security professional with a strong technical foundation and a passion for cloud security.
Preferred Qualifications
- Strong understanding of core information security principles including authentication authorization confidentiality integrity and availability.
- Solid knowledge of secure design principles including least privilege defense in depth and secure-by-design practices.
- Good understanding of cryptography concepts including encryption certificate management and key lifecycle management.
- Strong experience securing AWS environments including Identity and Access Management (IAM) Data Security Network Security Compute/Workload Security Security operations and secure DevOps practices.
- Working knowledge of enterprise cloud platforms across IaaS PaaS and SaaS environments including AWS Azure GCP Salesforce Microsoft 365 Rafay or similar technologies.
- Knowledge of AI security principles including securing Generative AI large language model (LLM) applications AI/ML workloads and AI orchestration platforms (e.g. Databricks and n8n) in cloud environments.
- Experience implementing security controls for cloud-native AI services and platforms including identity and access management data protection encryption secrets management API security and network security.
- Experience securing AI development pipelines (MLOps/LLMOps) including Databricks ML workflows supply chain security model artifact protection Infrastructure as Code (IaC) and CI/CD security.
- Experience securing AI orchestration and automation platforms (e.g. n8n) including workflow governance API security credential and secrets management and secure integration with enterprise systems and LLM services.
- Experience securing managed AI services and platforms such as Amazon Bedrock Amazon SageMaker Azure OpenAI Service Google Vertex AI and Databricks.
- Knowledge of public private and hybrid cloud architectures including cloud service models (IaaS PaaS and SaaS) infrastructure design networking scalability and cloud security best practices.
- Knowledge of Identity Governance principles including identity lifecycle management authentication authorization privileged access management (PAM) and access governance.
- Knowledge of Cloud SIEM and SOC capabilities including centralized logging security monitoring threat detection incident response and security analytics.
- Hands-on experience with AWS core services related to compute networking storage content delivery automation deployment security and operations.
- Experience developing cloud-native applications using microservices architecture container technologies (e.g. Docker) and serverless computing platforms (e.g. AWS Lambda).
- Strong knowledge and engineering expertise in designing developing automating and operating AWS-based solutions with practical experience across EC2 Lambda DynamoDB API Gateway RDS CloudFormation CloudWatch CloudFront and Route 53.
- Experience designing and developing cloud-native applications and REST APIs within AWS environments.
- Experience architecting highly available scalable and resilient cloud solutions leveraging load balancing horizontal scalability and high-availability design principles.
- Proficiency in at least one programming or scripting language such as Java Python or JSON policy languages.
- Experience using AI technologies such as developing AI Agents and building and LLM
- Excellent written and verbal communication skills.
- Strong collaboration skills with the ability to work effectively across cross-functional teams.
- Team-oriented placing priority on successful completion of team goals.
- Self-motivated proactive and able to manage competing priorities in a dynamic environment.
- Self-starter with a high degree of initiative.
Preferred Certifications
- Certified Cloud Security Professional (CCSP) Certificate of Cloud Security Knowledge (CCSK) or an equivalent cloud security certification.
- AWS Certified Solutions Architect Professional and/or AWS Certified Security Specialty.
- Certified Information Systems Security Professional (CISSP) or an equivalent information security certification.
THRIVE
What you can expect of us
As we work to develop treatments that take care of others we also care deeply for our teammates well-being and growth.
Vast opportunities to learn develop and move up and across our global organization.
Diverse and inclusive community of belonging where colleagues are empowered to bring ideas to the table take risks and act.
Generous AMGEN Total Rewards Plan comprising healthcare finance wealth and career benefits.
Flexible work arrangements.
APPLY NOW
Objects in your future are closer than they appear. Join us.
EQUAL OPPORTUNITY STATEMENT
AMGEN is an Equal Opportunity employer and will consider you without regard to your race color religion sex sexual orientation gender identity national origin protected veteran status or disability status.
We will ensure that individuals with disabilities are provided a reasonable accommodation to participate in the job application or interview process to perform crucial job functions and to receive other benefits and privileges of employment. Please contact us to request an accommodation.
.Salary Range
5232090EUR-7078710EURRequired Experience:
Senior IC
About Company
Amgen, a biotechnology pioneer, discovers, develops and delivers innovative human therapeutics. Our medicines have helped millions of patients in the fight against cancer, kidney disease, rheumatoid arthritis and other serious illnesses. As an organization dedicated to improving the ... View more