高级云安全工程师 - AI 弹性和安全增强
Senior Cloud Security Engineer - AI Resilience & Security Enhancements
**项目** 📝
我们正在寻找一位经验丰富的**高级云安全工程师**,以合同形式加入Form3,负责在我们的云原生支付平台上实施一项战略性的安全增强计划。
专注于提升云安全、运营弹性和治理能力,您将与我们的平台工程和安全团队紧密合作,设计并实施实用的安全改进措施,以提升我们构建、部署和运营关键支付基础设施的方式。
您将在加强云平台安全、软件供应链安全、身份和访问管理、AI治理、加密控制和自动化安全保证等领域发挥关键作用,确保解决方案可扩展、生产就绪,并符合监管要求。
**主要职责**
- 评估Form3各环境中的当前云安全状况,识别风险、控制差距和改进机会。
- 设计并实施可扩展的云安全控制措施,以提高我们云原生平台的弹性和安全性。
- 提升云基础设施上的边界安全控制。
- 通过安全的构建流程、自动化安全测试、部署治理和工件完整性来加强CI/CD流水线安全。
- 改进生产访问安全,包括RBAC、最小权限实现、部署工具和操作流程。
- 通过依赖项管理、容器镜像扫描、来源验证、签名和漏洞修复来增强软件供应链安全。
- 为AI驱动的工程能力的 securely 采用和治理做出贡献,包括数据保护、可审计性和操作弹性方面的控制。
- 提供云安全架构和安全工程实践的技术领导力和指导。
- 编写高质量的技术文档,包括解决方案设计、实施方案、操作流程和安全证据。
- 与工程、平台和安全团队密切合作,交付可维护、生产就绪的安全改进。
- 确保所有交付成果符合操作弹性要求、监管义务和内部安全标准。
- 使用结构化、低风险的变更管理实践交付变更,同时保持服务可用性。
**我们寻找的人选** 🔍
**必备条件**
- 在设计和实施云安全解决方案方面有丰富经验,熟悉主流云平台(如AWS、Azure、GCP)的安全最佳实践。
- 精通云安全控制,包括网络隔离、访问控制、加密和日志监控。
- 有实际经验在CI/CD流水线中集成安全实践,如静态代码分析、依赖项扫描和容器安全。
- 熟悉身份和访问管理(IAM)框架,包括多因素认证(MFA)、单点登录(SSO)和基于角色的访问控制(RBAC)。
- 具备良好的沟通能力和团队协作精神,能够与跨职能团队有效合作。
- 拥有相关认证(如Certified Cloud Security Professional (CCSP)、Certified Kubernetes Security Specialist (CKS)等)者优先。
查看英文原文
**THE PROJECT** 📝
We're looking for an experienced **Senior Cloud Security Engineer** to join Form3 on a contract basis to deliver a strategic programme of security enhancements across our cloud-native payments platform.
Focusing on improving cloud security, operational resilience and governance across our engineering ecosystem, you will work closely with our Platform Engineering and Security teams to design and implement practical security improvements that enhance how we build, deploy and operate critical payment infrastructure.
You'll play a key role in strengthening areas such as cloud platform security, software supply chain security, identity and access management, AI governance, cryptographic controls and automated security assurance, ensuring solutions are scalable, production-ready and aligned with regulatory expectations.
**Key responsibilities**
- Assess the current cloud security posture across Form3 environments, identifying risks, control gaps and opportunities for improvement.
- Design and implement scalable cloud security controls that improve the resilience and security of our cloud-native platform.
- Enhance perimeter security controls across cloud infrastructure.
- Strengthen CI/CD pipeline security through secure build processes, automated security testing, deployment governance and artefact integrity.
- Improve production access security, including RBAC, least-privilege implementation, deployment tooling and operational processes.
- Enhance software supply chain security through dependency management, container image scanning, provenance, signing and vulnerability remediation.
- Contribute to the secure adoption and governance of AI-enabled engineering capabilities, including controls for data protection, auditability and operational resilience.
- Provide technical leadership and guidance on cloud security architecture and secure engineering practices.
- Produce high-quality technical documentation, including solution designs, implementation plans, operational procedures and security evidence.
- Collaborate closely with engineering, platform and security teams to deliver maintainable, production-ready security improvements.
- Ensure all deliverables align with operational resilience requirements, regulatory obligations and internal security standards.
- Deliver changes using structured, low-risk change management practices while maintaining service availability.
**WE’RE LOOKING FOR** 🔍
**Essential**
- Extensive experience designing and implementing cloud security solutions within large-scale cloud-native environments.
- Strong hands-on experience securing public cloud platforms (AWS preferred).
- Expertise in cloud security architecture, identity and access management, workload protection and infrastructure security.
- Experience securing CI/CD pipelines and modern software delivery practices.
- Strong understanding of software supply chain security, including dependency management, artefact signing, provenance and vulnerability management.
- Experience implementing least-privilege access models and RBAC.
- Knowledge of security monitoring, risk assessment and security governance.
- Experience working within highly regulated or business-critical production environments.
- Excellent stakeholder management and communication skills, with the ability to influence engineering teams.
- Strong technical documentation and design skills.
**Desirable**
- Experience implementing security controls for AI or machine learning platforms.
- Knowledge of cryptographic controls and key management.
- Experience with Infrastructure as Code and policy-as-code tooling.
- Familiarity with payment platforms or financial services environments.
- Understanding of operational resilience frameworks and regulatory requirements affecting critical financial infrastructure.
- Relevant cloud or security certifications (AWS Security Specialty, CISSP, CCSP or similar).
**TECH STACK** ⚙️
- **AWS** – Cloud infrastructure and security controls.
- **Kubernetes** – Container orchestration and workload security.
- **Terraform** – Infrastructure as Code and security automation.
- **CI/CD tooling** – Secure software delivery, build security and deployment governance.
- **Container security tooling** – Image scanning, vulnerability management and runtime protection.
- **Identity & Access Management (IAM)** – Least privilege, RBAC and privileged access controls.
- **Software Supply Chain Security** – Dependency scanning, artefact signing, provenance and integrity controls.
- **Security monitoring & observability platforms** – Detection, auditability and operational visibility.
- **AI governance and security controls** – Supporting secure adoption of AI-enabled engineering capabilities.
**INTERVIEW PROCESS** ✍️
**Stage 1:** Screening Call with Talent Team
**Stage 2:** Kubernetes & Linux Interview
**Stage 3:** Cloud Security & Engineering Best Practices interview
We always aim to stick to the above process, however there may be occasions when an additional interview stage is needed for us to be sure we’re hiring the right fit for the role.
**HIRING LOCATIONS📍**
Here are the locations that we are looking to engage with contractors from. Please note, we are not looking to engage with contractors outside of these locations.
- Austria
- Bulgaria
- Croatia
- Cyprus
- Estonia
- Greece
- Hungary
- Italy
- Latvia
- Lithuania
- Malta
- Romania
- Slovakia
- Slovenia
All contractors start their first day in our office to collect the equipment needed to work remotely.
**ABOUT FORM3 💭**
Revolutionising the world of payments with our cloud-native, multi-cloud platform. For more information about Form3, check out the following pages:
[What we do](https://www.form3.tech/platform) | [Life at Form3](https://www.form3.tech/culture) | [Payments Cannot Fail Series](https://www.youtube.com/@Form3Cloud/podcasts) | [.Tech Podcast](https://techpodcast.form3.tech/episodes)
**OUR DEI&B COMMITMENT**
We hire talented people from a variety of backgrounds and experiences and are committed to a work environment based on diversity, open-mindedness and curiosity. We’re united by our company values (we even created them together!) and we celebrate our unique differences.
Our employee lifecycle processes are designed to embrace equal opportunity and prevent discrimination against our people regardless of personal characteristics. It is our strong belief that the more inclusive and belonging we are as a business, the better our work will be.
As an inclusive employer, we guarantee to interview all neurodiverse and physically disabled applicants who meet the minimum criteria for this role. We also encourage candidates to notify us of any reasonable adjustments that may be required during the recruitment process. This includes providing job adverts in alternative, accessible formats or adjustments required at interview stage.
If you consider yourself to be neurodiverse or physically disabled under the UN definition of disability and would like to be considered under this scheme and/or require any reasonable adjustments please let us know by sending an email to [careers@form3.tech](mailto:careers@form3.tech) clearly stating your consent for us to process this data.
For more information please refer to our [Recruitment Data Policy](https://www.form3.tech/legal/recruitment-data-policy).