Senior Engineer - Cloud Engineering
- Hiring from
- Colombia
- Work type
- Hybrid
- Posted
524,705 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
For more than 40 years, Accelya has been the industry’s partner for change, simplifying airline financial and commercial processes and empowering the air transport community to take better control of the future. Whether partnering with IATA on industry-wide initiatives or enabling digital transformation to simplify airline processes, Accelya drives the airline industry forward and proudly puts control back in the hands of airlines so they can move further, faster.
Location: Bogota, Colombia (Hybrid Scheme: 2 days per week in the office)
About the Role
- We're looking for a hands-on Cloud Security Engineer to serve as our remediation subject matter expert (SME) across our AWS environment. This role owns the full lifecycle of security findings — from identifying code-level vulnerabilities to triaging and remediating Upwind Cloud Security Posture Management (CSPM) findings across our cloud platform. Beyond remediation, you'll support incident investigations and contribute to cloud security architecture reviews, working closely with engineering, DevOps, and platform teams to close gaps quickly and durably.
- This is not a policy-only or advisory position — you'll be in the code, the console, and the pipelines fixing things.
Key Responsibilities
Vulnerability Analysis & Remediation
- Analyze code for security vulnerabilities (SAST/SCA output, dependency issues, insecure configurations, IaC misconfigurations) and work with development teams to remediate.
- Triage, prioritize, and drive remediation of Upwind CSPM findings across AWS accounts, workloads, and services.
- Own remediation runbooks and track findings through to closure, including root-cause fixes rather than one-off patches.
- Partner with engineering teams to remediate issues in Terraform/CloudFormation, container images, and application code.
Cloud Security Operations
- Act as the go-to SME for AWS security tooling and findings (Security Hub, GuardDuty, Config, IAM Access Analyzer, Inspector, Upwind, and related CNAPP/CSPM tools).
- Maintain and improve detection and remediation workflows, including automation where feasible (Lambda, EventBridge, SSM Automation).
- Track posture metrics and report on remediation velocity, aging findings, and risk trends.
Incident Response & Investigations
- Assist in cloud security incident investigations — log analysis (CloudTrail, VPC Flow Logs, GuardDuty findings), scoping impact, and supporting containment/remediation.
- Contribute to post-incident reviews and help translate findings into preventive controls.
Architecture & Design Review
- Participate in cloud security architecture reviews for new services and major changes, evaluating IAM design, network segmentation, encryption, and data protection.
- Provide practical, risk-based recommendations that balance security with delivery timelines.
Required Qualifications
- 3+ years of hands-on experience in cloud security, with deep, practical AWS experience (IAM, VPC, KMS, S3, CloudTrail, Security Hub, GuardDuty, Config, Inspector).
- Direct experience remediating findings from a CSPM/CNAPP platform (Upwind, Wiz, Prisma Cloud, Orca, or similar) — not just reviewing dashboards, but fixing the underlying issues.
- Experience analyzing and remediating application/code-level vulnerabilities (SAST, SCA, container image scanning).
- Working knowledge of Infrastructure as Code (Terraform and/or CloudFormation) and the ability to remediate misconfigurations directly in code.
- Scripting ability in Python and/or Bash for automation and investigation tasals.
- Familiarity with incident response processes and cloud-native log sources.
- Strong written and verbal communication skills — able to explain technical risk to both engineers and non-technical stakeholders.
- Fluent English: Interviews will be held in this language.
Preferred Qualifications
- Experience securing containerized workloads (EKS, ECR, Kubernetes security policies).
- Exposure to CI/CD security integration (scanning gates, policy-as-code, pipeline hardening).
- Familiarity with compliance frameworks relevant to the business (SOC 2, ISO 27001, PCI-DSS, GDPR) and especially, NIST 800-53 Baseline Controls.
- AWS certifications (Security Specialty, Solutions Architect) or vendor CSPM certifications.
- Prior experience in a dedicated cloud security or DevSecOps team.
- What Success Looks Like in This Role
- Upwind findings backlog is actively triaged, with clear ownership and shrinking mean-time-to-remediate.
- Code-level vulnerabilities are caught and fixed before or shortly after deployment, not left open indefinitely.
- Engineering teams see this role as a trusted partner for fixing issues, not just flagging them.
- Incident investigations move faster because this person can navigate logs, findings, and architecture without hand-holding.
Nice To Haves:
- Experience with ethical hacking.
- Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), GIAC Certified Incident Handler, (GCIH), Certified Information Systems Security Professional (CISSP).
What does the future of the air transport industry look like to you? Whether you’re an industry veteran or someone with experience from other industries, we want to make your ambitions a reality!
About Us
For more than 40 years, Accelya has been the industry’s partner for change, simplifying airline financial and commercial processes and empowering the air transport community to take better control of the future. Whether partnering with IATA on industry-wide initiatives or enabling digital transformation to simplify airline processes, Accelya drives the airline industry forward and proudly puts control back in the hands of airlines so they can move further, faster.
Introduce Yourself
Not finding the right fit? Let us know you're interested in a future opportunity by clicking Get Started below or create an account by clicking 'Sign In' at the top of the page to set up email alerts as new job postings become available that meet your interest!