- Location
- Czechia · Slovakia
- Type
- Full-time
- Department
- G&A - GIST
- Seniority
- Senior
- Source
- Greenhouse
Description
- We're taking autonomous search mainstream, making product discovery more intuitive and conversational for customers, and more profitable for businesses.
- We’re making conversational shopping a reality, connecting every shopper with tailored guidance and product expertise — available on demand, at every touchpoint in their journey.
- We're designing the future of autonomous marketing, taking the work out of workflows, and reclaiming the creative, strategic, and customer-first work marketers were always meant to do.
About the Role
You will serve as a trusted security partner to Engineering, DevOps, and IT, designing and hardening secure AWS environments, securing our containerized and Linux-based workloads, and protecting our corporate infrastructure and identity/access tooling — while partnering closely with our dedicated SOC team on detection and response.
You will act as a key member of the Cloud Security team, owning cloud and corporate infrastructure security architecture, vulnerability remediation, and Splunk administration and data integration, in close partnership with the SOC team, which owns detection content, alerting, playbooks, and incident triage/response.
Your Job Will Be (but not limited to)
- Design, implement, and monitor security controls across our AWS cloud infrastructure, applying platform-native services (e.g., IAM, GuardDuty, Security Hub, KMS, VPC/Security Groups, Config) and secure architecture patterns to protect production environments.
- Maintain deep working knowledge of the AWS security service landscape, evaluating new and existing services to close coverage gaps and strengthen our security architecture.
- Secure our Linux server fleet and containerized workloads (Docker, Kubernetes), including host hardening, image and runtime security, and Kubernetes cluster and workload configuration.
- Own the security of our corporate infrastructure, including security configuration and administration of identity and access tooling such as JumpCloud and zero-trust network access tooling such as Twingate.
- Administer and integrate Splunk as a data platform — onboarding new log sources, maintaining data pipelines, and supporting platform health and licensing — in partnership with the SOC team, which owns detection content, alerting logic, and playbooks.
- Identify, triage, and drive remediation of infrastructure and web application vulnerabilities, partnering with engineering teams to reduce MTTR and improve remediation rates.
- Lead CVE lifecycle management and patching efforts, performing root cause analysis and tracking remediation metrics across cloud, corporate, and on-prem systems.
- Build and maintain secure automation and tooling for vulnerability remediation and infrastructure hardening using Python, Go, or Bash or similar scripting languages.
- Implement security guardrails and policy-as-code within Infrastructure as Code (IaC) and CI/CD pipelines, performing static IaC scanning and enforcing security baselines prior to deployment.
- Define logging and telemetry requirements for cloud, container, and corporate infrastructure assets, ensuring the SOC team has the data coverage needed for effective detection.
- Develop, document, and operationalize security architecture standards for cloud, container, and corporate infrastructure, partnering with engineering pillars and IT to drive adoption across the organization.
- Partner with the SOC team on incident response as a technical subject-matter expert for cloud, container, and corporate infrastructure
- Mentor junior security engineers and prioritize security initiatives based on risk and business impact, driving continuous improvement of the organization's cloud and corporate infrastructure security posture.
Professional Experience and Skills Requirements
- 6+ years of hands-on experience in cybersecurity engineering, with a focus on cloud security, infrastructure security, and system hardening.
- Deep, hands-on experience securing AWS environments, including secure architecture design, IAM, and applying native AWS security services (e.g., GuardDuty, Security Hub, KMS, Config, Inspector).
- Strong working knowledge of Linux system administration and hardening, and hands-on experience securing containerized environments (Docker and Kubernetes).
- Experience securing corporate infrastructure and identity/access tooling, such as JumpCloud, Twingate, or comparable zero-trust/IAM platforms.
- Experience administering and integrating Splunk (or comparable data/SIEM platforms) as a log and data pipeline, including onboarding data sources and maintaining platform health.
- Demonstrated ownership of the vulnerability and CVE lifecycle, including triage, root cause analysis, patching, and MTTR/remediation-rate reporting.
- Proficiency in scripting and automation (Python, Go, or Bash) to build or extend security tooling for hardening and remediation.
- Experience implementing policy-as-code and security guardrails within CI/CD pipelines, including static IaC scanning and pre-deployment security baselines.
- Working knowledge of common security frameworks (CIS, NIST) and typical weaknesses exploited in infrastructure, containers, and web applications.
- Strong cross-functional communication skills, with experience partnering closely with SOC, engineering, and IT teams on shared security outcomes.
- Experience mentoring junior engineers and prioritizing security work based on risk and business impact.
- Relevant certifications preferred: AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, or CCSK.
Your Success Story Will Be
In the First 30 Days
- Develop a foundational understanding of Bloomreach's AWS environment, corporate infrastructure, and existing security controls, including JumpCloud and Twingate configurations.
- Become familiar with the Cloud Security team's tooling, current Splunk data integrations, and how the team partners with the SOC on detection coverage.
- Review current CVE/vulnerability management processes, IaC pipelines, and security baselines for cloud, container, and Linux environments.
- Establish working relationships with Engineering, DevOps, IT, and the SOC team.
- Identify quick-win opportunities to strengthen existing hardening, IaC guardrails, or corporate infrastructure configurations.
In the First 60 Days
- Independently triage and drive remediation of infrastructure, container, and web vulnerabilities identified through scanning and assessments.
- Onboard at least one new data source into Splunk and contribute to maintaining existing data pipelines.
- Contribute to IaC security scanning and policy-as-code enforcement within CI/CD pipelines.
- Partner with Engineering and IT to close CVE and patching gaps, tracking MTTR and remediation-rate metrics.
- Begin mentoring junior team members on cloud and infrastructure security fundamentals.
In the First 90 Days
- Own end-to-end security architecture reviews for at least one major AWS workload or corporate infrastructure system, independently identifying risks and driving mitigations.
- Demonstrate hands-on ownership of Linux, container, and Kubernetes security hardening for at least one environment.
- Propose improvements to security architecture standards or automation based on observed gaps.
- Demonstrate consistent ownership of vulnerability and CVE lifecycle management with minimal supervision.
- Actively mentor junior engineers and contribute to prioritization of the team's security roadmap.
#LI-HO1
The pay range actually offered will take into account a variety of potential factors considered in compensation, including but not limited to skills, qualifications, geographic location, accomplishments, experience, credentials, internal equity and business needs, and may vary from the range listed above.
More things you'll like about Bloomreach:
Culture:
-
A great deal of freedom and trust. At Bloomreach we don’t clock in and out, and we have neither corporate rules nor long approval processes. This freedom goes hand in hand with responsibility. We are interested in results from day one.
-
We have defined our 5 values and the 10 underlying key behaviors that we strongly believe in. We can only succeed if everyone lives these behaviors day to day. We've embedded them in our processes like recruitment, onboarding, feedback, personal development, performance review and internal communication.
-
We believe in flexible working hours to accommodate your working style.
-
We work virtual-first with several Bloomreach Hubs available across three continents.
-
We organize company events to experience the global spirit of the company and get excited about what's ahead.
-
We encourage and support our employees to engage in volunteering activities - every Bloomreacher can take 5 paid days off to volunteer*.
-
The Bloomreach Glassdoor page elaborates on our stellar 4.7/5 rating. The Bloomreach Comparably page Culture score is even higher at 4.9/5
Personal Development:
-
We have a People Development Program - participating in personal development workshops on various topics run by experts from inside the company. We are continuously developing & updating competency maps for select functions.
-
Our resident communication coach Ivo Večeřa is available to help navigate work-related communications & decision-making challenges.*
-
Our managers are strongly encouraged to participate in the Leader Development Program to develop in the areas we consider essential for any leader. The program includes regular comprehensive feedback, consultations with a coach and follow-up check-ins.
-
Bloomreachers utilize the $1,500 professional education budget on an annual basis to purchase education products (books, courses, certifications, etc.)*
Well-being:
-
The Employee Assistance Program -- with counselors -- is available for non-work-related challenges.*
-
Subscription to Calm - sleep and meditation app.*
-
We organize ‘DisConnect’ days where Bloomreachers globally enjoy one additional day off each quarter, allowing us to unwind together and focus on activities away from the screen with our loved ones.
-
We facilitate sports, yoga, and meditation opportunities for each other.
-
Extended parental leave up to 26 calendar weeks for Primary Caregivers.*
Compensation:
-
Restricted Stock Units or Stock Options are granted depending on a team member’s role, seniority, and location.*
-
Everyone gets to participate in the company's success through the company performance bonus.*
-
We offer an employee referral bonus of up to $3,000!
-
We reward & celebrate work anniversaries -- Bloomversaries!*
(*Subject to employment type. Interns are exempt from marked benefits, usually for the first 6 months.)
Excited? Join us and transform the future of commerce experiences!
If this position doesn't suit you, but you know someone who might be a great fit, share it - we will be very grateful!
Any unsolicited resumes/candidate profiles submitted through our website or to personal email accounts of employees of Bloomreach are considered property of Bloomreach and are not subject to payment of agency fees.
#LI-Remote