← Back to list
Job · Senior

Senior Security Engineer

Security Engineer • Senior • Hybrid • Full-time • Italy Milan, Italy

Docebo is looking for a Senior Security Engineer to secure the company's cloud infrastructure, with a primary focus on AWS: from designing security controls to runtime detection and compliance enforcement. Hybrid work with an on-call rotation.

Responsibilities

  • ▹Own the security posture of Docebo's AWS environments: define and enforce secure account structures, service control policies (SCPs), guardrails and baseline configurations across multi-account setups
  • ▹Evaluate and improve network segmentation, IAM boundaries and data protection controls
  • ▹Identify and remediate misconfigurations using CSPM tooling and manual review
  • ▹Partner with Cloud Infrastructure to integrate security controls into IaC workflows and define guardrails that catch insecure configurations before deployment
  • ▹Own security scanning in CI/CD pipelines and promote a shift-left approach to cloud security
  • ▹Participate in the on-call rotation for security incidents, including triage, containment and escalation for after-hours events
  • ▹Lead investigation and root cause analysis for cloud security incidents with clear written post-mortems
  • ▹Leverage automation and AI tooling to reduce mean time to detect and respond
  • ▹Build and maintain detection coverage for cloud-native threats (privilege escalation, unusual API activity, lateral movement, data exfiltration)
  • ▹Use CloudTrail, GuardDuty and SIEM integrations to maintain visibility across the AWS estate; align detection logic with MITRE ATT&CK for Cloud
  • ▹Own vulnerability management for cloud workloads: prioritize findings from configuration assessments and runtime protection tools, drive remediation, build automated enforcement
  • ▹Define and enforce least-privilege principles across AWS IAM, service accounts and federated identity; reduce standing access and enforce JIT access where appropriate
  • ▹Develop and document cloud security best practices, policies and procedures; provide guidance and training to engineering and infrastructure teams
  • ▹Maintain relationships with security vendors, ensure smooth operation of security tools and escalate problems to vendors when required

Requirements

  • ▹5+ years of relevant work experience in cybersecurity, with a strong focus on cloud security in production AWS environments
  • ▹Deep hands-on experience with AWS security services: IAM, SCPs, CloudTrail, GuardDuty, Config, KMS, VPC security and more
  • ▹Good knowledge of Kubernetes security: RBAC, pod security standards, network policies, admission controllers, secrets management
  • ▹Experience with cloud security posture management (CSPM) and cloud workload protection (CWPP/CNAPP) tools
  • ▹Experience securing IaC pipelines (Terraform, CloudFormation) and integrating security scanning into CI/CD workflows
  • ▹Good experience with container and image security: scanning, runtime protection, supply chain risk
  • ▹Experience with SIEM and detection engineering: building and tuning cloud-native detection rules, threat hunting across CloudTrail and application logs
  • ▹Familiarity with automation platforms and AI-driven security tools to streamline detection, enrichment and response
  • ▹Experience with Infrastructure as Code and scripting (Python, Bash or similar) to develop custom security tooling and automate workflows
  • ▹Strong IAM fundamentals: least privilege, cross-account roles, permission boundaries, federated identity, privileged access management
  • ▹Comfortable working across Azure/GCP in addition to AWS (multi-cloud exposure is a plus)
  • ▹In-depth knowledge of information security principles and frameworks relevant to cloud environments: MITRE ATT&CK for Cloud, CIS Benchmarks, AWS Well-Architected Security Pillar, NIST CSF, SOC 2, ISO 27001
  • ▹Willingness and ability to participate in an on-call rotation, including after-hours response
  • ▹Ability to produce clear, well-structured documentation (incident reports, architecture reviews, runbooks, security standards) and to communicate complex technical issues to non-technical stakeholders

Nice to have

  • ▹Security certifications such as those from ISC2, ISACA, SANS or CompTIA
  • ▹Cloud architecture certifications (AWS Security Specialty, AWS Solutions Architect or equivalent)

Soft skills

Builder's mindsetPartnering with engineering teamsClear risk communication to non-technical stakeholdersDecision making under pressureFast, high-ownership work

What we offer

  • ▹Hybrid work: three days a week in the office (Tuesday-Thursday), flexibility the rest of the week
  • ▹Employee Share Purchase Plan (ESPP) at a 15% discount, plus a competitive compensation package
  • ▹Health benefits
  • ▹Paid vacation days, two company-wide Docebo Days, floating holidays and your birthday off
  • ▹Family support and parental time
  • ▹Employee Resource Groups and global communities

About the company

Docebo is an AI-powered learning platform that helps organizations create, deliver and manage training in one place. It has more than 900 employees around the world.

Similar jobs