onsite
Senior IT Security Engineer Application, Cloud & Data - Bitco Insurance Companies
Security Engineer
Lead the design, implementation, and continuous improvement of application, cloud, and data security controls, leveraging AWS, Azure, and DevSecOps practices to protect critical assets and ensure regulatory compliance.
About the role
Key Responsibilities
- Design, implement, and maintain security architectures for web, mobile, and API applications across multi‑cloud environments.
- Develop and enforce data protection strategies, including encryption, tokenization, and secure data lifecycle management.
- Integrate security controls into CI/CD pipelines using DevSecOps tools and automate vulnerability scanning, remediation, and compliance reporting.
- Conduct threat modeling, risk assessments, and security reviews for new and existing workloads, providing actionable recommendations.
- Collaborate with engineering, operations, and governance teams to define security standards, policies, and incident response procedures.
Requirements
- 5+ years of hands‑on experience securing applications and data in public cloud platforms (AWS, Azure, or GCP).
- Deep knowledge of application security frameworks (OWASP, SANS) and data protection regulations (PCI‑DSS, HIPAA, GDPR).
- Proficiency with DevSecOps tooling such as Terraform, Jenkins, GitHub Actions, container security, and automated scanning solutions.
- Experience performing threat modeling, risk assessments, and security architecture reviews.
- Relevant certifications (CISSP, CCSP, AWS Certified Security – Specialty, or equivalent) and strong communication skills.