Senior Cloud Security Engineer
Amgen · Portugal - Lisbon
Job description
Career CategoryInformation SystemsJob DescriptionJoin our team at AMGEN Capability Center Portugal, the #1 company in Best Workplaces™ (201–500 employees category) in 2024 by the Great Place to Work Institute. With over 400 talented individuals from more than 40 nationalities, our Lisbon center thrives at the intersection of innovation, excellence, and inspiration. This is your opportunity to explore the future of healthcare through technology and digital innovation, supporting our mission To Serve Patients. Senior Cloud Security Engineer At Amgen, technology is more than an enabler—it is a catalyst for discovery, transformation, and better patient outcomes. Every innovation you help deliver contributes to improving and saving lives. If you're passionate about cloud security, automation, and solving complex security challenges at enterprise scale, we'd love to hear from you. Live What you will do Amgen is seeking a Senior Cloud Security Engineer to join our Cloud Security Organization within the Global Cybersecurity and Digital Trust team. Based at our Lisbon Capability Center, you will play a key role in securing Amgen's global cloud platforms by designing, implementing, and continuously improving cloud security capabilities across AWS and other cloud environments. Working closely with engineering, infrastructure, DevOps, and security teams, you will strengthen Amgen's cloud security posture through automation, secure-by-design architectures, and operational excellence. You will also help drive the responsible adoption of AI technologies to enhance cloud security engineering, accelerate risk identification, and continuously improve the security posture of Amgen's cloud environments. Key Responsibilities Design, implement, and continuously improve secure cloud architectures across public, private, and hybrid cloud environments, aligned with enterprise security frameworks, Zero Trust principles, regulatory requirements, and industry best practices. Design and implement cloud network security architectures, including Zero Trust networking, micro-segmentation, Web Application Firewalls (WAF), API security, secure hybrid connectivity, and network segmentation to protect cloud-native and hybrid workloads. Design, engineer, implement, and maintain cloud security controls, including Identity and Access Management (IAM), Privileged Access Management (PAM), network segmentation, encryption, key management (KMS/HSM), secrets management, and certificate lifecycle management to protect cloud-native applications and infrastructure. Implement and optimize cloud security posture management (CSPM), cloud workload protection (CWPP), vulnerability management, and automated compliance solutions to continuously identify, prioritize, and remediate security risks. Design, develop, and maintain secure Infrastructure as Code (IaC) solutions using Terraform, CloudFormation, and policy-as-code frameworks to automate cloud provisioning and enforce security guardrails. Develop and maintain cloud governance frameworks, security baselines, guardrails, and landing zones across AWS, Azure, and Google Cloud Platform. Design and implement cloud-native logging, monitoring, and detection capabilities by integrating services such as AWS CloudTrail, Azure Monitor, GCP Cloud Logging, and cloud-native security tools into centralized SIEM and SOC platforms to improve threat detection, incident response, and operational visibility. Collaborate with Application Security, DevOps, Platform Engineering, and Application Development teams to embed security throughout the Software Development Lifecycle (SDLC) by integrating automated security testing, Infrastructure as Code scanning, secrets management, dependency analysis, and container security into CI/CD pipelines. Design and implement security controls for containerized, Kubernetes, serverless, and cloud-native application environments, ensuring secure deployment, runtime protection, and policy enforcement. Partner with Security Operations (SOC) and Incident Response (IR) teams to investigate, analyze, and respond to cloud security incidents, perform forensic analysis, root cause investigations, and threat hunting, and implement corrective and preventive security controls to enhance cloud security posture, detection capabilities, and operational resilience. Lead cloud security architecture reviews for cloud-native platforms, Kubernetes environments, managed cloud services, APIs, AI services, and enterprise applications, ensuring alignment with enterprise security standards, regulatory requirements, and secure-by-design principles. Conduct threat modeling and cloud security risk assessments to identify security threats, design appropriate mitigations, and validate security controls for new cloud solutions, services, and architectures. Evaluate emerging cloud, AI, and cybersecurity technologies to drive continuous improvement, automation, innovation, and operational efficiency across cloud security capabilities. Design and implement security controls for cloud-native AI and machine learning services, including Generative AI, LLM integrations, AI orchestration platforms, and AI development pipelines, ensuring secure access, data protection, governance, and regulatory compliance. Partner with Data Engineering, AI, and Platform Engineering teams to secure enterprise AI platforms (e.g., Databricks), AI workflows, and AI automation solutions while evaluating emerging AI technologies to drive innovation, automation, and continuous improvement. Develop and automate cloud security capabilities using scripting, APIs, Infrastructure as Code, and security orchestration to improve operational efficiency, consistency, and scalability. Develop, maintain, and continuously improve cloud security standards, reference architectures, technical documentation, operational procedures, and security runbooks to support secure engineering and operational excellence. Provide technical leadership, mentoring, and subject matter expertise to engineering, operations, architecture, and product teams, promoting cloud security best practices and secure-by-design principles. Support internal and external security audits, compliance assessments, and regulatory initiatives by providing evidence of cloud security controls and ensuring adherence to applicable standards and policies. Participate in after-hours support activities as required and travel occasionally. Win What we expect of you We value diverse perspectives and believe that every employee brings unique strengths to our mission of serving patients. The ideal candidate is a collaborative security professional with a strong technical foundation and a passion for cloud security. Preferred Qualifications Strong understanding of core information security principles, including authentication, authorization, confidentiality, integrity, and availability. Solid knowledge of secure design principles, including least privilege, defense in depth, and secure-by-design practices. Good understanding of cryptography concepts, including encryption, certificate management, and key lifecycle management. Strong experience securing AWS environments, including Identity and Access Management (IAM), Data Security, Network Security, Compute/Workload Security, Security operations, and secure DevOps practices. Working knowledge of enterprise cloud platforms across IaaS, PaaS, and SaaS environments, including AWS, Azure, GCP, Salesforce, Microsoft 365, Rafay or similar technologies. Knowledge of AI security principles, including securing Generative AI, large language model (LLM) applications, AI/ML workloads, and AI orchestration platforms (e.g., Databricks and n8n) in cloud environments. Experience implementing security controls for cloud-native AI services and platforms, including identity and access management, data protection, encryption, secrets management, API security, and network security. Experience securing AI development p
Verified and listed by ActiveJobs. Applications are made directly on Amgen's own career page — we never sit in the middle.