Manager, Cloud Security
Listed on 2026-01-01
-
IT/Tech
Cybersecurity, Cloud Computing
The Team
Within our Info Sec organization, Our global security engineering team is responsible for designing, building, and enhancing the underlying security components that help with securing the Celonis Application and Platforms stacks. We think about both offensively and defensively. We continuously monitor our global security posture and are always adapting to the ever-changing threat landscape. The security engineering team is looking for talented subject matter experts in application, platform and offensive security.
The RoleProvide strategic leadership and hands-on expertise to secure Celonis’ multi-cloud infrastructure (AWS, Azure, GCP). This Manager of Cloud Security will drive the cloud security strategy, ensuring robust protection of our SaaS platform. You will lead a team of security engineers, setting best practices and fostering a culture of security excellence. The role balances high-level strategy with deep technical involvement in day-to-day cloud security operations.
Thework you’ll do
Leadership & Strategy: Lead, mentor, and develop a team of cloud security engineers. Implement the cloud security roadmap and ensure alignment with Celonis’ business goals and risk posture.
Cloud Security Controls: Design and implement security controls across AWS, Azure, and GCP environments. Continuously enhance our cloud security posture management (CSPM) program to identify and remediate risks in configurations and policies.
Container & Kubernetes Security: Oversee security for containerized applications and Kubernetes clusters (EKS, AKS, GKE). Establish best practices for container image security, pod security policies, and cluster network segmentation to protect our microservices.
Tools Integration: Integrate and manage advanced security tools into our infrastructure. This includes solutions like Teleport for secure access management and Tenable for vulnerability scanning and management. Ensure these tools are effectively used to protect cloud endpoints, and refine their configurations to fit Celonis’ environment.
Cross-Team
Collaboration:
Work closely with security automation, enterprise security, and engineering teams to embed security into CI/CD pipelines and infrastructure provisioning. Champion a secure guardrails approach—automating security checks and educating teams to build secure systems from the ground up.Incident Response & Compliance: Collaborate with Security Operations to respond to cloud security incidents, performing root-cause analysis and implementing preventive measures. Ensure cloud architectures meet and industry benchmarks and participate in audits as needed.
Extensive Cloud Security
Experience:
Over 7 years of hands-on experience in information security, specializing in securing cloud infrastructure across AWS, Azure, and GCP. Demonstrated managerial experience (3-5 years) leading security teams, driving the implementation of best practices, and securing cloud services in production environments. Proven ability to manage complex security projects, mentor team members, and deliver scalable security solutions across multi-cloud platforms.Technical Expertise: Deep expertise in identity and access management (IAM), network security (VPCs, security groups, firewalls), and container security, including hands-on experience with Container Network Interfaces (CNI) such as Cilium. Extensive practical experience securing Kubernetes orchestrations and container ecosystems. Proficient with infrastructure-as-code tools (Terraform, Cloud Formation) and automation/scripting (Python, Bash) to enforce scalable, automated security measures. Experienced in offensive cloud security assessments using tools such as Scout Suite, Prowler, Cloud Sploit, Pacu, and similar cloud security auditing utilities, with the ability to proactively identify and remediate vulnerabilities.
Leadership
Skills:
Demonstrated ability to lead and mentor security teams or projects. Strong project management and communication skills to articulate risks and influence technical and non-technical stakeholders.Security Best Practices: Up-to-date understanding of modern cloud security practices…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).