About the job
Ebury is dedicated to empowering ambitious businesses in their quest for global expansion, and we extend that same commitment to our employees. We foster an innovative and collaborative environment that encourages problem-solving and ensures that everyone feels valued, supported, and empowered to thrive.
If you're a team player eager to reshape the way businesses function on a global scale, reach out to us! We're excited to discuss how Ebury can elevate your career and help you influence the future.
Senior Cloud Infrastructure Security Engineer
Hybrid (4 days in office) in Madrid
Ebury is making substantial investments in its cloud infrastructure security to uphold the trust and safety of our worldwide financial services. As a Senior Security Engineer specializing in Cloud Infrastructure, you will take charge of enhancing the security framework of our cloud environments across AWS and GCP, focusing on network security, perimeter defense, and attack surface management.
This hands-on position demands extensive knowledge of cloud-native security controls, network architecture, and defensive security operations. You will design, implement, and sustain security infrastructure that proactively identifies and mitigates threats before they affect our business. Close collaboration with platform, infrastructure, and security operations teams will be essential to instill security best practices within our cloud foundations.
Key Responsibilities
- Own cloud security posture and attack surface management: Maintain comprehensive visibility and control across AWS and GCP environments. Implement cloud-native security monitoring, detection, and alerting to proactively identify and mitigate threats before they impact customers or the business. Define and enforce security baselines using policy-as-code.
- Design and maintain web application firewall infrastructure: Manage WAF configurations across AWS and GCP, developing and tuning detection rules in line with application threat models and emerging attack patterns. Establish operational processes for rule lifecycle management and incident response integration, collaborating with application teams to implement protections without compromising availability.
- Architect network segmentation and isolation: Develop and execute network security strategies ensuring proper separation between development, staging, and production environments. Define consistent patterns across multi-cloud infrastructure, applying zero-trust principles to workload communication and documenting reference architectures for engineering teams.

