About the job
Join our dynamic tech team at manusai as a Senior Information Security Engineer. In this crucial role, you will spearhead the design, implementation, and enhancement of security measures across our extensive global multi-cloud environment. Your expertise will not only address security incidents but will also shape innovative security strategies for the future.
Key Responsibilities
Threat Modeling & Incident Response: Establish and uphold global cloud security incident response protocols, craft comprehensive playbooks, and lead routine drills. Efficiently manage intricate security incidents, perform thorough root cause analyses (RCA), and implement safeguarding measures.
Security Architecture & Operations: Conceptualize, deploy, and sustain security solutions across multi-cloud platforms (AWS, GCP, Azure), ensuring that architecture is scalable, resilient, and adaptable to future needs.
Enterprise Security Leadership: Align security strategies with business objectives, enhancing the overall security maturity of the organization.
Compliance & Automation: Ensure adherence to international security standards such as ISO 27001, ISO 27701, and SOC 2. Advocate for security automation and “Security as Code” initiatives to elevate operational efficiency.
Vulnerability Management & Penetration Testing: Execute regular vulnerability assessments, risk evaluations, and penetration tests. Monitor emerging threats and coordinate remediation efforts effectively.
Qualifications
Required:
Bachelor’s degree in Computer Science, Cybersecurity, or a related discipline, coupled with a minimum of 3 years of experience in information security.
Extensive knowledge in cloud security, with practical experience in at least two major cloud platforms (AWS, GCP, Azure) and associated security tools (e.g., AWS Security Hub, GCP Security Command Center).
Proficient in Linux system security, including hardening, log analysis, intrusion detection, and incident response.
Demonstrated ability to manage high-pressure security incidents and conduct effective post-incident reviews.
In-depth knowledge of web and application security, with experience in penetration testing and code reviews.
Preferred:
Relevant certifications such as CISSP, CISM, or similar.
Experience with security-related scripting and automation.

