Cloud Security Engineer (M/F)

SIEMENS S.A.SRhôneEURESpublished 08/06/2026
Must-have:AWSDockerKubernetesCloudDevOpsSecurity
Machine translation — original language: French.Show original

Job Description:

The Siemens Digital Industries Software portfolio accompanies all industrial sectors (Automotive, Aerospace, Electronics, Energy, Pharma, Cosmetics, Food & Beverage) in their digital transformation.

Come demonstrate your ingenuity alongside us and give new meaning to your career in a dynamic, innovative, and human environment!

Your playground:

Do you dream of designing and defending robust cloud architectures? Of working on SaaS applications protecting thousands of users? Our cloud portfolio is expanding rapidly and we need a passionate cloud expert to consolidate our SaaS posture, automate our security controls, and become the "guardian" of our cloud infrastructure.

Audit and hardening of our AWS configurations (IAM, networking, storage). Implement end-to-end container vulnerability management. Automate the detection of cloud misconfigurations (shift-left). Implement cloud security best practices (CIS Benchmarks, AWS Well-Architected). Reduce our "blast radius" in case of an incident (data exposure, compromise). Mentor DevOps/Dev teams on "secure by design & by default" principles.

Your responsibilities:

  1. AWS Architecture & Security (35%)

You will design and maintain secure cloud architectures. VPC & Networking Design: VPC architecture, subnets, Security Groups, NACLs, VPC Flow Logs. Identity & Access Management (IAM): Granular policies, role-based access, least privilege, service accounts. Data Protection: Encryption at rest (KMS, S3 encryption), encryption in transit (TLS), secrets management (AWS Secrets Manager, HashiCorp Vault). Container Security: ECR scanning, image hardening, runtime security. S3 Security: Bucket policies, ACLs, public access block, versioning, MFA delete.

  1. Container Vulnerability Management & ECR Security (30%)

You will manage vulnerabilities end-to-end. Deploy & maintain container scanning tools. Docker image integrity control. Keep images up to date. Triage vulnerabilities and establish remediation SLAs. Collaborate with teams to fix vulnerabilities.

  1. Infrastructure-as-Code (IaC) Security (10%)

You will secure our CloudFormation. Code review of infrastructure changes. IaC scanner to detect vulnerabilities before deployment (Checkov). Create "secure by default" templates. Establish security standards for IaC across the organization.

  1. Collaboration & Mentoring (5%)

You will guide DevOps/Dev teams towards "secure by design & by default". Code review of teams' cloud configurations. Awareness sessions on cloud security best practices. Mentor junior engineers on cloud security. Participate in security incident management.

This permanent contract (CDI) is based at our Lyon (69) site and is available as soon as possible.

Status: Executive (Cadre)

Assets for success: Good experience in cloud security or AWS infrastructure.

Profile Description:

Assets for success: Good experience in cloud security or AWS infrastructure.

  • 2+ years of hands-on experience with AWS (core products: IAM, VPC, EC2, S3, KMS).
  • Track record of 5+ secure Cloud architectures designed/audited in production.
  • Experience with containerization (Docker, Kubernetes) and container security.
  • Fluent English (communication in an international context).