Overview
In this role you secure Docebo’s AWS-based cloud stack, partnering with Infrastructure, Engineering, and security teams. You design and enforce cloud security controls, improve IaC security, and lead incident response and post-mortems. You’ll build cloud detection, manage vulnerabilities, and uphold least-privilege access while supporting a security-aware culture. This hands-on role offers impact across architecture, operations, and threat detection at scale.
Pay / Benefits
- Employee Share Purchase Plan (ESPP) at 15% discount
- health benefits
- paid vacation days
- Docebo Days
- floating holidays
- birthday off
Responsibilities
- Own the security posture of Docebo’s AWS environments, including multi-account structure, SCPs, guardrails and secure baselines
- Integrate security into IaC workflows, set guardrails for secure deployments, and lead security scanning in CI/CD pipelines
- Participate in on-call rotation for security incidents, lead investigations and post-mortems
- Develop and maintain cloud-detection coverage for threats using CloudTrail, GuardDuty, and SIEM integrations, aligned to MITRE ATT&CK for Cloud
- Manage vulnerability & configuration management for cloud workloads and drive remediation with engineering teams
- Enforce least-privilege IAM principles across AWS accounts, roles, and federated identities
- Develop security best practices, policies, and provide guidance to engineering and infrastructure teams
- Maintain vendor relationships for security tools and escalate incidents when needed
Key requirements
- 5+ years in cybersecurity with focus on cloud security in production AWS environments
- Deep hands-on experience with AWS security services (IAM, SCPs, CloudTrail, GuardDuty, Config, KMS, VPC security)
- Knowledge of Kubernetes security (RBAC, pod security standards, network policies, admission controllers, secrets management)
- Experience with CSPM/CWPP tools and securing IaC pipelines (Terraform, CloudFormation)
- Container and image security, including scanning and runtime protection
- SIEM and detection engineering experience; threat hunting across CloudTrail and logs
- Familiarity with automation and AI-driven security tools for detection/enrichment/response
- IaC scripting (Python, Bash or similar) for custom tooling
- Strong IAM fundamentals and cross-account/federated identity concepts
- Willingness to participate in on-call rotations; multi-cloud familiarity a plus
- Certifications in ISC2/ISACA/SANS/CompTIA and AWS security-related architecture certifications are a plus
- Strong communication of risk to non-technical stakeholders
- Collaborative partner mindset with engineering and infra teams
- Ability to work under pressure during on-call incidents
- AWS security services (IAM, SCPs, CloudTrail, GuardDuty, Config, KMS, VPC)
- Kubernetes security (RBAC, pod security standards, network policies)
- CSPM/CWPP tools
…
