M

Senior Cloud Security Engineer - Payment Gateway Infrastructure

Mayflower • Cyprus
Visa Sponsorship Relocation
Apply
AI Summary

Design, implement, and manage secure cloud infrastructure for a payment gateway handling PCI DSS compliance. Automate security controls, CI/CD pipelines, and monitoring across AWS and Kubernetes environments. Requires 3+ years of DevSecOps experience with AWS security services and PCI DSS expertise.

Key Highlights
PCI DSS compliance for payment gateway infrastructure
DevSecOps automation and CI/CD security integration
AWS security services (WAF, GuardDuty, Security Hub, KMS)
Kubernetes and container security (Helm, Docker)
Security monitoring and incident response
Key Responsibilities
Design, implement, and manage infrastructure with security controls and secure configuration
Automate cloud operations ensuring deployments conform to security baselines
Implement infrastructure security best practices including IAM, network security, encryption, and monitoring
Develop and maintain CI/CD pipelines with automated security checks (SCA, SAST)
Implement security monitoring and logging systems using CloudWatch, CloudTrail, AWS Security Hub
Implement and manage security alerting mechanisms for incident detection and response
Conduct security assessments and periodic reviews mandated by PCI DSS
Manage and control access across various services
Prepare for and participate in PCI DSS audits
Collaborate with development, operations, and security teams on shared security responsibility
Train and advise team members on DevSecOps principles and secure engineering practices
Participate in task definition, estimation, and prioritization
Continuously optimize AWS infrastructure for security, performance, scalability, and cost efficiency
Maintain clear documentation and provide regular reports on security posture and audit readiness
Technical Skills Required
AWS DevSecOps Kubernetes PCI DSS
Benefits & Perks
EU-based employment contract
3-year Cyprus work visa sponsorship
Full relocation package (flights, apartment, support)
Private medical insurance
50% school fee coverage
Provident fund co-funded by employee and company
Transparent performance reviews with bonuses
Corporate mobile plan (unlimited in Cyprus)
Mindfulness & well-being support
Professional growth support (language courses, conferences)
Free office breakfasts and lunches
In-house electric scooter and bike rentals
Nice to Have
AWS Certified Solutions Architect
AWS Certified Security – Specialty
CISSP or CCSP certification
Experience implementing DevSecOps culture
Security champion programs and training for development teams
Terraform/OpenTofu and Terragrunt experience
CKS certification program knowledge
GitOps (Helmfile/ArgoCD/FluxCD) experience
Service mesh (Linkerd) experience

Job Description


Our team is developing a payment gateway for accepting funds from users on behalf of merchants, as well as sending funds from merchants to users. The system involves storing user payment data and is subject to PCI DSS compliance. It contains multiple integrations with payment systems, providers, and other gateways and processors, including 3DS.


Job Responsibilities:

  • Design, implement, and manage infrastructure with a focus on establishing security controls and ensuring secure configuration, in collaboration with DevOps.
  • Automate cloud operations, ensuring all deployments and configurations conform to security baselines.
  • Implement infrastructure security best practices such as IAM, network security, encryption, and monitoring.
  • Develop and maintain CI/CD pipelines that integrate automated security checks such as SCA and SAST.
  • Implement security monitoring and logging systems using services such as CloudWatch, CloudTrail, AWS Security Hub, and related tooling.
  • Implement and manage security alerting mechanisms, ensuring timely detection of and response to security incidents.
  • Apply security best practices in daily operations, including password management, phishing prevention, and security evaluation of new solutions.
  • Conduct security assessments and periodic reviews as mandated by PCI DSS, ensuring continuous maintenance of processes such as vulnerability and change management.
  • Manage and control access across various services.
  • Prepare for and actively participate in PCI DSS audits, ensuring controls and evidence are in place.
  • Collaborate with development, operations, and security teams to promote a culture of shared security responsibility across all stages of the system lifecycle.
  • Train and advise team members on DevSecOps principles and secure engineering practices.
  • Participate in task definition, estimation, and prioritization, and contribute to planning activities on weekly, monthly, quarterly, and annual horizons.
  • Continuously optimize AWS infrastructure for security, performance, scalability, and cost efficiency.
  • Maintain clear documentation and provide regular reports on security posture, audit readiness, and operational metrics.

Important and Challenging Tasks:

  • Preparation for and participation in PCI DSS audits.
  • Ensuring infrastructure compliance with high security standards.
  • Continuous improvement and optimization of infrastructure and security processes.

Technology Stack:

  • AWS (WAF, Shield, GuardDuty, Security Hub, KMS, Secrets Manager, Inspector, etc.)
  • Kubernetes, Docker, Helm
  • Terraform, Terragrunt, OpenTofu
  • GitLab CI/CD
  • SAML, SSO, MFA
  • ELK Stack, CloudWatch, CloudTrail
  • Linkerd

Job requirements

You’ll thrive here if you have:

  • 3+ years of experience with Cloud infrastructure.
  • Proficiency in DevSecOps tools and methodologies, including CI/CD, containerization (Docker), and orchestration (Kubernetes).
  • Knowledge and application of security best practices in cloud environments, particularly AWS.
  • Understanding of PCI DSS requirements and experience implementing and maintaining compliance in AWS.
  • Experience implementing security controls and monitoring for AWS (AWS WAF, Shield, GuardDuty, Control Tower, Security Hub, CloudTrail Insights, KMS, CloudHSM, Macie, Secrets Manager, Inspector).
  • Experience with logging and monitoring tools (AWS CloudWatch, ELK).
  • Deep understanding of networking concepts and protocols, including VPNs, firewalls, and load balancers.
  • Experience with security groups and IAM in AWS.
  • Experience with Helm.
  • Experience with SAML authentication configuration.
  • Experience with SSO solutions.
  • Knowledge of encryption techniques and key management.
  • English proficiency at B1 level or higher.

Preferred Qualifications:

  • AWS certifications (AWS Certified Solutions Architect, AWS Certified Security – Specialty).
  • Certified Information Systems Security Professional (CISSP) or Certified Cloud Security Professional (CCSP).
  • Experience implementing a DevSecOps culture within an organization.
  • Knowledge of security champion programs and security training for development teams.
  • Experience with Terraform / OpenTofu and Terragrunt.
  • Knowledge of the CKS (Certified Kubernetes Security Specialist) certification program.
  • Knowledge of GitOps (Helmfile / ArgoCD / FluxCD).
  • Experience with service mesh (Linkerd).


Conditions

We know that great talent deserves great conditions, so here's what you can expect when joining us:

  • EU-based employment contract and a 3-year Cyprus work visa with full support for your relocation and visa processes, including assistance for your family.
  • EU passport. Opportunity to obtain an EU passport after 4 years of residence
  • Full relocation package: flights to Limassol for you and your family, a company-covered apartment for the first month, and full relocation support to make your move smooth and hassle-free.
  • Provident fund (Cyprus): a long-term savings plan co-funded by you and the Company together (available after probation) that grows throughout your time with us in Cyprus.
  • Transparent performance reviews twice a year, with bonus opportunities and salary adjustments.
  • Private medical insurance for you and your family
  • Corporate mobile plan (unlimited in Cyprus with roaming included)
  • Mindfulness & well-being support, including psychological assistance with 50% coverage.
  • 50% coverage of school and kindergarten fees for your children.
  • Fully covered sports benefits, and also access to in-house electric scooters and bike rentals
  • Professional growth support: language courses, conferences, training programs, and coaching.
  • Peer recognition program: receive and share kudos for great work.
  • A fully equipped office in Limassol’s city center, with everything you need for deep work and collaboration.
  • Free breakfasts and lunches in the office and an in-house coffee bar with high-quality drinks and a health bar stocked with nutritious snacks.
  • A strong engineering culture: international teams, corporate events, team buildings, and hackathons — because great work happens in great communities.


Recruitment process

  • HR interview (40 min);
  • Technical interview (1.5 hour);
  • Final interview;
  • Recommendations check;
  • Job Offer.

Similar Jobs

Explore other opportunities that match your interests

SRE Engineer

Devops
•
4d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

fingular

Cyprus

Senior Database Platform Engineer (PostgreSQL)

Devops
•
6d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

nexters ($gdev)

Cyprus
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Entry level

arival bank

Cyprus

Subscribe our newsletter

New Things Will Always Update Regularly