# Staff Cloud Security Engineer (AWS)

[Solarisbank](https://gurify.com/jobs?q=Solarisbank) · Berlin · Posted 7 weeks ago

Contract

Principal

[Security](https://gurify.com/jobs/security)

[Cloud](https://gurify.com/jobs/cloud)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/solarisbank/jobs/8596423002-14)

## Job description

Solaris is Europe's leading embedded finance platform. Solaris’ full German banking license and proprietary modular B2B tech stack empowers its partners – from SMEs to large, multinational, non-financial companies – to offer compliant, customer-centric banking services, providing seamless experiences to customers across all industries. Founded in 2016, Solaris pioneered the Banking-as-a-Service market with an unparalleled combination of tech and banking. Solaris is headquartered in Berlin and employs 300 people in Europe.

### Your Role

- Partner closely with the existing Cloud Architecture and Engineering teams to audit the current AWS environment, identify security technical debt, and plan the refactoring of legacy resources into secure Terraform code.

- Design, deploy, tune, and maintain AWS WAF (Web Application Firewall) policies and rulesets to proactively protect corporate applications and APIs against application-layer attacks (OWASP Top 10, bots, and zero-day exploits).

- Establish and enforce cloud security guardrails, multi-account structures (AWS Organizations/Control Tower), and Service Control Policies (SCPs) in collaboration with the infrastructure team.

- Help on define and audit AWS Identity and Access Management (IAM) strategies, guiding engineering teams to transition from over-privileged legacy roles toward the principle of least privilege.

- Manage and optimize cloud-native security monitoring and detection tools (AWS Security Hub, GuardDuty, CloudTrail, Inspector, or KMS).

- Help on the incident respond for AWS-specific security alerts, performing cloud forensic analysis and coordinating containment strategies.

- Ensure the AWS cloud ecosystem remains fully compliant with relevant financial regulations, internal policies, and security frameworks (NIST, CIS, BaFin requirements).

- Lead the security automatizations on the AWS environment.

- Understanding of AWS native AI capabilities (ie Bedrock or Quick)

### We'd love to see

Depending on your level of experience, your responsibilities and scope of role will range. We don’t care much about fancy titles, but rather about real personal and professional development, as laid out in our learning framework. Let’s figure together out how you can contribute to our team.

- A degree in Computer Science, Cloud Computing, Cyber Security, Information Technology, or equivalent professional experience.

- You have spent 5+ years of dedicated professional experience in Cloud Security Engineering, with a proven track record of securing complex AWS environments.

- AWS WAF & Edge Security: Deep hands-on experience designing, implementing, and fine-tuning AWS WAF, AWS Shield, and CloudFront to protect public-facing application endpoints.

- Advanced Terraform & IaC: Strong proficiency in Terraform and auditing IaC templates for security drifts.

- AWS Security Governance: Mastery of AWS native security tools (IAM, KMS, Security Hub, GuardDuty) and multi-account security architecture.

- Collaboration with Engineering: Experience working alongside separate, established Cloud Architecture or DevOps teams, acting as a security consultant rather than a solo administrator.

- Understands agile workflows and lean principles.

- Technical leadership, cross-team collaboration, and cloud governance focus.

- Business proficient written and spoken English.

- Highly Valued Certification: AWS Certified Security - Specialty. AWS Certified Solutions Architect (Associate/Professional) is a strong plus.

- Exceptional diplomatic and communication skills to align security requirements with the objectives of the existing Architecture and Engineering teams.

- Thinking: Structured and analytical approach to untangling legacy cloud setups and defining clear, secure milestones.

- Empathic team player who avoids the "silo" mentality and focuses on enabling other teams to build securely.

- Proactive peer that helps the growth of the team.

- Curious, constant learner that is willing to share learning with others.

### Benefits

- Home office budget.

- Learning & development budget of €1000 per year and a transparent growth framework to support your career goals.

- Competitive salary and a variable remuneration program.

- Monthly meal allowance.

- Deutschland ticket subsidy.

- 28 vacation days, increasing by 2 days after 2 years and 3 days after 3 years with Solaris.

- Opportunity to work abroad for up to 12 weeks per year.

While job ads usually paint an ideal picture of a candidate, studies show that most applicants meet an average of 60% of the criteria. Unfortunately, many promising candidates tend to apply only if they meet all the criteria. So if you think you have what it takes, but don't necessarily meet every single item in the job description, please contact us anyway. We'd love to talk with you and find out if you might be a good fit for us.

At Solaris, we are committed to nurturing an inclusive environment, where all Solarians feel valued, respected and supported. We are dedicated to building a diverse workforce that reflects the diversity of our communities. We are committed to equal employment opportunity regardless of color, ethnicity, religion, sex, origin, disability, marital status, citizenship, or gender identity. We are proud to be an equal opportunity workplace. If you have a disability or special need that requires accommodation, please let us know.

### Information on data processing:

DE: https://www.solarisgroup.com/gdpr_notice_de
EN: https://www.solarisgroup.com/gdpr_notice_en

### The annual gross salary range for this position is:

€85.000—€110.000 EUR

**Live in Solarisbank’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- ST [Senior Product Security Engineer](https://gurify.com/job/senior-product-security-engineer-at-staffbase-46bf92e491d9) Staffbase · Berlin, Germany · last week
- LI [Product & AI Security Engineer](https://gurify.com/job/product-ai-security-engineer-at-linkedin-dde4a2718339) Linkedin · Berlin · last week
- SO [Cyber Security Engineer (Vulnerability Management & SecOperations)](https://gurify.com/job/cyber-security-engineer-vulnerability-management-secoperations-at-fcc0e5cd2dcb) Solarisbank · Berlin · 7 weeks ago
- GA [Security Engineer — Platform Security](https://gurify.com/job/security-engineer-platform-security-at-gallup-d8e240b6c682) Gallup · Berlin · 3 weeks ago
- ST [Senior Product Security Engineer](https://gurify.com/job/senior-product-security-engineer-at-staffbase-6f07e69045f7) Staffbase · Dresden, Germany · 4 weeks ago
- ST [Senior Product Security Engineer](https://gurify.com/job/senior-product-security-engineer-at-staffbase-555e2314269e) Staffbase · Chemnitz, Germany · 4 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Staff Cloud Security Engineer (AWS)","description":"\u003Cp\u003ESolaris is Europe\u0026#39;s leading embedded finance platform. Solaris\u2019 full German banking license and proprietary modular B2B tech stack empowers its partners \u2013 from SMEs to large, multinational, non-financial companies \u2013 to offer compliant, customer-centric banking services, providing seamless experiences to customers across all industries. Founded in 2016, Solaris pioneered the Banking-as-a-Service market with an unparalleled combination of tech and banking. Solaris is headquartered in Berlin and employs 300 people in Europe.\u003C/p\u003E\u003Ch3\u003EYour Role\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EPartner closely with the existing Cloud Architecture and Engineering teams to audit the current AWS environment, identify security technical debt, and plan the refactoring of legacy resources into secure Terraform code.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDesign, deploy, tune, and maintain AWS WAF (Web Application Firewall) policies and rulesets to proactively protect corporate applications and APIs against application-layer attacks (OWASP Top 10, bots, and zero-day exploits).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEstablish and enforce cloud security guardrails, multi-account structures (AWS Organizations/Control Tower), and Service Control Policies (SCPs) in collaboration with the infrastructure team.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHelp on define and audit AWS Identity and Access Management (IAM) strategies, guiding engineering teams to transition from over-privileged legacy roles toward the principle of least privilege.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EManage and optimize cloud-native security monitoring and detection tools (AWS Security Hub, GuardDuty, CloudTrail, Inspector, or KMS).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHelp on the incident respond for AWS-specific security alerts, performing cloud forensic analysis and coordinating containment strategies.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEnsure the AWS cloud ecosystem remains fully compliant with relevant financial regulations, internal policies, and security frameworks (NIST, CIS, BaFin requirements).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELead the security automatizations on the AWS environment.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnderstanding of AWS native AI capabilities (ie Bedrock or Quick)\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWe\u0026#39;d love to see\u003C/h3\u003E\u003Cp\u003EDepending on your level of experience, your responsibilities and scope of role will range. We don\u2019t care much about fancy titles, but rather about real personal and professional development, as laid out in our learning framework. Let\u2019s figure together out how you can contribute to our team.\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EA degree in Computer Science, Cloud Computing, Cyber Security, Information Technology, or equivalent professional experience.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou have spent 5\u002B years of dedicated professional experience in Cloud Security Engineering, with a proven track record of securing complex AWS environments.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAWS WAF \u0026amp; Edge Security: Deep hands-on experience designing, implementing, and fine-tuning AWS WAF, AWS Shield, and CloudFront to protect public-facing application endpoints.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAdvanced Terraform \u0026amp; IaC: Strong proficiency in Terraform and auditing IaC templates for security drifts.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAWS Security Governance: Mastery of AWS native security tools (IAM, KMS, Security Hub, GuardDuty) and multi-account security architecture.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECollaboration with Engineering: Experience working alongside separate, established Cloud Architecture or DevOps teams, acting as a security consultant rather than a solo administrator.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnderstands agile workflows and lean principles.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETechnical leadership, cross-team collaboration, and cloud governance focus.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBusiness proficient written and spoken English.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHighly Valued Certification: AWS Certified Security - Specialty. AWS Certified Solutions Architect (Associate/Professional) is a strong plus.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExceptional diplomatic and communication skills to align security requirements with the objectives of the existing Architecture and Engineering teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThinking: Structured and analytical approach to untangling legacy cloud setups and defining clear, secure milestones.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEmpathic team player who avoids the \u0026quot;silo\u0026quot; mentality and focuses on enabling other teams to build securely.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProactive peer that helps the growth of the team.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECurious, constant learner that is willing to share learning with others.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EBenefits\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EHome office budget.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELearning \u0026amp; development budget of \u20AC1000 per year and a transparent growth framework to support your career goals.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECompetitive salary and a variable remuneration program.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMonthly meal allowance.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDeutschland ticket subsidy.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E28 vacation days, increasing by 2 days after 2 years and 3 days after 3 years with Solaris.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOpportunity to work abroad for up to 12 weeks per year.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWhile job ads usually paint an ideal picture of a candidate, studies show that most applicants meet an average of 60% of the criteria. Unfortunately, many promising candidates tend to apply only if they meet all the criteria. So if you think you have what it takes, but don\u0026#39;t necessarily meet every single item in the job description, please contact us anyway. We\u0026#39;d love to talk with you and find out if you might be a good fit for us.\u003C/p\u003E\u003Cp\u003EAt Solaris, we are committed to nurturing an inclusive environment, where all Solarians feel valued, respected and supported. We are dedicated to building a diverse workforce that reflects the diversity of our communities. We are committed to equal employment opportunity regardless of color, ethnicity, religion, sex, origin, disability, marital status, citizenship, or gender identity. We are proud to be an equal opportunity workplace. If you have a disability or special need that requires accommodation, please let us know.\u003C/p\u003E\u003Ch3\u003EInformation on data processing:\u003C/h3\u003E\u003Cp\u003EDE: https://www.solarisgroup.com/gdpr_notice_de\u003Cbr /\u003EEN: https://www.solarisgroup.com/gdpr_notice_en\u003C/p\u003E\u003Ch3\u003EThe annual gross salary range for this position is:\u003C/h3\u003E\u003Cp\u003E\u20AC85.000\u2014\u20AC110.000 EUR\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"staff-cloud-security-engineer-aws-at-solarisbank-119d21b86ef8"},"url":"https://gurify.com/job/staff-cloud-security-engineer-aws-at-solarisbank-119d21b86ef8","datePosted":"2026-07-09","validThrough":"2026-10-14T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Solarisbank","sameAs":"https://job-boards.greenhouse.io/solarisbank"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"DE","addressLocality":"Berlin"}},"employmentType":"CONTRACTOR"}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Germany","item":"https://gurify.com/jobs/germany"},{"@type":"ListItem","position":3,"name":"Staff Cloud Security Engineer (AWS)","item":"https://gurify.com/job/staff-cloud-security-engineer-aws-at-solarisbank-119d21b86ef8"}]}
```
