Mondoo is creating a new way that helps companies keep their users and data safe from hackers around the world. We believe that a great user experience and visual design will help our users to love and enjoy our product and make it easier to take action against attackers.
Your impact
You will have a direct impact on the Mondoo Platform including our policy engine, resources, scale, and multi-region functionality. You will be helping teams to assess, scope, prioritize, triage and remediate security findings.
Key responsibilities
We're seeking a talented Platform Engineer who is eager to enhance their expertise in security. This position offers the opportunity to work with cutting-edge technologies and gain hands-on experience in "policy as code" frameworks while contributing to our dynamic team.
In this role, you will:
Build, manage, and optimize cloud infrastructure using Infrastructure as Code (IaC) tools like Terraform and CloudFormation.
Automate system configurations using tools like Ansible, Puppet, or Chef.
Collaborate with teams to ensure seamless integration of infrastructure with CI/CD pipelines.
Assist in translating high-level security requirements into practical policy as code implementation within cloud and on-premises environments.
Review vulnerability reports submitted by external users
Participate in gathering evidence for our audits
Support the implementation and scaling of automated security controls in Kubernetes, cloud environments (AWS, Azure, GCP), and operating systems.x5
Stay updated on infrastructure management and automation trends, ensuring a robust and scalable system foundation
Required qualifications
Strong hands-on experience with IaC tools like Terraform or CloudFormation.
Proficiency in configuration management tools such as Ansible, Puppet, or Chef.
Solid understanding of at least one major cloud platform (AWS, Azure, or GCP) and its core services.
Experience working with container technologies like Docker and orchestration tools like Kubernetes.
Comfortable scripting in at least one language (e.g., Python, Bash, or similar).
Knowledge of networking basics (TCP/IP, DNS, etc.).
Experience with version control systems (e.g., Git).
Strong problem-solving and analytical skills.
Willingness to learn and grow into a role focused on security policies and automation.
Excellent communication skills with the ability to work effectively in a collaborative team environment.
Able to handle one-off requests while still maintaining the rest of the work
Preferred qualifications
Familiarity with security tools and concepts such as policy as code frameworks (Open Policy Agent, Sentinel).
Knowledge of compliance standards (e.g., CIS, SOC 2, ISO 27001).
Previous exposure to cloud-native security tools and services.
Relevant certifications in cloud platforms (e.g., AWS, Azure, GCP).
A keen interest in learning about security best practices, frameworks, and tools.
Application Process
As part of your application, please share links to your GitHub/GitLab repositories or a portfolio of projects that demonstrate your experience with security policy implementation, policy as code, and relevant cloud security tools. We're particularly interested in seeing examples that showcase your ability to translate complex security requirements into executable code for cloud environments.
If you're passionate about enhancing cloud security through code, implementing scalable and automated security policies across cloud platforms, participating in collaborative security design processes, and staying at the forefront of cloud security best practices, we'd love to hear from you!
Skills Required
- Strong hands-on experience with Terraform or CloudFormation
- Proficiency with Ansible, Puppet, or Chef
- Understanding of at least one major cloud platform: AWS, Azure, or GCP
- Experience with Docker and Kubernetes
- Scripting experience in Python, Bash, or a similar language
- Knowledge of networking fundamentals, including TCP/IP and DNS
- Experience with version control systems such as Git
- Strong problem-solving and analytical skills
- Willingness to learn and develop expertise in security policies and automation
- Excellent communication and collaboration skills
- Familiarity with policy as code frameworks such as Open Policy Agent or HashiCorp Sentinel
- Knowledge of CIS, SOC 2, ISO 27001, or similar compliance standards
- Exposure to cloud-native security tools and services
- Relevant AWS, Azure, or GCP certifications
- Interest in security best practices, frameworks, and tools
What We Do
Mondoo is a powerful security, compliance, and asset inventory tool that helps businesses identify vulnerabilities, track lost assets, and ensure policy compliance across their entire infrastructure. Our eXtensible Security Posture Management (XSPM) platform is built on open-source components like cnquery and cnspec, giving customers complete transparency and control over how their data is processed. With Mondoo, you can easily integrate security into your developer workflows and protect your organization's assets while minimizing the risk of security incidents.








