- We're taking autonomous search mainstream, making product discovery more intuitive and conversational for customers, and more profitable for businesses.
- We’re making conversational shopping a reality, connecting every shopper with tailored guidance and product expertise — available on demand, at every touchpoint in their journey.
- We're designing the future of autonomous marketing, taking the work out of workflows, and reclaiming the creative, strategic, and customer-first work marketers were always meant to do.
About the Role
You will serve as a trusted security partner to Engineering, DevOps, and IT, designing and hardening secure AWS environments, securing our containerized and Linux-based workloads, and protecting our corporate infrastructure and identity/access tooling — while partnering closely with our dedicated SOC team on detection and response.
You will act as a key member of the Cloud Security team, owning cloud and corporate infrastructure security architecture, vulnerability remediation, and Splunk administration and data integration, in close partnership with the SOC team, which owns detection content, alerting, playbooks, and incident triage/response.
Your Job Will Be (but not limited to)
- Design, implement, and monitor security controls across our AWS cloud infrastructure, applying platform-native services (e.g., IAM, GuardDuty, Security Hub, KMS, VPC/Security Groups, Config) and secure architecture patterns to protect production environments.
- Maintain deep working knowledge of the AWS security service landscape, evaluating new and existing services to close coverage gaps and strengthen our security architecture.
- Secure our Linux server fleet and containerized workloads (Docker, Kubernetes), including host hardening, image and runtime security, and Kubernetes cluster and workload configuration.
- Own the security of our corporate infrastructure, including security configuration and administration of identity and access tooling such as JumpCloud and zero-trust network access tooling such as Twingate.
- Administer and integrate Splunk as a data platform — onboarding new log sources, maintaining data pipelines, and supporting platform health and licensing — in partnership with the SOC team, which owns detection content, alerting logic, and playbooks.
- Identify, triage, and drive remediation of infrastructure and web application vulnerabilities, partnering with engineering teams to reduce MTTR and improve remediation rates.
- Lead CVE lifecycle management and patching efforts, performing root cause analysis and tracking remediation metrics across cloud, corporate, and on-prem systems.
- Build and maintain secure automation and tooling for vulnerability remediation and infrastructure hardening using Python, Go, or Bash or similar scripting languages.
- Implement security guardrails and policy-as-code within Infrastructure as Code (IaC) and CI/CD pipelines, performing static IaC scanning and enforcing security baselines prior to deployment.
- Define logging and telemetry requirements for cloud, container, and corporate infrastructure assets, ensuring the SOC team has the data coverage needed for effective detection.
- Develop, document, and operationalize security architecture standards for cloud, container, and corporate infrastructure, partnering with engineering pillars and IT to drive adoption across the organization.
- Partner with the SOC team on incident response as a technical subject-matter expert for cloud, container, and corporate infrastructure
- Mentor junior security engineers and prioritize security initiatives based on risk and business impact, driving continuous improvement of the organization's cloud and corporate infrastructure security posture.
Professional Experience and Skills Requirements
- 6+ years of hands-on experience in cybersecurity engineering, with a focus on cloud security, infrastructure security, and system hardening.
- Deep, hands-on experience securing AWS environments, including secure architecture design, IAM, and applying native AWS security services (e.g., GuardDuty, Security Hub, KMS, Config, Inspector).
- Strong working knowledge of Linux system administration and hardening, and hands-on experience securing containerized environments (Docker and Kubernetes).
- Experience securing corporate infrastructure and identity/access tooling, such as JumpCloud, Twingate, or comparable zero-trust/IAM platforms.
- Experience administering and integrating Splunk (or comparable data/SIEM platforms) as a log and data pipeline, including onboarding data sources and maintaining platform health.
- Demonstrated ownership of the vulnerability and CVE lifecycle, including triage, root cause analysis, patching, and MTTR/remediation-rate reporting.
- Proficiency in scripting and automation (Python, Go, or Bash) to build or extend security tooling for hardening and remediation.
- Experience implementing policy-as-code and security guardrails within CI/CD pipelines, including static IaC scanning and pre-deployment security baselines.
- Working knowledge of common security frameworks (CIS, NIST) and typical weaknesses exploited in infrastructure, containers, and web applications.
- Strong cross-functional communication skills, with experience partnering closely with SOC, engineering, and IT teams on shared security outcomes.
- Experience mentoring junior engineers and prioritizing security work based on risk and business impact.
- Relevant certifications preferred: AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, or CCSK.
Your Success Story Will Be
In the First 30 Days
- Develop a foundational understanding of Bloomreach's AWS environment, corporate infrastructure, and existing security controls, including JumpCloud and Twingate configurations.
- Become familiar with the Cloud Security team's tooling, current Splunk data integrations, and how the team partners with the SOC on detection coverage.
- Review current CVE/vulnerability management processes, IaC pipelines, and security baselines for cloud, container, and Linux environments.
- Establish working relationships with Engineering, DevOps, IT, and the SOC team.
- Identify quick-win opportunities to strengthen existing hardening, IaC guardrails, or corporate infrastructure configurations.
In the First 60 Days
- Independently triage and drive remediation of infrastructure, container, and web vulnerabilities identified through scanning and assessments.
- Onboard at least one new data source into Splunk and contribute to maintaining existing data pipelines.
- Contribute to IaC security scanning and policy-as-code enforcement within CI/CD pipelines.
- Partner with Engineering and IT to close CVE and patching gaps, tracking MTTR and remediation-rate metrics.
- Begin mentoring junior team members on cloud and infrastructure security fundamentals.
In the First 90 Days
- Own end-to-end security architecture reviews for at least one major AWS workload or corporate infrastructure system, independently identifying risks and driving mitigations.
- Demonstrate hands-on ownership of Linux, container, and Kubernetes security hardening for at least one environment.
- Propose improvements to security architecture standards or automation based on observed gaps.
- Demonstrate consistent ownership of vulnerability and CVE lifecycle management with minimal supervision.
- Actively mentor junior engineers and contribute to prioritization of the team's security roadmap.
#LI-HO1
The pay range actually offered will take into account a variety of potential factors considered in compensation, including but not limited to skills, qualifications, geographic location, accomplishments, experience, credentials, internal equity and business needs, and may vary from the range listed above.
- A great deal of freedom and trust. At Bloomreach we don’t clock in and out, and we have neither corporate rules nor long approval processes. This freedom goes hand in hand with responsibility. We are interested in results from day one.
- We have defined our 5 values and the 10 underlying key behaviors that we strongly believe in. We can only succeed if everyone lives these behaviors day to day. We've embedded them in our processes like recruitment, onboarding, feedback, personal development, performance review and internal communication.
- We believe in flexible working hours to accommodate your working style.
- We work virtual-first with several Bloomreach Hubs available across three continents.
- We organize company events to experience the global spirit of the company and get excited about what's ahead.
- We encourage and support our employees to engage in volunteering activities - every Bloomreacher can take 5 paid days off to volunteer*.
- The Bloomreach Glassdoor page elaborates on our stellar 4.7/5 rating. The Bloomreach Comparably page Culture score is even higher at 4.9/5
- We have a People Development Program - participating in personal development workshops on various topics run by experts from inside the company. We are continuously developing & updating competency maps for select functions.
- Our resident communication coach Ivo Večeřa is available to help navigate work-related communications & decision-making challenges.*
- Our managers are strongly encouraged to participate in the Leader Development Program to develop in the areas we consider essential for any leader. The program includes regular comprehensive feedback, consultations with a coach and follow-up check-ins.
- Bloomreachers utilize the $1,500 professional education budget on an annual basis to purchase education products (books, courses, certifications, etc.)*
- The Employee Assistance Program -- with counselors -- is available for non-work-related challenges.*
- Subscription to Calm - sleep and meditation app.*
- We organize ‘DisConnect’ days where Bloomreachers globally enjoy one additional day off each quarter, allowing us to unwind together and focus on activities away from the screen with our loved ones.
- We facilitate sports, yoga, and meditation opportunities for each other.
- Extended parental leave up to 26 calendar weeks for Primary Caregivers.*
- Restricted Stock Units or Stock Options are granted depending on a team member’s role, seniority, and location.*
- Everyone gets to participate in the company's success through the company performance bonus.*
- We offer an employee referral bonus of up to $3,000!
- We reward & celebrate work anniversaries -- Bloomversaries!*
(*Subject to employment type. Interns are exempt from marked benefits, usually for the first 6 months.)
Excited? Join us and transform the future of commerce experiences!
If this position doesn't suit you, but you know someone who might be a great fit, share it - we will be very grateful!
Any unsolicited resumes/candidate profiles submitted through our website or to personal email accounts of employees of Bloomreach are considered property of Bloomreach and are not subject to payment of agency fees.
#LI-Remote
Skills Required
- 6+ years of hands-on cybersecurity engineering experience focused on cloud security, infrastructure security, and system hardening
- Hands-on experience securing AWS environments, including IAM and AWS security services
- Strong Linux system administration and hardening experience
- Hands-on experience securing Docker and Kubernetes environments
- Experience securing corporate infrastructure and identity/access or zero-trust platforms such as JumpCloud or Twingate
- Experience administering and integrating Splunk or comparable SIEM/data platforms
- Ownership of vulnerability and CVE lifecycle management, including triage, root cause analysis, patching, and remediation reporting
- Proficiency in Python, Go, Bash, or similar scripting languages
- Experience implementing policy-as-code, CI/CD security guardrails, and static Infrastructure as Code scanning
- Working knowledge of CIS, NIST, and infrastructure, container, and web application weaknesses
- Strong cross-functional communication with SOC, engineering, and IT teams
- Experience mentoring junior engineers and prioritizing security work by risk and business impact
- AWS Certified Security Specialty, Certified Kubernetes Security Specialist, CISSP, CCSP, or CCSK certification
Bloomreach Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Bloomreach and has not been reviewed or approved by Bloomreach.
-
Fair & Transparent Compensation — Pay is considered competitive versus peers and aligned with tech‑market norms for comparable roles and levels. Many roles cite compensation that feels fair and market‑appropriate.
-
Strong & Reliable Incentives — Company‑wide performance bonuses follow a semi‑annual cadence, and go‑to‑market roles feature structured base/OTE plans. This predictable incentive design meaningfully augments base pay.
-
Leave & Time Off Breadth — Quarterly company‑wide DisConnect Days, generous PTO practices, and paid volunteer time expand time off beyond standard holidays. These scheduled shutdowns are designed to enable genuine unplugging in a remote‑first setup.
Bloomreach Insights
What We Do
Bloomreach is the leader in Commerce Experience™ Our Bloomreach Experience Platform (brX) competes in three core categories: Engagement (CDP and marketing automation), Content (headless content and experience management), and Discovery (e-commerce search, merchandising, recommendations, and SEO). We connect both customer data and product data to personalize all customer touch-points, leveraging our patented AI to recommend, predict, and segment. This empowers the marketer to create individual experiences, increase revenue, strengthen customer loyalty, and improve efficiency. With a global footprint, Bloomreach powers over 25% of all e-commerce experiences across the US and UK, and supports 300+ global enterprises including Neiman Marcus, CapitalOne, Staples, NHS Digital, Bosch, Puma, and Marks & Spencer.








