Senior Security Engineer
51.000 € - 55.000 €Docebo
Artificial Intelligence. Actual Impact.
At Docebo, we’re using AI to change how people learn at work—and we mean actually change it. We’re an AI‑powered learning platform that helps organizations create, deliver, and manage training all in one place. But our real mission goes deeper: we help teams move faster, work smarter, and focus on the work that truly matters. Our platform is built with intelligent, time‑saving tools that personalize learning, eliminate busywork, and turn training from a checkbox into a superpower. The result? Better experiences for learners and real results for businesses.
Role Overview
The Senior Security Engineer will play a central role in securing Docebo’s cloud infrastructure, with a primary focus on AWS environments. Working closely with Cloud Infrastructure & Operations, Engineering, and other security teams, this role is responsible for designing, implementing, and continuously improving cloud security controls across all layers of the stack — from infrastructure provisioning and container orchestration to runtime detection and compliance enforcement. This is a hands‑on, high‑ownership role for someone who thinks in terms of risk and moves quickly to reduce it. The role also includes participation in an on‑call rotation for security incidents affecting Docebo systems.
Responsibilities (including but not limited to)
- Cloud Security Architecture & Hardening: Own the security posture of Docebo’s AWS environments. Define and enforce secure account structures, service control policies (SCPs), guardrails, and baseline configurations across multi‑account setups. Evaluate and improve network segmentation, IAM boundaries, and data protection controls. Identify and remediate misconfigurations using CSPM tooling and manual review.
- Infrastructure as Code Security: Partner with Cloud Infrastructure to integrate security controls into IaC workflows. Define guardrails to catch insecure configurations before deployment. Own security scanning in CI/CD pipelines and promote a shift‑left approach to cloud security across engineering teams.
- Incident Response & On‑Call: Participate in the on‑call rotation for security incidents, including triage, containment, and escalation for after‑hours events. Lead investigation and root cause analysis for cloud security incidents with clear written post‑mortems. Leverage automation and AI tooling to reduce mean time to detect and respond.
- Cloud Detection & Threat Monitoring: Build and maintain detection coverage for cloud‑native threats (privilege escalation, unusual API activity, lateral movement, data exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud.
- Vulnerability & Configuration Management: Own vulnerability management for cloud workloads — prioritizing findings from cloud configuration assessments, and runtime protection tools. Drive remediation with Engineering and Infrastructure teams, and build automated enforcement where manual review doesn’t scale.
- Identity & Access Management: Define and enforce least‑privilege principles across AWS IAM, service accounts, and federated identity. Review and improve IAM policies, permission boundaries, cross‑account roles, and access patterns. Reduce standing access and enforce JIT access where appropriate.
- Development of Security Best Practices: Develop and document best practices, policies, and procedures for cloud security. Provide guidance and training to engineering and infrastructure teams to promote a security‑aware culture.
- Vendor relationships: Maintain relationships with security vendors for technical issues, ensure smooth operations of security tools and services, and elevate problems or incidents to vendors when required.
What It Takes to Be Successful
You're a cloud security practitioner who operates with a builder’s mindset. You understand AWS deeply — not just its security services, but how misconfigurations and design decisions create real risk. You're comfortable reading IaC, reviewing IAM policies, and diving into CloudTrail logs to reconstruct what happened. You know how to work with engineering and infrastructure teams as a partner, not a gatekeeper — and you can communicate risk clearly to stakeholders who don’t live in the cloud console. You're comfortable being on‑call and making decisions under pressure.
Additionally, holding security‑related certifications such as those from ISC², ISACA, SANS, or CompTIA, and having Cloud Architecture certifications (AWS Security Specialty, AWS Solutions Architect, or equivalent) will significantly enhance your effectiveness in this role.
Requirements
- 5+ years of relevant work experience in cybersecurity, with a strong focus on cloud security in production AWS environments.
- Deep hands‑on experience with AWS security services: IAM, SCPs, CloudTrail, GuardDuty, Config, KMS, VPC security, and more.
- Good knowledge of Kubernetes security — including RBAC, pod security standards, network policies, admission controllers, and secrets management.
- Experience with cloud security posture management (CSPM) and cloud workload protection (CWPP/CNAPP) tools.
- Experience securing IaC pipelines (Terraform, CloudFormation) and integrating security scanning into CI/CD workflows.
- Good experience with container and image security — scanning, runtime protection, supply chain risk.
- Experience with SIEM and detection engineering — building and tuning cloud‑native detection rules, threat hunting across CloudTrail and application logs.
- Familiarity with automation platforms and AI‑driven security tools to streamline detection, enrichment, and response.
- Experience with Infrastructure as Code (IaC) and scripting (Python, Bash, or similar) to develop custom security tooling and automate workflows.
- Strong IAM fundamentals: least privilege, cross‑account roles, permission boundaries, federated identity, and privileged access management.
- Comfortable working across Azure/GCP in addition to AWS — multi‑cloud exposure is a plus.
- In‑depth knowledge of information security principles and cybersecurity frameworks relevant to cloud environments: MITRE ATT&CK for Cloud, CIS Benchmarks, AWS Well‑Architected Security Pillar, NIST CSF, SOC 2, ISO 27001.
- Willingness and ability to participate in an on‑call rotation, including after‑hours response.
- Ability to produce clear, comprehensive, and well‑structured documentation (e.g. incident reports, architecture reviews, runbooks, and security standards) and to communicate complex technical issues effectively to non‑technical stakeholders.
Our Hybrid Work Philosophy
Great work can happen anywhere but coming together helps us go further. Our team spends three days a week in the office (Tuesday‑Thursday) to collaborate, solve problems, and learn from each other. With flexibility the rest of the week, it’s a balance designed to help everyone do their best work and keep growing.
Our Total Rewards Philosophy
Our Total Rewards Philosophy centers around three core areas to reward and care for our People:
- Rewarding Impact: We lead with competitive pay to reward the impact, skills and traits that fuel our success.
- Fostering Holistic Wellbeing: We care deeply about and invest in the whole person with programs that support our people’s physical, mental, and financial well‑being.
- Empowering Our Talent Culture: We build a culture of trust and empowerment by designing our rewards and benefits with transparency, equity, and flexibility, enabling our people to do their best work and stay for the long haul.
Our Promise to You
- Financial Wellness: Own a piece of Docebo through our Employee Share Purchase Plan (ESPP) at a 15% discount, plus a competitive compensation package.
- Your Well‑Being, Covered: You’ll get access to health benefits, so you can get the care you need when you need it.
- Rest, Relax, Repeat: Rest and recharge with paid vacation days, two company‑wide Docebo Days, floating holidays for cultural celebrations, and your birthday off.
- Family First: We provide coverage offering you time with your little one(s) so you can soak up all those precious moments. Fun fact: we had 30 Docebian babies join the family in 2025!
- Connections That Count: Connect with global communities through our Employee Resource Groups (including PRIDE, DWA, BIDOC, and Green Ambassadors) and company‑wide events that keep the fun rolling all year long.
About Docebo
At Docebo, we create seamless, AI‑powered learning experiences for over 3,000 customers worldwide. We have successfully achieved two IPOs (TSX: DCBO & NASDAQ: DCBO), been recognized as a top SaaS e‑learning solution, and are growing exponentially in the process. We’re a global company, with offices across North America, EMEA, APAC, and beyond. Our team is guided by five core values—Grow Together Win Together, Build with Our Customer, Clear is Kind, Own Outcomes, Progress Over Perfection—which shape everything we do. If this resonates with you, now is the perfect time to join one of the fastest‑growing learning technology companies in the world.
Equal Employment Opportunity Statement
Docebo is an Equal Employment Opportunity employer. We are committed to diversity and inclusion in our workforce. All qualified applicants and employees will receive consideration for employment regardless of their race, colour, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, citizenship status, age, disability, genetic information, or any other category protected under applicable law.
As a federal contractor, Docebo is committed to the principles of affirmative action and equal employment opportunity for protected veterans and individuals with disabilities. Docebo does not discriminate because of protected veteran status or on the basis of disability, and Docebo takes affirmative action to employ and advance in employment qualified protected veterans and individuals with disabilities.
Any individuals requiring a reasonable accommodation or who would like to voluntarily disclose a disability or protected veteran status to assist with their employment application should send an e‑mail to Visualizzare la mail su click.jobroute.io. The email should also include the position you’re interested in.
Compensation Range: €51K - €55K
#J-18808-Ljbffr- ...Docebo is seeking a Senior Security Engineer to secure our AWS environments and guide cloud security architecture. You will own security controls, guardrails, and vulnerability remediation while partnering with Cloud Infra, Engineering, and security teams. You’ll participate...Senior
- Dedagroup cerca un professionista esperto per gestire progetti e infrastrutture Microsoft, inclusi ambienti on-premise e cloud. La figura avrà responsabilità nella progettazione e implementazione di architetture Cloud e multicloud. È richiesta un'esperienza di almeno 5 ...SeniorOrario flessibile
51.000 € - 55.000 €
...and real results for businesses. /ph3Role Overview /h3pThe Senior Security Engineer will play a central role in securing Docebo’s cloud infrastructure... ...posture of Docebo’s AWS environments. Define and enforce secure account structures, service control policies (SCPs),...SeniorLavoro ibridoRemotoTurniOrario flessibile- ...Siamo alla ricerca di un/una Cybersecurity Senior Associate con focus su Identity & Access Management (IAM) da inserire all’interno... ...percorsi di digital transformation in ambito identity-centric security. Responsabilità principali Analizzare e definire i requisiti...Senior
- pPwC Italy cerca un/una Cybersecurity Senior Associate con focus su Identity Access Management (IAM) per il team Cyber. Sarai responsabile... ...nella digital transformation in ambito identity-centric security. È richiesta una laurea in Informatica e almeno 2 anni di esperienza...Senior
- Una banca internazionale è alla ricerca di un Cyber Threat Hunter Expert per il team di Cyber Threat Hunting. Il candidato sarà responsabile della conduzione di attività di Threat Hunting, analisi forense, e implementazione di tecniche di adversary deception. Sono richieste...Senior
- pTalan Spain is seeking a Senior Cybersecurity Analyst to join a global Cybersecurity Operations team responsible for protecting critical... ...against evolving cyber threats. /ppYou’ll be part of a 24x7 Security Operations Centre (SOC), collaborating with cybersecurity...Senior
- ...to build a better working world. The EY Global Information Security team is looking for new members helping manage security risk using... ...Cloud security certifications such as AZ-500 Azure Security Engineer Product Management – working with a broader business team on...SeniorDisponibilità immediataOrario flessibile
- ...protecting critical environments and supporting international organizations against evolving cyber threats. /p pYou’ll be part of a b24x7 Security Operations Centre (SOC) /b, working with cybersecurity specialists across the world to monitor, investigate and respond to...SeniorImpiego permanenteLungo termineOrario flessibile
- ...to build a better working world. /p pThe EY Global Information Security team is looking for new members helping manage security risk using... ...liCloud security certifications such as AZ-500 Azure Security Engineer /li liProduct Management - working with a broader business team...SeniorDisponibilità immediataOrario flessibile
- A global professional services firm based in Milan is seeking an experienced security consultant to join their team. The successful candidate will be responsible for designing and implementing security solutions primarily in a Microsoft Azure environment. Key qualifications...Senior
- Una società globale di workforce management cerca un Security Architect per contribuire alla sicurezza delle infrastrutture cloud. Il candidato ideale avrà esperienza avanzata in cloud security e risk management, con la responsabilità di integrare requisiti di sicurezza...Lavoro ibrido2 giorni/sett.
- Un'azienda tecnologica cerca un Cyber Security Specialist Junior per supportare il team IT Security in un contesto avanzato. La persona ideale deve possedere un diploma in Cyber Security e avere fino a un anno di esperienza. Le responsabilità includono monitorare eventi...ApprendistatoLavoro ibrido
- Una società di consulenza tecnologica cerca un Cyber Security/System Engineer per gestire e migliorare le soluzioni di SIEM e Log Management. Sarai responsabile della configurazione di nuove sorgenti dati, monitoraggio degli eventi, e sviluppo di parser per integrazione...
- ...realtà in continua evoluzione, nella quale le relazioni umane sono sempre al primo posto. Siamo alla ricerca di un Network Security Engineer presso una nostra azienda partner su Milano specializzata in consulenza IT e servizi tecnologici, focalizzata su cloud,...Impiego permanenteContratto con partita IVA
- ...Realtà di prodotto multinazionale è alla ricerca di un Cyber Security Engineer Sede di lavoro : Milano Ovest Modalità ibrida e... ...in ambito Cyber Security; Affiancamento diretto a figure senior e possibilità di aumentare progressivamente ownership; Contesto...Lavoro ibridoRemotoOrario flessibile
- ...Maranello, Bologna, Firenze, Roma, Napoli e Bari. /ph3bDescrizione: /b /h3pSarai inserito all'interno di un SOC come Cyber Security/System Engineer con il compito di definire i requisiti per la generazione, l'archiviazione, l'utilizzo e la cancellazione dei log, in base...Stage/TirocinioLavoro ibrido
- pEligo Recruitment è alla ricerca di un Cyber Security Engineer per una multinazionale in forte crescita. Il candidato lavorerà a stretto contatto con il Cyber Security Lead, gestendo controlli di sicurezza e partecipando a incident response e vulnerability management....Lavoro ibridoRemotoOrario flessibile
- ...Siamo specializzati in servizi di consulenza e sviluppo software su tematiche Cloud, IoT, NoSQL. /ppPer il potenziamento del team IT Security di un nostro cliente, siamo alla ricerca di un/una bCyber Security Specialist Junior /b, desideroso/a di crescere...Stage/TirocinioApprendistato
- ppSiamo alla ricerca di un bNetwork Security Engineer /b con esperienza in contesti bdatacenter enterprise /b e infrastrutture di rete complesse. /p h3Attività: /h3 ul liTi occuperai della progettazione, implementazione e gestione di infrastrutture di rete e sicurezza ad...
- Una società di consulenza internazionale cerca un SAP Security Senior Associate a Turbigo. Sarai coinvolto in progetti ad alto valore per la sicurezza di processi SAP, con responsabilità dalla traduzione delle esigenze agli strumenti di governance. Richiesta laurea e almeno...Senior
- Un'azienda di consulenza IT in Lombardia cerca un Network Security Engineer per gestire reti e sistemi di sicurezza. Il candidato ideale ha solide basi nella progettazione di architetture di rete e nell'implementazione di firewall avanzati come Palo Alto e Check Point....Impiego permanente
- Un'azienda tecnologica specializzata è alla ricerca di un Network Security Engineer in Lombardia. Il candidato ideale avrà esperienza nella progettazione e gestione di infrastrutture di rete sicure, con focus su ambienti datacenter. Richieste solide competenze in Network...
- ppSiamo alla ricerca di un Network/Security Implementation Specialist per il nostro team di Professional Services. Il profilo si occuperà di progettazione e implementazione di progetti e di supporto delle infrastrutture IT e sarà in grado di gestire e operare sui sistemi...Lavoro ibridoOrario flessibile
- pTrasforma le tue aspirazioni professionali in una storia di successo, entra in PwC come SAP Security Senior Associate /ppIn PwC Other Trust Solutions (OTS) supportiamo le organizzazioni nel rafforzamento di resilienza, trasparenza, governance e conformità normativa, operando...Senior
- ...Geometra Senior, Milano Mercury è leader europeo nelle soluzioni per l'edilizia. Geometra Senior, Milano Mercury è leader... ...leader in construction solutions. We build and manage complex engineering & construction projects for the world’s leading corporations....Senior
- ph3Engagement /h3pLong-term, Embedded Role /ph3The Opportunity /h3pWe are seeking a senior bCisco High Touch Engineer (Red Badge) /b to support mission-critical networks within the bItalian Public Sector /b, working closely with central government bodies, ministries, and...Senior
- ...le relazioni umane sono sempre al primo posto. Modalità: Ibrida Luogo: Milano (MI) Stiamo ricercando un Networking & Security Engineer che sarà responsabile della progettazione, implementazione e gestione avanzata delle infrastrutture di rete e della postura di...Impiego permanenteLavoro ibrido
- Un gruppo europeo di consulenza ingegneristica sta cercando un Networking & Security Engineer con almeno 4 anni di esperienza in ambito Networking e Security. Le principali responsabilità includono la progettazione delle infrastrutture di rete e gestione della sicurezza...Impiego permanenteLavoro ibrido
- ...Senior Finance Consultant: Corporate Strategy & Research (Remote Advisory) About Prolific Prolific is not just another player in the AI space – we are building the biggest pool of quality human data in the world. Over 35,000 AI developers, researchers, and organizations...SeniorContratto con partita IVARemotoLavoro da casaOrario flessibile
- rappresentante senior Turbigo (MI)
- senior data engineer Turbigo (MI)
- senior sales Turbigo (MI)
- senior product manager Turbigo (MI)
- senior account manager Turbigo (MI)
- tecnico senior Turbigo (MI)
- senior developer Turbigo (MI)
- impiegata senior Turbigo (MI)
- senior system engineer Turbigo (MI)
- senior marketing Turbigo (MI)