Cloud Security Engineer
All-in-one Philippine e-wallet and cryptocurrency exchange combining crypto trading with payments, bills, QR checkout, mobile load, and remittances.
Funding history
About Coins.ph
Coins.ph is a regulated digital-asset and payments platform operating under the Coins.ph brand. Its services include buying, selling, and holding cryptocurrency; peso wallets; bill payments; mobile load; QR payments; money transfers; and remittances. The current user agreement identifies Betur, Inc. and DCPay Philippines, Inc. as the entities doing business as coins.ph.
Skills
About the Role
Lead security architecture assessments and hardening for cloud platforms, primarily AWS. Maintain cloud security baselines and monitor IAM, networking, storage, and compute security posture. Drive vulnerability remediation, improve monitoring and automated detection, participate in incident response, produce root cause analyses, and communicate cloud risk posture to management.
Requirements
- 5+ years of experience in cloud security or information security
- At least 3 years of experience focused on AWS environments
- Strong command of AWS IAM, VPC, S3, EC2, KMS, CloudTrail, GuardDuty, and Security Hub
- Vulnerability identification and risk assessment
- Familiarity with CIS Benchmark, NIST, and MITRE ATT&CK for Cloud
- Experience driving remediation efforts across teams
- Familiarity with a CSPM or CNAPP tool
- Scripting or automation skills in Python, Terraform, or CloudFormation
Responsibilities
- Lead security architecture assessments and hardening for AWS cloud platforms
- Define and maintain cloud security baselines, policies, and standards
- Monitor the security posture of IAM, networking, storage, and compute environments
- Identify and assess security vulnerabilities and configuration risks
- Define remediation plans and priorities
- Drive engineering and operations teams to complete fixes
- Track and verify remediation outcomes
- Build and improve cloud security monitoring, alerting, and automated detection mechanisms
- Participate in security incident response
- Produce root cause analyses and improvement recommendations
- Produce security assessment reports
- Communicate cloud risk posture to management
