Senior Cloud Application Security Engineer
Additiv Technologies Ltd. · Bucharest · On-site
Posted Oct 6, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
About this role
We are seeking a senior Cloud Application Security Engineer to strengthen application and API security across the production estate. The role investigates monitoring and assessment findings and coordinates remediation with CloudOps and development teams. The engineer will work with the existing security team.
Your responsibilities
Provide production-focused security oversight for applications, APIs and microservices
Review Defender for Cloud and Sentinel alerts, recommendations and security findings
Operate and improve continuous vulnerability assessment and VAPT, including the AI-enabled security-validation platform when selected
Correlate findings and telemetry from Defender for Cloud, Sentinel, Azure Front Door/WAF, API Management, AKS, OpenTelemetry, Azure Monitor and Grafana
Investigate suspicious activity and potential attack paths; assess exposure, exploitability and business risk
Support application/API threat modelling, design reviews and secure development; assess authentication, authorisation, access controls, secrets, dependencies, containers and supply-chain risks
Validate findings, filter false positives, prioritise remediation, coordinate fixes with CloudOps and development teams, and retest through closure
Tune assessment and detection configurations; support incident investigations, evidence collection, post-incident reviews and security reporting
Your qualifications, skills and experience
At least 5 years of relevant application security, cloud security, vulnerability management or security engineering experience, with senior-level ownership of investigations or remediation
Hands-on experience in application/API security testing, vulnerability triage and remediation validation
Practical knowledge of Azure security, especially Defender for Cloud and Sentinel; familiarity with KQL, Azure Monitor, Log Analytics and OpenTelemetry is an advantage
Understanding of web/API risks, secure development, authentication, authorisation, access control, containers, AKS/Kubernetes and software supply chains
Experience with DAST, API scanning, vulnerability assessment or continuous VAPT
Experience with .NET, ASP.NET (MVC, Web API), Web Services, and SQL DBs
Clear communicator in English, able to explain findings to developers, CloudOps, security colleagues and management
Investigative, evidence-led and collaborative; prioritises risk pragmatically and follows remediation through validation
Careful to test production systems only within approved scope and change controls.
Focused on improving production defence
Location
Work from our office in: Bucharest/ Dubai/ Sarajevo
We offer you
An open-minded, international and fast-paced environment where decisions are made quickly, ideas are welcomed and people are encouraged to make a real impact
A meritocratic culture built on ownership, performance and continuous feedback, where ambition is recognized and contribution matters
The opportunity to…