Description review

Cloud Infrastructure Security Engineer

Bjak · Remote · back to the listing

HR standards

49/100

poor

Title ↔ description

85/100

strong

Reads as

Security Engineer

100% confident

What this role officially is

ICT security administrator — ESCO, the EU occupation classification

ICT security administrators plan and carry out security measures to protect information and data from unauthorised access, deliberate attack, theft and corruption.

Also known as: network security administrator, system security administrator, ICT security administrators, IT security administrator

How others title the same work

Large employers

  • Security Risk Management Specialist Canonical Ltd.
  • Security Software Engineer Canonical Ltd.
  • Senior Security Operations Engineer Canonical Ltd.
  • Staff Security Operations Engineer Canonical Ltd.
  • Ubuntu Security Engineer Canonical Ltd.

Startups

  • Security Engineer (Bangalore, India) AiPrise
  • Security & Trust Engineer Alex
  • Elucid | Senior Security Engineer | Boston, MA | ONSITE (hybrid) | $130k–$170k Elucid
  • Factory | Security Engineer | ONSITE, San Francisco, CA | Full-Time Factory
  • Factory | Security Engineer | Onsite in San Francisco | Full-time Factory

What the listing never says

  • No section describes what the person would actually do. Scope clarity
  • No pay range published. Candidates cannot tell whether applying is worth their time. Pay transparency

The listing, marked up

Nothing in the wording of this listing tripped a check. The scores above still judge how complete and coherent it is.

About BJAK

The original mission of BJAK is we believe people deserve smarter ways to plan, save and grow their money. This is the origin of our name.

Started in 2019, we built the first mobile-first, insurance platform, enabling insurance to be accessible online by millions in the region. Today, its the leading insurance platform in Southeast Asia.

Today, we are expanding ways to help people in the region — this includes spending, saving, investing, exchanging, travelling, and more. Our mission is help people get more from their money every day.

We have teams working around the world, with over 20 nationalities from our offices and remotely, who truly enjoys their work. We are looking for the most talented and driven people we can find. We are looking for people who work for their passion, not counting hours. Who loves building great next-generation products, not status quo. Who cares about redefining how everyone around us can get the best financial applications, not for an exclusive few.

If you're this person, we'd love to talk to you.

The Role

Protect BJAK's cloud environments, networks, compute platforms, and core infrastructure across AWS and GCP. Strengthen configuration, access controls, monitoring, resilience, and technology risk management.

What You Will Build

• Design and maintain security controls across AWS and GCP infrastructure, networks, compute, storage, and platform services.

• Review cloud configurations and infrastructure changes for misconfigurations, excessive permissions, exposure, and resilience risks.

• Manage IAM, privileged access, network segmentation, encryption, key management, secrets, and secure connectivity.

• Improve cloud security monitoring, logging, alerting, threat detection, and incident response.

• Own cloud and infrastructure controls for SC TRM and BNM RMiT, including evidence, testing, remediation, and audit support.

• Automate security checks and infrastructure guardrails using infrastructure-as-code and scripting tools.

• Improve vulnerability management, backup, recovery, business continuity, and secure operations with engineering teams.

What We Look For

• Degree in Computer Science, IT, Cybersecurity, or related field, or equivalent experience.

• 3+ years in cloud, infrastructure, systems, or security engineering.

• Experience implementing and owning SC TRM and BNM RMiT controls for cloud and technology infrastructure.

• Hands-on experience securing AWS and GCP environments and cloud-native architectures.

• Strong knowledge of IAM, networking, firewalls, encryption, key management, hardening, and cloud security posture management.

• Experience with infrastructure as code, automation, vulnerability scanning, logging, and incident response.

• Strong troubleshooting and communication skills across platform, application, and compliance teams.

Language

English is our main working language across global teams. Strong English communication is required.

Originally posted on Himalayas

How this was produced

Highlights are found by rule, not by a model: each one is a phrase matched at a known position, and every note is a template we wrote. The two scores come from a typed-decision model (Jev) that reads the listing against the official role definition and real listings for the same role, and returns probabilities rather than prose — it never writes any of the words on this page, and never chooses what to highlight.

Deterministic penalty applied to the HR score: 12 points (from 61 before penalties). Reviewed 30 Sep 2026.