Cloud Security Analyst (CNAPP / DevSecOps)
Location & Work Model
- B2B contract
- Hybrid model: 6 days per month from the office in Kraków (preferred) or Warsaw
Overview
We are looking for a skilled and motivated Cloud Security Analyst to join a growing team focused on Cloud-Native Application Protection Platform (CNAPP). In this role, you will act as a bridge between technical teams and business stakeholders, helping to embed cloud security capabilities into internal processes and platforms.
You will combine technical expertise in cloud security with strong analytical and communication skills to translate business needs into actionable technical requirements and support secure cloud adoption at scale.
Key Responsibilities
- Gather, analyze, and document functional and non-functional requirements in collaboration with stakeholders (architects, engineers, security teams)
- Translate requirements into epics, features, and user stories within Agile/Scrum frameworks
- Ensure traceability between business needs, technical specifications, and delivered solutions
- Support stakeholders in adopting CNAPP capabilities and guide them through requirement definition
- Conduct security and threat assessments for cloud-native platforms
- Work with data analytics tools (e.g., Databricks) to support security insights and reporting
- Facilitate workshops, demos, and design discussions; validate and obtain solution sign-off
- Define acceptance criteria and ensure delivered solutions meet agreed requirements
- Design and map integrations and APIs between security platforms, data lakes, and other systems
- Collaborate closely with engineering teams (cloud, containers, DevOps, cybersecurity)
Requirements
Technical Skills
- 5+ years of experience as a Technical Analyst in cybersecurity or security/compliance platforms (SaaS or on-premise)
- Hands-on experience with:
- Vulnerability scanning
- Cloud security posture management (CSPM)
- Application security posture management (ASPM)
- Inventory and compliance tools (e.g., CNAPP)
- Experience working in Agile/Scrum environments (writing epics, features, user stories)
- Knowledge of APIs, microservices, containerization (Kubernetes), and cloud platforms (AWS, GCP)
- Understanding of DevSecOps practices
- Nice to have:
- Knowledge of standards (PCI-DSS, CIS benchmarks)
- Cloud or security certifications (AWS, GCP, security analyst)
Soft Skills
- Strong stakeholder management and communication skills
- Ability to work in a fast-paced, dynamic environment
- Proactive, self-driven, and collaborative mindset
- Strong problem-solving and analytical thinking
- Ability to manage multiple priorities and drive consensus
- Fluent English (written and spoken)
Benefits
- Private medical care (LuxMed)
- Cafeteria platform (MyBenefit)
- Support from a dedicated Contractor Care specialist