Docebo
Senior Security Engineer
Part remote, part office, you need to live within commuting distance of a named location.
Hybrid · Milan, Italy
Employer listed it 3 months ago · Added yesterday
Been open since 3 months ago. Long-running listings are sometimes left up after the role is filled.
Salary
€51,000–€65,000
Location
Hybrid · Milan, Italy
Timezone
Not stated
Contract
Full-time
Experience
Senior
Category
Software
Published by the employer
Remote flexibility
Hybrid
This role is only partly remote, the employer expects time in the office around Milan, Italy, Biassono, Italy, Hybrid, so you need to live within commuting distance.
What the employer says
- Source listing states candidate location: "Milan, Italy, Biassono, Italy, Hybrid"
- Listing mentions "Hybrid" and three days a week in the office
What Nomaders makes of it
- Not suitable if you plan to move between countries
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Artificial Intelligence. Actual Impact.
At Docebo, we’re using AI to change how people learn at work—and we mean actually change it. We’re an AI-powered learning platform that helps organizations create, deliver, and manage training all in one place. But our real mission goes deeper: we help teams move faster, work smarter, and focus on the work that truly matters. Our platform is built with intelligent, time-saving tools that personalize learning, eliminate busywork, and turn training from a checkbox into a superpower. The result? Better experiences for learners and real results for businesses.
We’re shaping the future of learning with a team that isn’t afraid to challenge the status quo. If you're excited by the idea of using AI to make work-life better for real people–you’ll feel right at home here. And it’s not just what we build, it’s how we show up. At Docebo, our values aren’t just posters on the wall—they guide how we work every day. We call it the Docebo Heart : trust by default, assume positive intent, and create space for different perspectives to thrive.
So… what are you waiting for? Join 900+ Docebians around the world and help us reinvent the way people learn, because learning never stops.
Role Overview
The Senior Security Engineer will play a central role in securing Docebo's cloud infrastructure, with a primary focus on AWS environments. Working closely with Cloud Infrastructure & Operations, Engineering, and other security teams, this role is responsible for designing, implementing, and continuously improving cloud security controls across all layers of the stack — from infrastructure provisioning and container orchestration to runtime detection and compliance enforcement. This is a hands-on, high-ownership role for someone who thinks in terms of risk and moves quickly to reduce it. The role also includes participation in an on-call rotation for security incidents affecting Docebo systems.
Responsibilities (including but not limited to):
Cloud Security Architecture & Hardening: Own the security posture of Docebo's AWS environments. Define and enforce secure account structures, service control policies (SCPs), guardrails, and baseline configurations across multi-account setups. Evaluate and improve network segmentation, IAM boundaries, and data protection controls. Identify and remediate misconfigurations using CSPM tooling and manual review.
Infrastructure as Code Security: Partner with Cloud Infrastructure to integrate security controls into IaC workflows. Define guardrails to catch insecure configurations before deployment. Own security scanning in CI/CD pipelines and promote a shift-left approach to cloud security across engineering teams.
Incident Response & On-Call: Participate in the on-call rotation for security incidents, including triage, containment, and escalation for after-hours events. Lead investigation and root cause analysis for cloud security incidents with clear written post-mortems. Leverage automation and AI tooling to reduce mean time to detect and respond.
Cloud Detection & Threat Monitoring: Build and maintain detection coverage for cloud-native threats (privilege escalation, unusual API activity, lateral movement, data exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud.
Vulnerability & Configuration Management: Own vulnerability management for cloud workloads — prioritizing findings from cloud configuration assessments, and runtime protection tools. Drive remediation with Engineering and Infrastructure teams, and build automated enforcement where manual review doesn't scale.
Identity & Access Management: Define and enforce least-privilege principles across AWS IAM, service accounts, and federated identity. Review and improve IAM policies, permission boundaries, cross-account roles, and access patterns. Reduce standing access and enforce JIT access where appropriate.
Development of Security Best Practices: Develop and document best practices, policies, and procedures for cloud security. Provide guidance and training to engineering and infrastructure teams to promote a security-aware culture.
Vendor relationships: Maintain relationships with security vendors for technical issues, ensure smooth operations of security tools and services, and escalate problems or incidents to vendors when required.
What it takes to be successful :
You're a cloud security practitioner who operates with a builder's mindset. You understand AWS deeply — not just its security services, but how misconfigurations and design decisions create real risk. You're comfortable reading IaC, reviewing IAM policies, and diving into CloudTrail logs to reconstruct what happened. You know how to work with engineering and infrastructure teams as a partner, not a gatekeeper — and you can communicate risk clearly to stakeholders who don't live in the cloud console. You're comfortable being on-call and making decisions under pressure.
Additionally, holding security-related certifications such as those from ISC2, ISACA, SANS, or CompTIA, and having Cloud Architecture certifications (AWS Security Specialty, AWS Solutions Architect, or equivalent) will significantly enhance your effectiveness in this role.
We know great candidates don't always check every box. If you're excited about this role but don't meet 100% of the qualifications listed, we still encourage you to apply — we'd love to hear from you.
Requirements :
5+ years of relevant work experience in cybersecurity, with a strong focus on cloud security in production AWS environments.
Deep hands-on experience with AWS security services: IAM, SCPs, CloudTrail, GuardDuty, Config, KMS, VPC security, and more.
Good knowledge of Kubernetes security — including RBAC, pod security standards, network policies, admission controllers, and secrets management.
Experience with cloud security posture management (CSPM) and cloud workload protection (CWPP/CNAPP) tools.
Requirements
- ·5+ years of relevant work experience in cybersecurity, with a strong focus on cloud security in production AWS environments.
- ·Deep hands-on experience with AWS security services: IAM, SCPs, CloudTrail, GuardDuty, Config, KMS, VPC security, and more.
- ·Good knowledge of Kubernetes security — including RBAC, pod security standards, network policies, admission controllers, and secrets management.
- ·Experience with cloud security posture management (CSPM) and cloud workload protection (CWPP/CNAPP) tools.
- ·Experience securing IaC pipelines (Terraform, CloudFormation) and integrating security scanning into CI/CD workflows.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, hybrid, matches where you plan to live and work.
- 2Tailor your CV to the role at Docebo, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
€51,000–€65,000 · You'll be taken to the employer's careers page.