Jobs Companies ON.energy AWS Cloud Security Engineer

Sobre este puesto de AWS Cloud Security Engineer en ON.energy

ON.energy · Presencial · Argentina

ON.energy is building the backbone of energy and AI infrastructure powering grid-safe data centers and mission-critical facilities. The company supplies and operates hyperscale power systems that solve the toughest resilience challenges, delivering custom solutions for AI data centers, mission-critical facilities, and front-of-the-meter assets. ON recently announced a 5GW partnership, with 3GW currently under construction across multiple hyperscale data center campuses. With patented technology and proprietary software, ON.energy develops projects worldwide that set new benchmarks for resilience.

Key Responsibilities 

  • The multi-account security foundation. AWS Organizations structure, SCPs, guardrails, a security tooling account, centralized logging, and secure baselines — delivered as infrastructure as code, not console clicks.
  • Security standards and review gates. You can mandate controls and block deploys that introduce unacceptable risk, through review gates on identity and network changes, a documented exception path, and a defined escalation route.
  • AWS identity and access. IAM Identity Center as the single front door, federated with Entra ID in partnership with IT, who own Entra as the source of truth. Role and group model mapping job functions to permissions; joiner/mover/leaver; privileged and break-glass access; workload identity; recurring access reviews. Hands-on at first, progressively automated so it stops being manual work.
  • Cloud-to-site connectivity and segmentation — the defining part of this role. Every plant, BESS site, and remote asset that reaches our cloud does so over a path you design and defend: site-to-cloud VPN and private connectivity, hard segmentation between IT and OT zones, DMZ and broker patterns for site telemetry, certificate and device identity for field gateways, remote vendor access to sites, and strict control over what may initiate traffic in each direction. You own the cloud side of that boundary and share the path itself with the OT security owner.
  • Threat detection, monitoring, and mitigation. You are expected to know how attacks actually run — credential and token abuse, cross-account privilege escalation, exposed control and management interfaces, lateral movement from a compromised site network into cloud, supply-chain and dependency compromise, ransomware staging — and to build the monitoring that catches them. GuardDuty, Security Hub, Detective, Inspector, Config, and CloudTrail tuned for real signal-to-noise, detections mapped to MITRE ATT&CK and ATT&CK for ICS, runbooks the wider team can execute, and the mitigations driven to done.
  • Vulnerability management. Scanning coverage across workloads, images, and dependencies; risk-based triage and prioritization; remediation SLAs and exception handling; posture reporting. You identify and prioritize; the AWS engineers remediate in the workloads they own.

 

Key Requirements

  • 5+ years in cloud security, security-focused infrastructure, or cloud operations, with deep hands-on AWS.
  • Production experience in multi-account AWS environments.
  • Demonstrable command of attacker techniques and the detections and mitigations that counter them — you can walk an intrusion path end to end and explain how you would catch it, contain it, and close it.
  • Hybrid and site-to-cloud network security: segmentation, VPN, private connectivity, firewalls, routing, DNS, CIDR and subnetting — securing connections between cloud and physical facilities.
  • Strong AWS identity: roles, policies, permission sets, MFA, least privilege, access reviews; IAM Identity Center federated with an external IdP, ideally Microsoft Entra ID.
  • AWS-native security services: GuardDuty, Detective, Security Hub, Inspector, Config, CloudTrail, KMS, WAF.
  • Infrastructure as code — CDK, CloudFormation, or Terraform. You build controls, you don't click them.
  • Advanced English (B2–C1) for daily work with English-speaking teams and written security documentation.

Preferred Qualifications

  • Security experience in OT- or ICS-adjacent environments: IT/OT segmentation, Purdue-model zoning, secure remote access to field sites, and protocols such as Modbus, DNP3, OPC UA, or MQTT crossing into cloud.
  • Detection engineering and SIEM work; threat modelling; incident response you have personally run.
  • Regulated or compliance-driven environments where access control, monitoring, and audit evidence are held to an external standard.
  • Turning scanner output and audit findings into prioritized, actionable work for engineers who do not report to you.
  • Troubleshooting security, identity, networking, and infrastructure issues across cloud and hybrid environments.
  • Landing zones, Control Tower, and security account patterns.
  • IEC 62443 or NIST SP 800-82 familiarity.
  • Containers and serverless workloads.
  • Energy, utilities, or other mission-critical environments.
  • Wazuh, Datadog, Grafana, or similar.
  • Security documentation and ADRs.

Certifications

Valued as a signal, not a substitute for experience: AWS Certified Security – Specialty; AWS Certified Advanced Networking – Specialty; AWS Certified Solutions Architect; GICSP or GIAC GRID; CISSP; CCSP; Microsoft Certified: Identity and Access Administrator Associate.

 

#LI-AD1


For US-based roles - What you’ll get:

  • Competitive salary + annual performance-based bonus eligibility
  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off and company holidays 

For Mexico-based roles - What you’ll get:

  • Competitive salary + annual performance bonus eligibility
  • Christmas Bonus (Aguinaldo): 30 days
  • Major medical expenses and life insurance
  • Paid time off and holidays (per local policy)

For all roles:

  • Professional development and growth opportunities
  • Opportunity to grow with a mission-driven team shaping the future of clean energy
  • Equal Opportunity: ON.energy is committed to equal employment opportunity and to maintaining a work environment free of harassment, discrimination, or retaliation.
  • Accommodations: If you need an accommodation during the application process, email [email protected]
  • Benefits vary by role and location and are subject to change.

Agency Notice: ON.energy does not accept unsolicited resumes from staffing agencies, search firms, or third-party recruiters. Resumes submitted without a fully executed Master Services Agreement (MSA) and a written request from an authorized member of our Talent Acquisition team will be considered the property of ON.energy. No placement fees or compensation will be paid for unsolicited candidate submissions.

¿Listo para postularte en ON.energy?
Postúlate en ON.energy

Sobre ON.energy

 

Take your next step with ON.energy

 

At ON.energy, we are proud to be an equal opportunity employer, offering a wide range of career opportunities for individuals passionate about driving the energy transition forward. Our culture is dynamic, innovative, and far from the traditional corporate mold. We are built on a foundation of customer satisfaction, teamwork, trust, and an unwavering commitment to excellence.

 

Joining ON.energy means advancing your career in the energy sector with exciting opportunities across many departments and skill-sets. We embrace diverse perspectives and are dedicated to equipping our team with the tools, resources, and support they need to thrive.

 

Be a part of a company that values your ideas, fuels your growth, and empowers you to make a meaningful impact in shaping the future of energy.

 

 


 

Open Positions:

 

Ver todos los empleos en ON.energy →

Empleos similares

Dlocal
Principal Security Engineer – Identity & Access
Dlocal
⚡ Postúlate pronto Madrid Híbrido
● Nuevo 👁 Visto ✓ Postulado hace 1d
adaption
Platform Engineer, APIs and Security
adaption
⚡ Postúlate pronto San Francisco · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 4d
Backblaze External Website
Sr. Software Engineer - Application Security
Backblaze External Website
⚡ Postúlate pronto Remote - Argentina; Remote - C... · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 1sem
Backblaze External Website
Sr. AI Security Engineer
Backblaze External Website
⚡ Postúlate pronto Remote - Argentina; Remote - C... · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 1sem
Mindrift
AI Evaluation Engineer (Python, QA or Security)
Mindrift
⚡ Postúlate pronto Brazil · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 1sem
Vidmob
Staff DevOps Security Engineer
Vidmob
⚡ Postúlate pronto Remote - LATAM · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 2sem
Solvd
Security Engineer II – IAM & SaaS Governance
Solvd
⚡ Postúlate pronto Argentina · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 2sem
Silver.dev
Canals - Security Engineer
Silver.dev
⚡ Postúlate pronto Argentina · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 2sem
HomeVision
Infrastructure Software Engineer, AI & Data Security (Contract, Argentina)
HomeVision
⚡ Postúlate pronto Argentina · restringido por ubicación $60,000–$96,000
● Nuevo 👁 Visto ✓ Postulado hace 2sem

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en ON.energy

Ver todos los empleos en ON.energy →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis