The posting, in Cambridge Mobile Telematics's own words
archived Sep 26, 2026CMT is looking for a Senior Site Reliability Engineer, SecOps to help us change the world. CMT has helped protect over 65 million drivers and prevent over 126,000 crashes worldwide. We build AI to solve some of the most difficult challenges in mobility — understanding and reducing risk, detecting crashes, and getting people life-saving help. The problems are hard. The impact is real. No matter your role, your work will matter at CMT.
Responsibilities:
Use independent judgment and discretion to implement security tooling and controls in AWS as defined by the Security Engineering team, including deployment, configuration, agent coverage, and ongoing tooling health Implement IAM Roles and Policies, account-level guardrails, and secrets management in AWS in line with Security Engineering standards Remediate vulnerability, cloud security posture, and compliance findings across the AWS estate, tracking work to the remediation SLAs defined by the Security Engineering team Own the security telemetry pipeline — org-wide CloudTrail, GuardDuty, Security Hub, AWS Config, VPC Flow Logs, and application/audit logs — including coverage validation, retention and immutability requirements, routing into Lacework and Datadog, and managing ingest/retention cost Implement and maintain preventive controls — SCPs/RCPs, permission boundaries, Config rules and conformance packs, IaC policy-as-code in CI, and secret scanning — including drift detection, auto-remediation, and a documented exception/waiver process with expiry Implement network and data protection controls: security group and egress baselines, VPC segmentation, KMS key lifecycle and rotation, encryption-at-rest/in-transit standards, certificate lifecycle, and public-exposure prevention (S3 Block Public Access, IAM Access Analyzer external findings). Codify everything as infrastructure-as-code using Terraform and CI/CD pipelines, enabling updates through Pull Requests with approval workflows, while also automating maintenance tasks to reduce toil Provide secure-by-default Terraform modules and self-service paved paths so product teams inherit controls; consult on design reviews and threat models; act as the translation layer between Security Engineering standards and platform/application reality, feeding back where standards are impractical. Participate in incident response for security events, contribute to blameless postmortems and systemic remediation, including participating in an on-call rotation Complete any additional tasks as they arise