Designing testing and implementing security controls for Azure AWS and GCP across the companys cloud environments using thirdparty SaaS solutions.
Analyzing the companys cloud security needs and determining how to incorporate these requirements into detective cloud controls for all cloud service providers (CSPs).
Collaborating closely with vendors and partner teams to develop deploy and test cloud security services.
Creating and producing compliance reports that highlight the status of cloud infrastructure drift management.
Partnering with resource owners to address and correct configuration drifts.
Setting priorities coordinating with other teams and leading continuous improvement initiatives for security tools systems and processes.
Researching evaluating and implementing new technologies to continuously enhance security capabilities.
Integrating configuring documenting and deploying compliant infrastructure and support services within the cloud platform.
Diagnosing issues conducting root cause analysis and resolving bugs caused by managed or owned security solutions where feasible.
Working with Risk Management Security Architecture and Cyber Incident Response teams to ensure all required controls for cloud services are properly implemented and tested.
Operating within a globally distributed team to deliver innovative and reliable cloudfocused solutions.
Requirements
You have: (musthave skills)
Deep knowledge of at least one of the 3 main Cloud Service Providers (Azure AWS GCP)
Knowledge of the Shared Responsibility Model; keen understanding of the security risks inherent in hosting cloudbased applications and data
Experience developing across the security assurance lifecycle (mainly detect & respond controls)
Experience configuring native CSP security tooling and capabilities
Deep understanding of DevOps processes and workflows.
Working knowledge of the Secure SDLC process.
Experience with Infrastructure as Code (IaC) tooling such as Terraform
Strong in scripting languages such as PowerShell Python and Bash.
Experience creating technical architecture documentation.
Excellent communication written and interpersonal skills.
Experience in IT Service Management.
Ability to articulate complex technical concepts to nontechnical stakeholders.
You might also have: (nice to have skills)
Experience with CSPM and SaaS 3rd party solutions
Understanding of OPA/REGO
Knowledge of Agile best practices and methodologies
Familiarity with Logging and data pipeline concepts and architectures in cloud.
Experience with risk control frameworks and engagements with risk and regulatory functions
Experience in the financial industry
Azure AWS and/or GCP Certifications
Security certification such as CISSP GIAC CISM OSCP or equivalent
Configuration management and patch management using automated tools
Experience with governance risk and cybersecurity frameworks such NIST CSF COBIT 5 ISO 27001/2 ITIL
Familiarity with standard Azure/AWS/GCP security tooling such as Security Command Center VPC Service Controls Azure Monitor Azure Policy AWS SCP AWS Config AWS IAM Permission Boundary
Practical experience in designing and configuring CICD pipelines.
Practical experience in GitHub Actions and Jenkins.
You have: (must-have skills) Deep knowledge of at least one of the 3 main Cloud Service Providers (Azure, AWS, GCP) Knowledge of the Shared Responsibility Model; keen understanding of the security risks inherent in hosting cloud-based applications and data Experience developing across the security assurance lifecycle (mainly detect & respond controls) Experience configuring native CSP security tooling and capabilities Deep understanding of DevOps processes and workflows. Working knowledge of the Secure SDLC process. Experience with Infrastructure as Code (IaC) tooling such as Terraform Strong in scripting languages such as PowerShell, Python and Bash. Experience creating technical architecture documentation. Excellent communication, written and interpersonal skills. Experience in IT Service Management. Ability to articulate complex technical concepts to non-technical stakeholders. You might also have: (nice to have skills) Experience with CSPM and SaaS 3rd party solutions Understanding of OPA/REGO Knowledge of Agile best practices and methodologies Familiarity with Logging and data pipeline concepts and architectures in cloud. Experience with risk control frameworks and engagements with risk and regulatory functions Experience in the financial industry Azure, AWS and/or GCP Certifications Security certification such as CISSP, GIAC, CISM, OSCP or equivalent Configuration management and patch management using automated tools Experience with governance, risk and cybersecurity frameworks such NIST CSF, COBIT 5, ISO 27001/2, ITIL Familiarity with standard Azure/AWS/GCP security tooling such as Security Command Center, VPC Service Controls, Azure Monitor, Azure Policy, AWS SCP, AWS Config, AWS IAM Permission Boundary Practical experience in designing and configuring CICD pipelines. Practical experience in GitHub Actions and Jenkins.