Job Description
Senior security professional with a firm understanding of cybersecurity principles and Google Cloud platform to work on threat modeling of various Google cloud services such as GKE Cloud SQL Cloud Storage etc. Using threat modeling you will identify threats and specify mitigating controls that will directly reduce the risk of operating in the Google Cloud platform.
Responsibilities:
Threat Modeling using a documented process.
Development of automation tools as required.
Maintain a high standard of work in identifying threats and specifying mitigating controls.
Attending to the lifecycle of identified threats and controls.
Delivery of threat models and supporting tasks within existing timeframes.
Required Technical skills:
IT experience minimum of 10 years with minimum a of 4 years in CyberSecurity/Information Security preferably in a highly regulated industry like financial services.
Threat Modeling (STRIDE PASTA Attack trees tooling Attack).
Identifying vulnerabilities using CWE or OWASP.
Experience working in a cybersecurity role.
Extensive knowledge of Google cloud platform.
Security practices pertaining to authentication authorization logging/monitoring encryption infrastructure security network/segmentation.
Operating systems and their hardening.
Development concepts (such as: CICD Pipelines SDLC).
Scripting languages Infrastructure as Code (Terraform CloudFormation).
Operating in a DevOps / agile team structure.
Understanding of Docker/K8S/serverless/helm.
Design and review technical architectures.
Certifications:
Google Cloud Architect Cloud Developer Data Engineer Network Engineer etc.
Google Professional Cloud Security Engineer.
CISM CISSP or any equivalent professional cyber security certification
authorization,network/segmentation,cism,pipelines,encryption,cloud,cicd,cyber-security,cloud developer,google cloud,authentication,scripting languages,infrastructure security,owasp,threat modeling,infrastructure as code,docker,network engineer,logging/monitoring,cissp,google professional cloud security engineer,devops,sdlc,k8s,agile team structure,technical architectures,data engineer,cwe,security,operating systems hardening,helm,serverless,google cloud architect,it experience,google cloud platform