About the job Senior Cloud Security Engineer
Our client is seeking an enthusiastic and passionate professional for a Senior Cloud Security, who wants to design and implement security solutions for systems and services in AWS and Azure. We need someone who can establish the highest standards that meet and exceed security governance solutions and practices. Provide assurance to management and auditors and ensure sustained protection by embedding controls in the operational and DevOps (CI/CD) practices with a focus on automation. We are looking for someone who has a high level of technical security expertise and who takes seriously the responsibility of monitoring, detecting, protecting and maintaining the security of data, systems, and networks.
You are a leader with a strong technical background. You have demonstrated strength at developing and implementing secure cloud architectures using a risk-based cybersecurity & data privacy strategy, defining security patterns and roadmap and operating model that leverages collaboration. Also be facilitating industry-standard information security governance, advising senior leadership on cybersecurity & privacy risks and threats and investment strategies, and documenting appropriate policies and procedures to manage information security risks.
As a qualified candidate, you will be part of the team driving Cloud implementation. As a member of this team, you should possess the ability to inspire yourself and all of our team. Based on your previous experiences you will inject new knowledge and skills into an already high performing team thus excelling our efforts to new heights.
- Assess, design, implement, automate, and document security solutions, controls, and processes for Amazon Web Service (AWS) and MS Azure cloud platforms;
- Develop and maintain Security patterns for Cloud Platforms and Services; Assess all cloud patterns to ensure adherence to best security practices and controls
- Design and implement DevOps processes, tools, and re-usable templates to incorporate security into application and infrastructure design patterns and the building of security controls into the CI/CD process.
- Build and deliver policies as code, automating security controls, and best practices.
- Review and approve codes and changes with security implications (e.g. IAM Roles and Policies, Security Groups etc.)
- Provide subject matter expertise on architecture, authentication, and systems security based on a clear understanding of our cloud engineering stack, services, and data flow
- Lead focused and continuous cybersecurity risk assessments of new and existing technologies to identify risks and appropriate controls that balance security and operability
- Provide effective and pragmatic cybersecurity guidance up-front in major technology projects, to enable the business to innovate securely
- Assist in investigation and remediation of security incidents and issues
- Be the cloud security subject matter expert for our Cloud Engineering group and its partners in any IaaS/ PaaS and SaaS implementations.
- Work closely with Information Security, product and software development teams to assess cybersecurity risk, cloud controls, and recommend solution and remediation in the cloud environment
- You are a self-starter, driven, and can handle multiple projects and priorities.
- You are passionate about driving the DevOps mindset and culture in a fast-paced, challenging environment where you get the opportunity to work with a spectrum of latest tools and technologies to drive forward Infrastructure-as-Code and Infrastructure-as-a-Service.
- You are actively looking to improve the solutions you implement, understand the efficacy of collaboration and reaching out across functional borders, and are keen to work in a team of CI/CD and Infrastructure specialists.
Required Core Skills:
- A university degree in Engineering, Computer Science, or Information Technology.
- 5-8 years of experience developing and fielding security architectures and/or engineering
- Security certification such as CISSP or CCSP or CCSK or any Cloud Certified Professional or Specialty certification (e.g., AWS Certified Security Specialty, Microsoft Certified Solutions Expert).
- Knowledge of technical security control environments and compliance frameworks including CSA CCM, ISO27001, ISO 27017 and NIST
- Demonstrated Knowledge of cloud architecture, cloud operations, cloud-based identity access and management, security, automation, and orchestration.
- A clear understanding of security protocols and standards and experience with software and security architectures
- Extensive experience with Cloud-native Security Solutions
- Firm grasp of networking protocols and operations. Comfortable with low-level packet sniffing, working knowledge on Kali, Wireshark, Burpsuite, Metasploit, Nmap, fiddler, sqlmap, Nessus. Knowledge of network attacks, detections, and defenses
- knowledge of theoretical and applied cryptography, key management, and a strong understanding of cryptography algorithms such as RSA, AES, SSL vs TLS, PKI, etc
- Knowledge of Identity and Access Management concepts and technologies to secure production and corporate access, such as SSO, SAML Federated Identity, RBAC, authentication & authorization solutions
- Experience with scripting (Python, Perl, Bash, PowerShell) and API integrations
- Demonstrable internal and external relationship building skills and the ability to clearly articulate complex security concepts that influence decision making within a diverse corporate culture.
- Ability to lead an in-depth client meeting/workshop across a broad range of topics including discovery, cloud compliance, and security
- Strong programming skills with experience in API and Webhook development using Python, Node.js, Ruby, PowerShell, and Shell Scripting languages.
- Strong interpersonal, communication and leadership Skills
- A critical thinker with strong research, analytics, and problem solving skills
- Self-motivated with a positive attitude and an ability to work independently and or in a team
- Ability to communicate across business units and the ability to interface with and communicate complex technical concepts to a broad range of internal and external stakeholders
- Time management skills with the ability to manage multiple streams and lead less experienced architects