Cloud Security Architect
Indexed description
- Global Award-Winning Culture
- Flexible Work Environment
- Generous Paid Time Off
- World-Class Benefits and Compensation
- Rapid Growth Opportunities
- Company Sponsored Two-Way Transportation
- Exponential Career Growth
People
Duties and Responsibilities aligned with Key Results:
- Own cloud security operations and posture management across the Firm’s multi-cloud environment.
- Engage directly with cloud platform and development teams as a security partner.
- Operate with a high degree of independence while maintaining clear communication with security leadership.
- May lead the security team in managing daily security operations center functions.
- Consult on security requirements and identify system integrations by evaluating and understanding business strategies and requirements.
- Create a positive team member experience.
- Serve as a cloud security subject matter expert for engineering and platform teams across the Firm.
- Integrate security requirements early in the build process—architecture reviews, Infrastructure as Code (IaC) pipeline checks, and predeployment guardrails.
- Translate risk into actionable guidance that enables delivery.
- Collaborate with our practice areas, as well as external resources, to ensure all information security-related matters are designed and maintained appropriately.
- Serve as the security expert in application design, cloud, network, mobility, and platform operating system efforts.
- Own the cloud security posture management platform: configure findings, drive remediation, and maintain accurate exposure reporting.
- Enforce cloud security policies and guardrails across identity, network security, data access, and resource configuration.
- Conduct threat hunting, own detection coverage, and treat every incident as an input to something that gets hardened.
- Stay current on cloud-specific adversary techniques and apply them to detection logic and hardening priorities.
- Plan and champion new security technologies, architectures, and products that will support the information security requirements for the Firm.
- Eight or more years of progressive information security experience, including four to six years of direct, hands-on cloud security experience.
- Production experience operating a cloud security posture management platform or cloud-native application protection platform.
- Hands-on experience across at least two major cloud platforms.
- Cloud platform and security knowledge sufficient to interpret and prioritize cloud security posture management findings without guidance.
- Experience with cloud security policy enforcement, including guardrails, baseline controls, or policy as code in a live environment.
- Security operations experience, including alert triage, event investigation, and incident response.
- Experience working alongside engineering or development teams as a security partner.
- Clear written communication skills across technical and nontechnical audiences.
- Highly self-motivated and directed.
- Experience with Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
- Kubernetes and container security experience.
- Shift-left experience, including Infrastructure as Code pipeline security, predeployment misconfiguration checks, or continuous integration/continuous delivery (CI/CD)-integrated security controls.
- Knowledge of common information technology regulatory compliance requirements associated with any of the following: Health Insurance Portability and Accountability Act (HIPAA), Health Information Technology for Economic and Clinical Health Act (HITECH), ISO 27001/27002, System and Organization Controls (SOC) 1/2, Sarbanes-Oxley Act (SOX), Payment Card Industry (PCI) requirements, and security best practices and procedures.
- Microsoft AZ-500, AWS Certified Security – Specialty, or Certified Cloud Security Professional (CCSP) certification preferred.
- Certified Information Systems Security Professional (CISSP) certification is a plus but not required.
Supervisory Responsibilities
This role may manage a team of direct reports.
Work Environment
- Standard indoor working environment.
- Position requires regular interaction with employees at all levels of the Firm; interaction with external vendors and clients is also necessary.
- Occasional long periods of sitting while working at a computer.
- Travel requirement: less than 10%.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search