Back to search
梅赛德斯-奔驰租赁有限公司 Linkedin · Posted 2d ago

Cloud Security

Beijing

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

该职位来源于猎聘 Objective of job: To safeguard Mercedes-Benz's cloud infrastructure, applications, and data by designing, implementing, and managing robust security strategies, controls, and solutions, ensuring compliance with industry standards and regulations, and proactively mitigating cyber threats to maintain the confidentiality, integrity, and availability of MB cloud-based assets. -Develop and implement cloud security strategies. -Assess and mitigate cloud security risks. -Implement and manage cloud security controls. -Ensure compliance with relevant regulations. -Collaborate with cloud team and application teams on security best practices. -Develop security automation in cloud environments. -Reducing risk while enabling the business to operate quickly, safely, and efficiently. -Promoting a security-first culture by acting as a liaison between the security team, cloud team and other departments. -Enhancing the security posture through innovative solutions and effective collaboration. -Staying up-to-date with the latest cloud security trends, technologies, and industry developments. Job designation

  • Cloud Security Strategy and Architecture
  • Developing and maintaining a comprehensive cloud security strategy aligned with business goals. -Designing secure cloud architectures and infrastructure. -Selecting and implementing appropriate security technologies and tools.
  • Security Implementation and Operations
  • Configuring and managing security controls in cloud environments -Monitoring cloud environments for security threats and incidents. -Responding to security incidents and breaches.] -Staying up-to-date on the latest cloud security threats, technologies, and trends -Evaluating current and new security products and services -Conducting research on emerging security threats and vulnerabilities
  • Risk Management and Compliance
  • Conducting risk assessments and vulnerability assessments of cloud environments. -Developing and implementing security policies, standards, and procedures -Ensuring compliance with relevant industry regulations and standards
  • Collaboration and Communication
  • Collaborating with other IT teams, developers, and business stakeholders. -Providing security training and awareness to employees. -Communicating security risks and recommendations to management. Qualification:
  • Proven experience in cloud security, with a deep understanding of cloud security principles, technologies, and best practices.
  • Experience with cloud security frameworks, such as CSA CCM, NIST, and ISO 27001.
  • Experience with cloud platforms such as Azure, AWS, and Ali Cloud
  • Relevant certifications, Certified Cloud Security Professional (CCSP), Certified Information Systems Security
  • Professional (CISSP), AWS Certified Security, Microsoft Certified: Azure Security Engineer, etc.
  • Experience with scripting languages (e.g., Python, PowerShell)
  • > 5 years experience with focus in areas of cloud operations and cloud security
  • Education: Bachelor's degree and above in Computer Science encompassing Information Security
  • Demonstrates in-depth expertise in at least one major cloud platform, such as AWS or Azure, with more than three years of hands-on cloud security experience across IAM, networking, storage, compute, containers, and serverless security models. Has proven experience building cloud capabilities from the ground up.
  • Strong cross-cloud architecture design capability, including the ability to design secure federation between AWS and Azure or other local Clouds across identity, networking, and data flows, rather than relying solely on basic VPN connectivity. 岗位职责(Job Designation) 一、云安全战略与架构(Cloud Security Strategy and Architecture) 制定并维护与公司业务目标相一致的整体云安全战略。 设计安全可靠的云架构和云基础设施。 评估、选型并实施适合的安全技术及工具。 二、安全实施与运营(Security Implementation and Operations) 配置和管理云环境中的安全控制措施。 持续监控云环境中的安全威胁和安全事件。 响应和处理安全事件及数据泄露事故。 持续跟踪最新云安全威胁、技术和行业趋势。 评估现有及新引入的安全产品和安全服务。 研究新兴安全威胁及漏洞风险。 三、风险管理与合规(Risk Management and Compliance) 对云环境开展风险评估和漏洞评估。 制定并实施安全政策、标准及流程规范。 确保符合行业法规、监管要求及安全标准。 四、协作与沟通(Collaboration and Communication) 与IT团队、开发团队以及业务部门保持紧密合作。 为员工提供安全培训和安全意识宣导。 向管理层沟通安全风险、改进建议及管理措施。 任职资格(Qualifications) 基本要求 具备扎实的云安全实践经验,对云安全原理、安全技术及实践有深入理解。 熟悉并具备以下云安全框架的实践经验: CSA CCM(Cloud Controls Matrix) NIST ISO 27001 具备以下主流云平台安全经验: Microsoft Azure Amazon Web Services(AWS) 阿里云(Alibaba Cloud) 持有以下相关认证者优先: CCSP(Certified Cloud Security Professional) CISSP(Certified Information Systems Security Professional) AWS Certified Security Microsoft Certified: Azure Security Engineer 其他相关安全认证 熟悉脚本开发语言,例如: Python PowerShell 5年以上云运营(Cloud Operations)及云安全(Cloud Security)相关工作经验。 计算机科学相关专业本科及以上学历(包含信息安全方向)。 核心能力要求 云平台深度安全能力 至少精通一个主流云平台(如AWS或Azure)。 在以下领域拥有3年以上实际云安全经验: IAM(身份与访问管理) 云网络安全 云存储安全 云计算资源安全 容器安全 Serverless(无服务器架构)安全 具备从零开始建设企业云安全能力体系的成功经验。 跨云架构设计能力 具备较强的跨云安全架构设计能力。 能够设计AWS与Azure或其他本地云平台之间的安全互联方案,而不仅仅是依赖基础VPN连接。 能够在以下领域实现安全联邦与可信互通: 身份认证与授权(Identity Federation) 网络架构与网络通信(Networking) 数据流转与数据安全(Data Flow Security)
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search