Jobs and Careers
TI

Lead Cloud Security Engineer - Kubernetes

TIAA
United Statesfull_timeVerifiedPosted 26 Jun 2024
💰 $183,800/yr($119,600/yr$183,800/yr)

About the role

Lead Cloud Security Engineer - Kubernetes

TIAA has an opportunity for a Lead Cloud Security Engineer who has specialized in Kubernetes. The ideal candidate will possess an in-depth understanding of cloud security principles and has experience in securing Kubernetes environments. This role will plan, implement, upgrade, or monitor security measures for the protection of computer networks and information. In addition, will Assess system vulnerabilities for security risks and propose and implement risk mitigation strategies.

This position will provide security for cloud-based digital platforms and will play an integral role in protecting our organization’s data. This may involve analyzing existing cloud structures and creating new and enhanced security methods. Furthermore, will serve as part of a larger team dedicated to cloud-based management and security.


Key Responsibilities and Duties

  • Design, implement and maintain security controls for Kubernetes-based cloud environments to protect sensitive data and applications.
  • Conduct security assessments and audits of Kubernetes clusters to identify and remediate vulnerabilities.
  • Develop and implement security policies, procedures, and best practices for Kubernetes deployments.
  • Monitor Kubernetes clusters for security incidents and anomalies and respond to security events as needed.
  • Collaborate with DevOps and development teams to integrate security into the CI/CD pipeline and automate security processes.
  • Stay current with the latest Kubernetes security threats, vulnerabilities, and best practices.

Educational Requirements

  • University (Degree) Preferred

Work Experience

  • 5+ Years Required; 7+ Years Preferred

Physical Requirements

  • Physical Requirements: Sedentary Work


Career Level
8IC

Qualifications:

Required:

  • Minimum of five (5) years of working in an Information Technology role, preferably cybersecurity or cloud security.
  • At least 3 years’ experience with working with cloud security principles and best practices, with a focus on Kubernetes security. Possess hands-on experience with Kubernetes deployment, configuration, and management in a large scale or complex environment.
  • At least 3 years of direct experience implementing serverless and containerized workload security best practices for Kubernetes clusters, GKE, EKS, AKS platforms.
  • At least 3 years of experience assisting customers make decisions to achieve complex security outcomes in at least one major cloud provider (AWS or Azure or Google).
  • At least 3 years of programming experience in one of the following languages: Java, C++, or Python.

Preferred:

  • Experience building immutable infrastructure-as-code solutions using tools like Terraform, Ansible, Chef, Puppet, Salt, and Packer.
  • Experience implementing DevSecOps pipelines for infra, applications, data, providing cloud security guardrails with tools such as Deployment Manager, Terraform, OPA, Versatile scanning tools and other technologies.
  • Possess professional security certifications such as GSEC, CEH, CISSP, CCSP, GCP security engineer, AWS Security Engineer.
  • Experience conducting GCP, AWS and Azure Security Assessments of large client environments and be able to migrate workloads securely.
  •  Experience and understanding of security principles across infrastructure platforms, data layers, integration points, and application layers. Experience leading a variety of commercial security technology implementations.
  • Experience designing security solutions and implementing standard methodologies to harden Kubernetes in the cloud (e.g., GKE, EKS, ECS, OpenShift and AKS etc.)
  • A “Cloud First” approach that is centered on design principles like infrastructure-as-code, immutable deployments, etc.
  • Experience mapping generic corporate security/compliance requirements to a Kubernetes environment, micro segmentation using ISTIO.
  • Understand threats in the Kubernetes control and data plane, Supply chain security, tools and technology used for preventing and detecting container vulns.
  • Experience partnering closely with business units/engineering teams to facilitate Kubernetes adoption in a secure manner.LI
  • Possess effective communication and documentation skills, especially when collaborating with audiences who may not have a security background.

#LI-VR1

Related Skills

Application Programming Interface (API) Development/Integration, Automation, Communication, Consultative Communication, Containerization, DevOps, Enterprise Application Integration, Group Problem Solving, Influence, Organizational Savviness, Prototy

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

TIAA

View company profile →