Manager, Cloud Security
Capital RxAbout the role
Location: Remote (For Non-Local) or Hybrid (Local to NYC area)
Position Summary:
As a Manager, Cloud Security, you will help build and manage services that detect and automate the mitigation of cybersecurity threats across Capital Rx infrastructure. You will work with our security engineers, software engineers, and DevOps engineers across multiple teams to develop innovative security solutions.
Position Responsibilities:
-
Lead, mentor, and develop a team of security practitioners, fostering a culture of continuous learning and improvement.
-
Drive the execution of security initiatives and projects, ensuring alignment with business and compliance goals.
-
Define and maintain a strategic roadmap for security engineering, incorporating innovation and automation to enhance security posture.
-
Advocate for security across the organization, influencing leadership and development teams to adopt security-first principles.
-
Drive strategic systemic solutions to solve, remediate, and automate recurring issues.
-
Interface with internal partner teams to help drive best practices and cybersecurity compliance.
-
Evaluate new software solutions with internal partners.
-
Write documentation for end-users as needed to facilitate procedural improvements.
-
Define and execute a roadmap to mature robust security, privacy, and risk management programs.
-
Evaluate, identify, and remediate risks associated with current vendors, new vendor acquisitions, and consumer data exchanges.
-
Actively participate in SDLC code-to-cloud and cloud-to-code integrations.
-
Help run Internal, external and vendor related red-team exercises.
-
Enhance cloud security strategies, ensuring compliance with frameworks such as NIST 800-53, SOC 2, HITRUST, FISMA, FedRAMP, and others.
-
Assist in developing, tracking and report threat intelligence metrics and KPI’s to senior leadership.
-
Experience with incident management and defense coordination against emerging cyber threats and critical vulnerabilities.
-
Facilitate coordination of annual third-party penetration testing.
-
Drive use cases to enable threat detection and hunting based on threat intelligence frameworks.
-
Establish and collaborate on the standardization of security practices amongst the development teams.
-
Champion Agile and Scrum practices and concepts.
-
Coordinate with the team to ensure security alerts are monitored 24x7 via on-call rotation.
-
Provide security consultation to teams across the company.
-
Responsible for adherence to the Capital Rx Code of Conduct, including reporting of noncompliance.
Minimum Qualifications:
-
Expert level experience related to duties and responsibilities.
-
Previous experience managing direct reports.
-
Extensive experience in AWS services related to security engineering.
-
Embracing and supporting this role as very hands-on, e.g. writing code daily.
-
Experience with serverless application architecture particularly as it applies to security and compliance.
-
Python & React/Redux Experience
-
Extensive experience writing and updating code and infrastructure via HashiCorp Terraform.
-
Extensive experience with DLP, SIEM, and cloud security vendors and services.
-
A customer-oriented approach to problem resolution.
-
Extensive experience leading security investigations, penetration testing, and/or incident response procedures.
-
Experience managing IT control auditing and compliance.
-
Experience with Wiz, Slack, DAST/SAST tools,
-
Excellent written and verbal communication skills
-
Highly self-motivated with an ability to work independently.
-
Desire to work at a rapidly growing organization.
-
Experience supporting remote users in a distributed environment.
Preferred Qualifications:
-
Azure experience
-
CISSP
-
CCSP
-
AWS Sec
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s