Senior Cloud Security Engineer Lead
BMOAbout the role
Application Deadline:
07/30/2024Address:
1630 Chicago RoadJob Family Group:
TechnologyWe are seeking a highly skilled Senior Cloud Security Specialist with expertise in securing cloud platforms, particularly AWS and Azure. The ideal candidate will have hands-on experience in cloud security and a deep understanding of various aspects including Identity and Access Management, Data Protection, Infrastructure Security, Logging and Monitoring, Incident Response, and Compliance Frameworks such as CIS and NIST. The candidate should also possess excellent communication skills and the ability to collaborate effectively with stakeholders across different teams.
You are a leader with a strong technical background. You're have demonstrated strength at developing and implementing secure cloud architectures using a risk-based cybersecurity & data privacy strategy, defining security patterns, roadmap and operating model that leverages collaboration, facilitating industry-standard information security governance, advising senior leadership on cybersecurity & privacy risks and threats and investment strategies, and documenting appropriate policies and procedures to manage information security risks.
Your Responsibilities
Secure cloud platforms (AWS and Azure) by implementing best practices and industry standards.
Develop and implement Identity and Access Management strategies to ensure secure access control.
Implement data protection measures to safeguard sensitive information within cloud environments.
Strengthen infrastructure security through appropriate configurations and security controls.
Establish logging and monitoring mechanisms to detect and respond to security incidents.
Build detective controls to identify and mitigate potential security threats.
Lead incident response efforts to address security breaches or vulnerabilities.
Ensure compliance with relevant regulatory requirements and industry standards.
Review cloud architecture designs and provide recommendations for security enhancements.
Communicate security risks and best practices to technical and non-technical stakeholders.
Possess programming skills to automate security processes and tasks.
Demonstrate a strong understanding of network concepts and their application in cloud security.
Knowledge of CI/CD pipelines and ability to secure CI/CD processes (DevSecOps).
Work on automation initiatives to streamline security operations and improve efficiency.
Act as a subject matter expert (SME) in cloud security, providing guidance and support to the team.
Assist in security alerts investigations and resolution.
Demonstrate leadership qualities to mentor junior team members and drive security initiatives forward.
Required Core Skills:
A university degree in Engineering, Computer Science, or Information Technology.
5-8 years of experience developing and fielding security architectures and/or engineering
Security certification such as CISSP or CCSP or CCSK or any Cloud Certified Professional or Specialty certification (e.g., AWS Certified Security Specialty, Microsoft Certified Solutions Expert).
Proficiency in Identity and Access Management (IAM) and data protection strategies.
Strong understanding of infrastructure security principles and practices.
Hands-on experience with logging and monitoring tools for cloud environments.
Excellent communication skills with the ability to interact effectively with stakeholders.
Knowledge of technical security control environments and compliance frameworks including CSA CCM, ISO27001, ISO 27017 and NIST
Demonstrated Knowledge of cloud architecture, cloud operations, cloud-based identity access and management, security, automation, and orchestration.
A clear understanding of security protocols and standards and experience with software and security architectures
Extensive experience with Cloud-native Security Solutions
Firm grasp of networking protocols and operations. Comfortable with low-level packet sniffing, working knowledge on Kali, Wireshark, Burpsuite, Metasploit, Nmap, fiddler, sqlmap, Nessus. Knowledge of network attacks, detections, and defenses
knowledge of theoretical and applied cryptography, key management, and a strong understanding of cryptography algorithms such as RSA, AES, SSL vs TLS, PKI, etc
Knowledge of Identity and Access Management concepts and technologies to secure production and corporate access, such as SSO, SAML Federat
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s