Cloud Security Engineer
UMB BankAbout the role
Our Information Security organization serves as the eyes and ears of UMB’s technology security and ensures controls, authentication and authorization are in place to keep UMB systems and applications safe. We monitor, discover and remediate any vulnerabilities while upholding and complying with all established corporate policies, standards and procedures. We work with UMB associates to help them be effective and be able to perform their jobs by granting the appropriate access. We collaborate with other technical teams to ensure base security metrics are being met. Best of all, we get to use cutting edge tools to make sure all systems and company devices are free from any potential threats. In today’s digital world, our team plays a critical role in UMB’s enterprise security plan.
As a Cloud Security Engineer, you will serve as a cloud security subject matter expert and support UMB’s Infrastructure team deliver secure solutions in the cloud. This will favor a cloud-native approach using solutions that are supportable, repeatable, and balance security versus risk. You will provide operational support for the Information Security owned solutions and for enterprise projects and design while serving as a subject matter expert on a diverse team of Information Security Engineers. This is a subset of the overall responsibilities which will include multiple initiatives as assigned by IT leadership.
This role is hybrid (Mon thru Thu on-site / Fri remote) for candidates in the Kansas City metropolitan area and open to qualified remote candidates outside of the Kansas City area but only within the US.
How you’ll spend your time:
- Define and execute public cloud-centric security controls and help design secure patterns for computing, storage, networking, operational, and security domains. This includes advising application, product, and cloud infrastructure teams on incorporating cloud infrastructure capabilities with an information security mindset, actively collaborating with cloud stakeholders to deliver best-fit secure solutions for UMB, and identifying emerging cloud infrastructure services and needs to meet business requirements.
- Serve as a pragmatic, results-driven thought leader and consensus builder with a technology-savvy mindset capable of articulating complex IT concepts to all audiences, from technical contributors inside and outside the company.
- Deploy, consult, and manage security controls leveraging solutions included but not limited to AWS multi-accounts structure, Organizational Units, Service Control Policies (SCP), IAM policies, Virtual Private Cloud (VPC), AWS Control Tower Guardrails and best practices.
- Partner with application teams to support them in their design and implementation of infrastructure-as-code stacks that meet the needs of the applications leveraging technologies, included but not limited to Terraform, CloudFormation, CDK constructs, and Ansible.
- Advise on all aspects of secure cloud infrastructure offerings and solution design.
- Provide hands-on technical coaching to accelerate cloud security learnings across the organization.
- Provide accurate and current information on AWS services and serve as a consultant to the IT Information Security organization to solve business use cases.
We’re excited to talk with you if you have:
- Bachelor’s Degree in Management Information Systems, Computer Science or related field OR equivalent work experience.
- At least 4 years of experience designing and implementing secure solutions and securing public cloud workloads.
- At least 2 years of experience with Metrics, Events, Logging, and Tracing solutions like Cloudtrail, CloudWatch, or Splunk.
- Strong infrastructure-as-code (IaC) expertise and deployment experience with technologies such as Terraform or AWS CloudFormation.
- In-depth experience with automation methodologies, processes improvement, and development of CI/CD pipelines.
- Demonstrated knowledge/experience with at least 2 scripting languages like Python, PowerShell, AWS/Azure CLI, Ansible, Bash, and JSON.
- Hands-on experience deploying and operating AWS computer instances (EC2), AWS Storage Services (EBS/S3/Glacier), AWS multi-accounts environment, IAM Policies, AWS Tower, AWS Config, and Service Control policies (SCP).
- Demonstrated knowledge with configuration management and pipeline automation with AWS DevOps, Jenkins, Git or similar offering.
- Knowledge with container technologies, such as Docker, Kubernetes, AWS EKS and ECS.
- Collaborated with service providers and partners.
- Working knowledge and expertise with common enterprise-grade security solutions.
Bonus Points if you have:
- Experi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s