Jobs and Careers
PR

Lead, Cyber Security Operations- Cloud/Containers

Prudential Financial
United Statesfull_timeVerifiedPosted 10 Sept 2024
💰 $186,100/yr($125,000/yr$186,100/yr)

About the role

Job Classification:

Technology - Information Security

Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability and efficiency?
 

Your Team & Role

As a Lead, Cyber Security Operations- Cloud/Containers on the Attack Surface Management Team, you will partner with other security professionals across the Information Security Office, the Chief Technology Office, and other groups in Prudential to drive Prudential’s Cloud security efforts across the global enterprise.
 

You will lead the team to detect and respond to cloud and container vulnerabilities across the multiple technology stacks (images, open source, 3rd party software, etc). You will partner with ASM teams such as Application Security and Configuration Compliance leaders to identify “secure by design” opportunities to enhance baseline capabilities and establish preventive controls.
 

In addition, you will help leaders evolve and grow the strategic direction of the program and contribute to security standards, drive enablement of new capabilities (container vulnerability management, SBOM implementation, serverless computing) and identification of attack surface reduction opportunities. You will work on significant and unique issues where analysis of context-based risk, unique business environments or vulnerability exploitability requires an evaluation of variables to drive time-sensitive risk reduction efforts. In your efforts, you will continuously look at opportunities to automate and strengthen controls. An agile and continuous improvement/learning mindset is needed as part of our team.
 

Here is What You Can Expect on a Typical Day:

  • Lead the cloud security strategy, including the design and implementation of attack surface reduction and security configurations across all cloud environments (AWS, Azure, GCP, etc.).
  • Manage and oversee the vulnerability management program, including regular scanning, assessment, prioritization, and remediation of security vulnerabilities.
  • Collaborate with the Attack Surface Management team to identify and address security risks associated with cloud environments and ensure that they are properly mitigated.
  • Develop and maintain cloud security policies, procedures, and best practices in alignment with industry standards and regulatory requirements.
  • Act as a subject matter expert (SME) for cloud and container security, providing guidance to development, operations, and security teams on best practices and emerging threats.
  • Oversee the implementation of security tools and technologies to monitor and protect cloud infrastructure.
  • Support and assist security incident response efforts related to cloud environments, working closely with the Incident Response team to support any investigations.
  • Conduct regular risk assessments and support evaluation of the effectiveness of security controls and identify areas for improvement.
  • Stay up-to-date with the latest security trends, threats, and technologies, and recommend innovative solutions to enhance the security posture of the organization.
  • Collaborate with external partners, vendors, and auditors to ensure compliance with security standards and regulations.
  • Management of requirements for scanning policies, coverage and lifecycle management processes for vulnerabilities and misconfigurations (Qualys, Wiz). This includes configuration-based assessments where automated detections are not available.
  • Identification and monitoring of high-risk software, services and ports.
  • Responsible for continuous monitoring of attack surface and ensuring remediation governance via escalation to business and risk advisors.
  • Partner with support organizations to establish security standards, design requirements and build the roadmap to implement cloud security controls to ensure the secure deployment of cloud-based resources.
  • Work to Operationalize new processes for cloud and container continuous monitoring.
  • Provide mentorship, training, and guidance for team members, working with and guiding more junior team members.
  • Support managers and Prudential leadership on new initiatives and opportunities to grow our security practices.
  • Ensures proper communication of the program’s results, opportunities, and deficiencies, as needed, to Prudential upper management.
  • Leverage Security Operations and tool/process specific knowledge to resolve complex technical/process/people problems the team faces. 

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Prudential Financial

View company profile →