Cloud Security Engineer/Architect
Role summary
This is a contract role for a Multi-Cloud Security Engineer/Architect. The primary focus is on implementing and defining cloud security strategies, standards, and best practices across multiple cloud platforms (AWS, Azure, GCP). Key responsibilities include integrating cloud services into corporate cybersecurity, implementing cloud-native security monitoring and tooling (like wiz.io), designing secure network traffic flows, developing threat models, and driving the adoption of authentication and authorization architectures. The role also involves mentoring staff, contributing to secure service catalogs, and maintaining compliance. Collaboration with engineering and operations teams is essential to address security gaps and foster a security-aware culture within the financial industry.
Role: Cloud Security Engineer (Multi-Cloud)
Job Location: Hybrid (Chicago IL, Charlotte NC, Frisco TX, or Iselin NJ)
Type: Contract
- Implement cloud security strategy, standards, procedures, best practices, and DevSecOps.
- Implement processes and technical controls supporting cloud security standards including integration of cloud services and workloads into corporate cybersecurity services.
- Collaborate with operations and engineering teams to implement and tune cloud-native security monitoring, tooling and reporting
- Implement CSPM tools such as wiz.io across multiple cloud platforms
- Define cloud security policies, standards, and best practices in a multi-cloud environment
- Promote awareness of corporate cybersecurity policy, standards and guidelines
- Design cloud-based network traffic flows to drive anomaly detection capability
- Mentor engineering and operations staff on unique cloud-based security controls
- Develop tools to improve cloud specific anomaly detection requirements
- Foster a culture of security by partnering with solutions architects & other business teams to balance key performance and security
- Perform regular reviews of cloud infrastructure for security, and cloud best practices.
- Develop threat models to identify risks and prioritize improvements to our architecture.
- Drive the adoption of Authentication and Authorization reference architectures for managing cloud infrastructure.
- Educate peers on applying the latest cloud native technologies when developing new services, systems and applications.
- Contribute to a secure/compliant cloud-native service catalog, repositories
- Maintain Compliance across our Production, Development and Corporate systems hosted in the public clouds
- Collaborate with engineering and operations teams toward implementing controls and processes that address identified gaps
Preferred qualifications & experience:
- Compliance Automation
- Strong experience in vulnerability management & risk assessment
- Strong experience in implementing CIS, NIST & other benchmarks
- Encryption theory & key management (PKI)
- Multi-Cloud security experience working in the Financial industry
- Proficient in analyzing architecture patterns, diagrams, Network & application architecture
- Ability to identify threat surfaces & identify pro-active & reactive security controls to minimize the overall residual risk.
- Cloud certifications in AWS, Azure & GCP is preferred.
