Typical Day in Role:
We are seeking a Cloud Security Engineer to join our Enterprise Security Services team. You are familiar with the DevOps space and have strong Cybersecurity and Cloud security knowledge and skills. In addition, you have strong communication and stakeholder engagement skills, allowing you to understand and implement Cloud Native Application Protection Platforms (CNAPP) solution and apply best practices.
Accountabilities
Collaborate with stakeholders across the client– you will work closely with development and engineering, DevOps, cloud, application security and other application owner teams across the organization to deliver Cloud Security capabilities for the client.
CNAPP Operation
• Contribute to the success of our cloud transformation by supporting the Review and Triage of the findings flagged by CNAPP
• Develop and/or enhance strategies and processes to manage the security vulnerabilities and threats for cloud native applications
• Adhere to an established process flow that ensures development support teams, infrastructure support teams, and business risk owners implement control measures that effectively mitigate or eliminate identified risks
DevSecOps Operation
• Review and consolidate the DevSecOps processes and tools
• Develop and/or enhance the strategies and processes to identify, analyze, and communicate cloud workload vulnerabilities as per the CISO Directives, technical standards and published communication process flows
• Develop and/or enhance reporting to development teams and all levels of management in order to provide proper tracking and measurement of remediation relative to established objectives
• Understand how the client’s risk appetite and risk culture should be considered in day-to-day activities and decisions
Candidate Requirements/Must Have Skills:
• 10+ years’ relevant working experience in IT (development, DevOps, cloud security etc.)
• 3+ years’ experience with Cloud Security domains like CNAPP, CWPP, CSPM and/or tools like SCCE, CrowdStrike, Prisma Cloud, Aqua Enterprise, MS Defender etc.
• 3+ years’ experience as a DevSecOps Engineer, with demonstrated experience in security integration, automation of security processes, risk assessment and mitigation
• 5+ years’ experience with popular CI/CD tools and processes like BitBucket/GitHub, Jfrog Artifactory, Jenkins, Azure DevOps, GitLab CI/CD, CircleCI
Nice-To-Have Skills:
• 5+ years’ experience with documenting process, procedure, and user guide like a technical writer.
• 3+ years’ experience with large organization cloud transformation – Top 5 Canadian banks
Soft Skills Required:
• Excellent communication skill and good support skills for triaging and analysis of issues for all development teams
• Proficient at collaborating with various stakeholders to achieve the objectives assigned
Education:
• Undergrad or equivalent experience – valuing work experience more
• GCP PCSE Certification will be asset