At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. EY Infosec is seeking a Cloud Security consultant with expertise in cloud security architecture, configuration, and governance across the Microsoft Azure platform with subject matter expertise on Cloud Native Application Protection Platform (CNAPP) technology and its integration into development, release, and operational practices. This is a hands-on role to guide, implement and maintain the security of cloud services and infrastructure. The consultant will lead the enablement of CNAPP technology and apply best practices for secure deployments to proactively identify and mitigate security risks for EY’s business applications hosted in the Azure environment. The ideal candidate will also have familiarity with other cloud platforms such as GCP and AWS. Role summary This position is a Business security consultant to drive the full lifecycle enablment of the Wiz CNAPP platform across a large and growing portfolio of applications hosted in Azure, as well as at the Azure infrastructure level. The consultant will work within a DevSecOps model and enable automated security testing and compliance, vulnerability management, and overall risk reduction in the environment. The ideal candidate will have to think outside the box to solve unique security issues that arise and adopt new cloud services. The role will also provide advice to the project teams in designing, developing and implementing all aspects of security for complex global applications based on Microsoft Azure technology and generally the Microsoft technology stack. The role is very much an individual contributor capable of supporting multiple project teams. In other words, it is not a program management or oversight role, but one that requires collaboration with product owners, architects, developers, DevOps, and other information security roles in the design, implementation and certification of security controls across multiple projects/applications. This also requires knowledge of various IT system architectures and Cloud technology, as well as supporting technologies such as SAST tools, DAST tools, Identity and Access Management (IAM), network security, firewalls, audit and logging, and other security concepts as outlined in ISO27001, OWASP and related security standards. The consultant should have knowledge of 3rd Party security assessments and applicability of SOC1 and SOC2 reports and concepts of vendor risk management.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level