Our client is a global financial services firm located in New York City. They are seeking a Cloud Security Architect to join the team. The Cloud Security Architect will design and develop Cloud Security Architecture, controls for public and hybrid cloud systems. This is hands-on position with will directly contribute to the execution to the firm's business and technology transformation strategy, cloud architecture and lead design and implementation of security controls around cloud-based applications, across all types (including Infrastructure, Platform, and Software as a Service (IaaS/PaaS/SaaS). Cloud Security Architect will serve as the central point of contact for Information Security for Information Technology, Application and Infrastructure and LOBs teams within the organization for all matters related to cloud security. Cloud Security Architect is responsible for driving the adoption of the culture, practices, processes and tools that will enable the Data Science team to securely adopt DevOps practices. The successful candidate will have a deep understanding of Cloud, DevOps and the various points at which development and operations could be improved by culture, practices, and automation to improve the stability, security, resiliency, efficiency and speed of development. The Cloud Security Architect will partner with Information Technology and Business Support to: Develop Cloud Deployment/Architecture, Cloud Security and Controls Framework aligned to security frameworks CSA, CIS and NIST for multi-cloud environment. Design and develop security architectures for cloud and cloud/hybrid based systems. Possess a firm understanding of the offerings within Amazon Web Services (AWS), Microsoft Azure platforms and SaaS applications such as O365, Dynamics, SalesForce, Slack, Box. Design and implement cloud-native architectures and designs that will allow those requirements to be met with a minimal degree of risk to Organization and with appropriate security controls present. Designing and Developing Cloud-specific security policies, standards and procedures e.g. Identity and Access Management (SSO, SAML), and Privilege Management, Firewall management, SSL/IPSec, Encryption Key Management (BYOK), Security incident and event management (SIEM), Data protection (DLP, encryption), Vulnerability Management in partnership with Infrastructure Services, and Application Development. Conducting cloud security analysis of prospective clients Cloud platforms/environments based on Industry best practice Cloud Cyber Risk Framework. Performing Cloud Security Assessments of Cloud platforms/environments using industry standard frameworks such as ISO, CSA-CSM and NIST. Executing on Cloud security engagements during different phases of the lifecycle assess, design, and implementation. Troubleshooting system level problems in a multi-vendor, multi-protocol network environment. Develop and improve communication, collaboration, and integration between Data Science developers, Information Security, and IT operations Automate the application delivery pipeline and develop core services that automate steps where manual activities currently exist Adoption of SDLC worfklow (JIRA), Automated security scanning, Automated deployment (AIM) Support the adoption of Agile methodology across Information Security in partnership with Application Development LOBs.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed