Ally Financial-posted 9 months ago
Full-time • Senior
Onsite • Charlotte, NC
Credit Intermediation and Related Activities

The Cloud Security Principal Engineer position at Ally is a member of the Information Protection and Risk Management team and works closely with other members of the IPRM program to identify, manage, and mitigate security risks at Ally. The engineer is part of a broader team of security engineers reporting to the Sr. Director, Cloud Security who are responsible for developing, deploying, and integrating technical controls and tools to meet specific security requirements, as well as defining processes and standards to ensure that security configurations and tools are maintained. This is a project focused resource within the organization and will focus on designing and implementing both technologies and governance processes focused on our SaaS platforms. This resource will have potential opportunity to transition into a longer-term engagement to continue to mature and improve the SaaS security service.

  • Support existing security infrastructure and security projects with potential to take on responsibilities for other technologies such as DevOps toolchain, Cloud automation, SaaS posture management and other technologies.
  • Define and mature cloud-focused security policies and controls (governance, processes, frameworks, metrics).
  • Manage the day to day troubleshooting of the enterprise CSPM platform and other security controls, including configuration tuning and troubleshooting.
  • Work with Security teams to tune control systems to best meet the needs of the business.
  • Identify security risks and work with IPRM team to report and lead remediation efforts.
  • Perform architecture and engineering responsibilities in support of existing technologies and new security projects.
  • Conduct daily, weekly and monthly health checks, user activity audits and determine baseline offsets.
  • Identify, implement, and operationalize security technologies and processes to improve visibility and reduce risk.
  • Partner with other technical leaders to refine and mature Ally's security posture for cloud-based technologies and platforms.
  • Consult with project teams to ensure that platform architecture has proper security controls in place.
  • Engage in other Cloud Security efforts where skills may overlap: Cloud Platform Security and DevSecOps / Pipeline Security.
  • Demonstrated technical expertise in two or more technology areas (compute, storage, network, data, etc).
  • Strong background in information security practices, controls, and governance (CISSP preferred).
  • 5+ years of experience as a technical resource within an IT organization (enterprise / matrixed organization preferred).
  • 2+ years of experience with cloud platforms (operational experience preferred for AWS, Azure, GCP, etc).
  • Strong soft skills: builds partnerships, translates complexities into simple terms, ability to maintain focus on objectives.
  • Highly proficient in drafting technical documents: process/procedures, standards/policies, architectures, etc.
  • 3+ years Experience as a software developer with knowledge of automation, Infrastructure as Code and DevOps + CI/CD tools and processes.
  • 11 paid holidays, 20 paid time off days, and 8 hours of volunteer time off yearly.
  • Industry-leading 401K retirement savings plan with matching and company contributions.
  • Student loan pay downs and 529 educational save up assistance programs.
  • Tuition reimbursement and employee stock purchase plan.
  • Flexible health and insurance options including medical, dental and vision.
  • Employee, spouse and child life insurance, short- and long-term disability.
  • Pre-tax Health Savings Account with employer contributions.
  • Adoption, surrogacy and fertility assistance as well as paid parental and caregiver leave.
  • Mentally Fit Employee Assistance Program and subsidized Weight Watchers® program.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service