Назад
Company hidden
10 дней назад

Global Cybersecurity Analyst (Cloud Security)

Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Global Cybersecurity Analyst (Cloud Security) (CNAPP/AWS/Azure/Google Cloud): Monitoring and triaging cloud security findings across BCG’s multi-cloud environment while identifying exposure in AI and LLM workloads, with an accent on contextual risk analysis, attack paths, permissions, and data exposure. Focus on investigating critical vulnerabilities, translating findings into remediation guidance, and improving security operations through automation, scripts, queries, and runbooks.

Company

hirify.global is a global consulting firm delivering management consulting, technology, design, and digital transformation services.

What you will do

  • Monitor, triage, and investigate findings across CNAPP capabilities, including CSPM, CIEM, KSPM, CWPP, IaC security, secrets detection, SCA/SBOM, API security posture, external attack surface management, and AI workload exposure.
  • Assess exploitability, effective permissions, attack-path reachability, data exposure, model access, and potential blast radius across cloud and AI-adjacent environments.
  • Investigate zero-day and critical vulnerabilities affecting cloud workloads, containers, inference endpoints, orchestration layers, and supporting data stores.
  • Identify risks in AI and LLM workloads, including exposed inference endpoints, unsafe secrets handling, vector store exposure, and LLMOps pipeline misconfigurations.
  • Translate findings into developer-actionable remediation guidance, track open issues, follow up with asset owners, and escalate aged or blocked risks.
  • Improve security operations by reviewing IaC and CI/CD findings, writing scripts, refining queries, updating runbooks, and supporting security guardrail adoption.

Requirements

  • 2–4 years of experience in information security, including at least 2 years in cloud security operations.
  • Hands-on experience triaging findings in CNAPP or cloud security platforms.
  • Working knowledge of AWS, Azure, or Google Cloud security fundamentals.
  • Ability to assess exploitability, permissions, data exposure, and attack-path context.
  • Basic awareness of AI workload risks, including model access and inference endpoint exposure.
  • Experience with Python, Bash, or APIs for triage automation and finding enrichment.

Nice to have

  • AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CCSP, or Certified Kubernetes Security Specialist certification.

Culture & Benefits

  • Work within a collaborative and technically rigorous Security Operations team.
  • Collaborate with cloud engineering, platform engineering, security architecture, threat intelligence, and DevSecOps teams.
  • Focus on clear risk ownership, practical remediation, and continuous improvement.
  • BCG is an Equal Opportunity Employer and an E-Verify employer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →