5 дней назад
Cybersecurity Manager (Cloud Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cybersecurity Manager (Cloud Security): Protecting a global multi-cloud environment through cloud security posture operations, contextual risk assessment, and risk-based remediation with an accent on CNAPP, attack path analysis, and AI workload security. Focus on prioritizing exploitable cloud exposures, driving remediation across engineering teams, and building automation and shift-left security controls.
Company
is a global consulting firm delivering business strategy, technology, design, and transformation services.
What you will do
- Lead triage, risk assessment, and response decisions across CNAPP capabilities, including CSPM, CIEM, KSPM, CWPP, IaC security, secrets detection, SCA/SBOM, API security posture, and external attack surface management.
- Assess cloud findings across AWS, Azure, and Google Cloud by analyzing exploitability, attack paths, effective permissions, lateral movement, blast radius, and business impact.
- Monitor zero-day and critical vulnerability exposure across cloud workloads and prioritize remediation based on affected asset scope and risk.
- Evaluate AI and LLM security risks involving inference endpoints, model access, secrets, vector stores, plugins, tools, and LLMOps pipelines.
- Drive remediation with developers, cloud architects, security architects, platform engineering, threat intelligence, and DevSecOps teams.
- Improve shift-left security through CI/CD guardrails, infrastructure-as-code controls, automation, detection logic, runbooks, and CNAPP policy inputs.
Requirements
- 6–8 years of information security experience, including at least 6 years in cloud security operations or cloud infrastructure security.
- Hands-on CNAPP experience with triage, posture reporting, and policy tuning.
- Deep knowledge of security controls in AWS, Azure, or Google Cloud.
- Practical understanding of AI workload security, LLMOps pipelines, or inference endpoint risk.
- Experience driving remediation across engineering, platform, architecture, or AI enablement teams.
- Experience with Python, Bash, or API integrations for automation and operational scale.
Nice to have
- AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CCSP, or Certified Kubernetes Security Specialist.
Culture & Benefits
- Highly collaborative and technically rigorous Security Operations environment.
- Global work across information security, risk management, cloud engineering, platform engineering, and DevSecOps.
- Focus on clear risk ownership, practical remediation, and continuous improvement.
- is an equal opportunity employer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →