Discover, remediate and validate security issues across cloud infrastructure per industry standard information security policies
Build, deploy, and manage production security tools and services to monitor networks, endpoints, and cloud workloads
Design and operate scalable processes to provision cloud access and maintain least-privilege
Maintain a reliable, easy to use and low-touch infrastructure using technologies such as Terraform, Kubernetes, and immutable images
Partner closely with security leadership, compliance and engineering to execute on security strategies for Snowflake infrastructure
Assess and propose solutions regarding cloud security to Snowflake leadership
Perform architectural and design reviews through the security lens and provide timely, actionable requirements and recommendations
MINIMUM QUALIFICATIONS:
4+ years experience deploying services on public cloud infrastructure
Detailed understanding of cloud and network security
Fluency in one or more programming or scripting languages
Experience deploying and customizing security tools to address threats and lower risk: vulnerability scanners, static analyzers, web application firewalls, IDS/IPS, endpoint security monitoring, etc.
Knowledge of networking and web protocols (TCP/IP, HTTP, TLS, REST), and the ability to analyze traffic to find anomalies
Understanding of modern cloud technology components and deployment patterns: virtual machines, containers, Kubernetes, serverless, infrastructure as code, etc.
Demonstrated ability to collaborate with other teams to achieve complex objectives
PREFERRED QUALIFICATIONS:
6+ years experience working in an information security discipline
Experience deploying services in a multi-cloud environment, with particular value on Azure and GCP expertise
Ability to write SQL queries and build dashboards, metrics, and reports to drive security outcomes
Experience using CI/CD pipelines to perform automated security testing and change management
Have read and are capable of implementing ideas from “Site Reliability Engineering” and “Building Secure & Reliable Systems”
Contributions to the security community, such as open source tools, research papers, conference talks, etc.