Job Responsibilities:
- Lead the execution and enhancement of a long term information risk and control strategy designed to keep the information assets of the public cloud secure.
- Deliver risk based assessments of secure technology controls relating to cloud services, cloud platforms and architectural components.
- Lead business technology teams to understand firm control requirements and implementations across a broad range of cloud architectures.
- Perform security reviews of infrastructure-as-code for cloud platform development.
- Contribute to documentation and agile processes in support of security programs.
- Interface with wider CTC teams ensuring platform integration with security operations, threat intelligence, IAM and network security.
Required qualifications, capabilities and skills.
- Formal training or certification on security concepts and proficient advanced experience
- Solid understanding of how to secure public cloud technology.
- Eagerness to collaborate in a team, and comfortable in both virtual and office environments.
- Self-disciplined, self-managed, self-motivated and strong sense of ownership, urgency, and drive.
- Proficient verbal and written communication skills, including the ability to effectively participate in discussions and meetings with internal management, peer groups, regulators and senior stakeholders.
- Ability to prioritize and work under stringent timelines.
Preferred qualifications, capabilities and skills.
- AWS, Azure or Google Cloud certifications would be an advantage.
- Hands on experience of developing, engineering or architecting within a public cloud environment would be an advantage.
- Experience engineering with Terraform or infrastructure-as-code would be an advantage.
- Understanding of DevOps or CI/CD concepts would be an advantage.