Expoint - all jobs in one place

The point where experts and best companies meet

Limitless High-tech career opportunities - Expoint

Bank Of America Senior Identity Security Engineer - Cloud 
United States, Texas, Addison 
946017733

29.08.2024

Job Description:

Job Description:

The Senior Identity Security Engineer – Cloud is a key individual contributor on the Identity & Authentication Services Team. We’re looking for an enthusiastic, inspired, creative thinker who can develop innovative strategic security solutions to complex business problems. In this role you will engage and partner with leaders across the bank leveraging your extensive hands-on background in (managing / delivering / implementing / architecting) cloud security technology combined with expertise in organizational and cross-functional communication to develop cloud security strategy, influence roadmaps, solution adoption, champion strategic opportunities / execution plans with the aim to improve security capabilities, reduce risk and position platform security enhancements.

Primary Level of Engagement: Is the day to day engineering lead for one or more initiatives, defines outcomes and the technical tasks required to complete the work.

Primary Interactions:

  • Direct Manager
  • Project Manager
  • Junior Engineers
  • GIS Peers
  • IT Stakeholders
  • Internal GIS Customers
  • Line of Business Customers

Key Responsibilities:

  • Serve as the in-depth subject matter expert for Identity and Authentication with a concentration on Cloud based engineering initiatives.
  • Lead the delivery of the major engineering milestones.
  • Serve as the point of contact for application teams working to integrate with SaaS products and Cloud base deployments.
  • Conduct research, proofs of concept and other exploration activities such as evaluating new toolsets.
  • Constantly looking for better ways of solving technical problems and designing the solution without being afraid of challenging the status quo.
  • Identify and raise risks or potential vulnerabilities at all stages of the security engineering process.
  • Think outside the box to develop multiple solutions to complex problems.
  • Navigate and work effectively across a complex, geographically dispersed organization.
  • Work closely with a diverse set of stakeholders with varying priorities to debate and negotiate paths forward.
  • Identify gaps in information security standards adherence and work with appropriate partners to develop plans to close gaps.
  • Mentor more junior security engineers and coach team members in the delivery and release.

Required skills:

  • 8+ years of experience in large scale security technology platform engineering, design, architecture, or strategy (experience in developing security strategy highly desired / preferred)
  • Extensive knowledge of cloud security (across a variety of commercial platforms)
  • Specific experience with Cloud Authentication service design and implementation
  • Experience with virtualization, containerization, SaaS platform security
  • Prior experience designing, engineering and implementing new Cloud authentication, encryption, key management, access management initiatives
  • Experience Cloud security policy / configuration management

Desired skills:

  • Experience with Identity Providers (Ping, Okta), Secrets Vaults (Hashi, CyberArch), Identity Threat Detection and Response (Crowdstrike, SIlverfort, Etc.)
  • Experience with distributed identity solution, identity proofing
  • Experience with Active Directory and Azure EntraID and AWS Identity Manager
  • Familiarity with common Information Security and data protection frameworks and standards (i.e. CIS, NIST, MITRE, ITIL, HIPAA, GDPR, PCI DSSS, ISO 270001)
  • Experience in building, configuring, operating and/or securing cloud infrastructure and applications in Azure or AWS, either with native cloud service provider capabilities or tools such as Terraform, Ansible, CloudFormation, Azure Resource Manager, Google Cloud Deployment Manager, or CloudBridge
  • Knowledge and understanding of key differences between most popular cloud provider solutions and cloud orchestration tools (e.g. Azure, AWS, GCP, Pivotal Cloud Foundry, BOSH, Kubernetes, Docker, etc.)
  • Minimum of two years scripting or programming experience in Python, Java, or any modern programming language.
  • Thorough understanding of network firewalls, proxy, DMZ architecture, remote access technologies
  • Experience building enterprise security strategy for cloud adoption or driving the program's evolution to meet new requirements
1st shift (United States of America)