As a Cloud Security Engineer, you will be responsible for Cloud Security (as part of Cyber Security) across both the banking arm and securities business under a dual‑hat arrangement. You will act and make decisions on behalf of both entities, ensuring comprehensive risk controls, compliance, and operational resilience across multi‑cloud environments.
Cloud Security Operations
- Monitor and proactively manage Cloud Security toolsets including CSPM (CloudGuard, Wiz, MS Defender for Cloud) and CWPP (CloudGuard, Wiz, CrowdStrike Falcon).
- Oversee Kubernetes security controls for workloads in AKS, OKE, EKS, and on‑prem environments.
- Review and assess enterprise cloud architectures for security gaps and recommend mitigations.
- Investigate and track cloud security alerts using ServiceNow workflows.
Policy, Standards & Governance
- Ensure NIST, ISO27002, and CIS‑aligned risk controls are covered.
- Develop, improve, and enforce cloud security standards, policies, and procedures.
- Conduct Cyber Security reviews for on‑prem, cloud, and third‑party systems, including firewall rules, architecture, and network designs.
- Support governance, risk, and compliance activities, including operational risk reporting and audit liaison.
Integration & Collaboration
- Collaborate with IT teams to highlight, manage, and mitigate Cyber Security alerts, threats, and vulnerabilities.
- Liaise with Technology and Business teams to ensure systems meet security standards or agree on mitigations.
- Provide operational insights to security engineering and architecture teams.
Continuous Improvement & Incident Response
- Support Cyber Security incidents, penetration testing, and remedial actions.
- Contribute to continuous improvement of security controls and detection rules.
- Maintain up‑to‑date knowledge of laws, regulations, and best practices relating to Cyber Security.
Experience
- You have 8–10 years of experience in Cloud, Information, or Cyber Security.
- You have experience implementing security solutions that enable business activity.
- You have been actively involved in audits and managed audit relationships.
Technical Expertise
- You have strong knowledge of frameworks and standards such as ISO27001, NIST, CIS, GDPR.
- You are proficient in cloud security tools (CSPM, CWPP) and multi‑cloud environments (Azure, OCI, AWS).
- You are experienced with Kubernetes security, endpoint, network, and web access monitoring systems.
- You hold certifications such as CISSP, CISM, CCSP, Azure Security Engineer, AWS Security Specialty, or CEH (preferred).
Ways of Working
- You demonstrate excellent communication and interpersonal skills.
- You operate with urgency, accountability, and sound judgement.
- You are structured, logical, and proactive in your approach.
- You are comfortable taking ownership of workstreams and delivering difficult messages when needed.
- You are passionate about Cyber Security and proactive in identifying and mitigating risks.