01Key Responsibilities
Lead the implementation and management of cloud security tools, with a focus on Wiz, to monitor and improve our cloud security posture.
Identify, triage, and help remediate cloud infrastructure and application vulnerabilities across multi-cloud environments.
Collaborate with DevOps and engineering teams to design secure cloud architectures and integrate security into CI/CD pipelines.
Conduct threat modeling and risk assessments for cloud-native applications and services.
Serve as an escalation point for cloud-related security incident response and forensics.
Coordinate third-party cloud security assessments and penetration tests.
Stay current on emerging cloud security threats, technologies, and best practices.
Provide guidance and training to engineering teams on secure cloud development practices.
Qualifications:
Strong understanding of cloud platforms (primarily AWS and Azure) and cloud-native security principles.
Hands-on experience with cloud security tools, especially Wiz or similar CSPM/CNAPP platforms.
Familiarity with infrastructure-as-code (IaC) security and DevSecOps practices (primarily Terraform).
Basic experience with a common scripting language (e.g. Python) for developing automations.
Experience with vulnerability management, threat modeling, and incident response in cloud environments.
Strong communication and collaboration skills to work effectively with cross-functional teams.
Relevant certifications such as AWS Certified Security Specialty, GIAC Cloud Security Automation (GCSA), or similar are a plus.
Background in application security is a plus, especially in cloud-native contexts.
#LI-SK1 .