You will be responsible for contributing to the vulnerability management programme aimed at enhancing the overall security posture of the organisation. This role involves working closely with cross-functional teams to ensure the security and compliance of cloud environments, identifying and mitigating risks, and staying current with cloud security best practices.
Monitor and triage security findings across cloud environments, coordinating with relevant stakeholders on remediation efforts.
Ensure cloud environments comply with industry standards, regulatory requirements, and organisational security policies.
Develop and implement incident response plans tailored to cloud environments.
Enforce least privilege principles and conduct regular reviews of access permissions.
Implement security automation and scripting to streamline security processes in the cloud.
Collaborate with development teams to ensure secure application design and implementation within cloud environments, focusing on vulnerability management and secure coding practices.
Stay updated on emerging threats and vulnerabilities relevant to cloud security.
Bachelor’s degree in Computer Science, Information Security, or a related field.
Strong understanding of vulnerability assessment to identify exploitability.
In-depth knowledge of cloud security principles and best practices.
Comprehension of programming languages and ability to participate in code reviews.
Experience with cloud-native security tools and services.
Excellent communication and collaboration skills with a team-oriented mindset.
Relevant certifications such as AWS Certified Security - Specialty, Certified Cloud Security Professional (CCSP), or equivalent.
Knowledge of TCP/IP stack, Load balancer, Networking.
Familiarity with the DevSecOps pipeline including relevant tools such as CSPM, CWS, SCA, SAST, and the rest.
Familiarity with security tools such as PrismaCloud and those provided by AWS.
Proficiency in scripting and automation (e.g. Python, PowerShell).
Proficiency in Terraform for infrastructure provisioning and management.
Professional experience within financial institutions or the banking sector, with a strong understanding of industry operations and strategic insights.