Location: Washington, DC
Responsible for providing highly advanced technical and analytical skills to the Technology Risk/Information Security Office. Under the supervision of the lead Director Security Technology Team, the incumbent will assist in the collection of requirements and contribute Subject Matter Expertise (SME) advice in the areas of Cloud security architectures, designs, policies, and control standards with a special emphasis on cyber security. Works with project teams to ensure technical quality of cloud security focused deliverables and adherence to security standards, governance and controls practices. Incumbent should be considered a security and technical expert in cloud security technology, architecture, designs, systems implementation and integration.
Responsibilities:
- Provides Cloud Security SME advice and guidance related to all company activities including Information as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) initiatives, projects, plans, and reviews.
- Works cross functionally to evolve cloud based products while adhering to Information Security Policies and Control Standards
- Assists project teams during system design and project lifecycle to: define time tables and project plans, including milestone definitions and progress tracking; draft logical architectural and design models with a focus on cloud security; Consult with application development teams to determine cloud security requirements and for planning and delivering cloud based business solutions; promote the efficient deployment of IT assets to cloud environments in a secure and policy compliant manner, ensure compliance with security policies, guidelines, standards, controls, and governance
- Participates in working groups of subject matter experts for definition and review of security standards, guidelines, principles, governance and controls
- Actively contributes SME advice to members, cross-functional application development teams, various councils and committees and architecture roundtable meetings
- Works closely with Chief Information Security Architect to ensure a shared vision across the organization for cloud architecture and security
- Contributes to overall strategy and cloud development by designing, developing, and implementing new cloud security technologies as necessary.
- Defines, publishes and maintains processes for security governance (i.e. compliance to principles, guidelines and standards)
- Coordinates the monitoring of the life cycle of specific cloud security assets
- Identifies, understands and documents extensions to, and variants from, cloud security and architecture standards
- Mitigates risk by following established procedures, spotting key errors and demonstrating strong ethical behavior.
Qualifications:
- Deep knowledge and experience of cloud computing infrastructure, application development methodologies, best practices, and available and emergent services in several cloud provider environments including Amazon Web Services (AWS) and Microsoft Azure.
- Minimum of 10 years of related experience.
- Bachelor’s degree preferred with Masters or equivalent experience.