Lead Cloud and Application Security Engineer / REMOTE
Motion Recruitment - philadelphia, PA
Apply NowJob Description
Position: Lead Cloud and Application Security EngineerLocation: Open for RemoteTerm: Full timeWe are seeking a proactive and collaborative Lead Cloud and Application Security Engineer to integrate security measures into every phase of our cloud and application development lifecycle. The ideal candidate will champion security best practices and foster a culture of security awareness within the organization. Responsibilities include developing automated security solutions to enhance efficiency and response capabilities, designing and managing security protocols for cloud infrastructure, and enforcing security guidelines for Infrastructure as Code (IaC). The role requires securing containerized environments, partnering with DevOps for CICD pipeline security, and leading security initiatives alongside the Senior Application Security Engineer. The Senior Cloud and Application Security Engineer will also maintain application security standards, stay updated on emerging security threats, and proactively investigate potential risks. An action-oriented mindset and strong relationship-building skills are essential to drive information security forward effectively.Essential Functions:Collaborate with IT, development, and operations teams to embed security into every aspect of the cloud and application security lifecycleAdvocate for security best practices, raising awareness and driving a security-first culture across the organizationDevelop and implement automated security solutions to streamline security processes, improve efficiency, and enhance response capabilitiesCollaborate with architecture and IT to design, implement, and manage security measures for our cloud environmentsDevelop and enforce security best practices for Infrastructure as Code (IaC) to ensure secure deployment and configuration managementSecure containerized environments, including Docker and Kubernetes, and ensure compliance with security benchmarksPartner with DevOps teams to integrate security into the CICD pipeline for container deployment and managementAlong with the Senior Application Security Engineer, lead application security initiatives, including secure code reviews, vulnerability assessments, and web application penetration testingDevelop and maintain application security standards and guidelines, ensuring they are integrated into the software development lifecycleStay abreast of the latest security threats, trends, and technologies, especially in cloud, IaC, and container environmentsProactively identify and investigate security threats by analyzing security logs, conducting threat hunting exercises, and implementing advanced detection mechanismsContinuously evaluate and improve security tools and processes to address evolving securityBe action oriented, demonstrating high energy and an action-oriented approach to challenging work tasks, with a willingness to act swiftly and with minimal planning when opportunities arise.Build strong peer relationships by finding common ground and fostering problem-solving for mutual benefit, advocating for information security interests while remaining equitable to other groups, promoting teamwork and cooperation, and maintaining open and honest communication with colleagues.EducationExperienceSkills:Bachelor's degree in computer scienceEngineeringInformation Security preferred.Minimum of 7 years' experience in Information Security within cloud-native or SaaS technology environmentsProficiency in cloud platforms such as AWS, Azure, and GCP, container orchestration tools (Kubernetes, Docker), and Infrastructure as Code (Terraform, Ansible)Experience in application security practices and tools, including staticdynamic analysis and familiarity with OWASP standardsStrong analytical, problem-solving, and communication skillsAbility to work collaboratively in a dynamic environment3-5 years of hands-on experience securing Infrastructure as Code, Application Security, and Policy as Code (PaC) using coding languages such as Python, Go, JavaScript, or YAMLMinimum two years of experience automating and scaling CIS benchmarks or equivalent standardsExtensive experience writing technical and business-friendly security documentationStrong written and verbal communication skills in EnglishProfessional certifications such as Certified Information Systems Security Professional (CISSP) or Certified Cloud Security Professional (CCSP) are highly desirable
Created: 2024-11-09