About this role
[What the role is] We are seeking a highly skilled and motivated Cloud Security Specialist to join our dynamic team and play a pivotal role in ensuring the security, integrity, and compliance of our cloud-based systems and applications. As a Cloud Security Specialist, you will work collaboratively with cross-functional teams to design, implement, and maintain robust security measures that protect our organisation's assets and data in cloud environments. [What you will be working on]
• Strategic Cloud Security Management:
• Review, update, and enforce cloud security policies and architecture designs to align with current threat landscape, regulatory requirements, and industry best practices.
• Identify current security gaps present in the cloud environments. Conduct studies on appropriate mitigation measures and/or evaluation of third-party solutions to propose for implementation.
• Cloud Security Operations & Response:
• Design and implement cloud infrastructure to support new implementations.
• Maintain Infrastructure-as-Code solutions using tools such as Terraform or CloudFormation. Perform configuration changes to comply to new policies introduced.
• Build and maintain automation scripts and tools to streamline security processes such as provisioning, configuration management, and incident response.
• Support audit and compliance activities by maintaining evidence of security controls, conducting security assessments, and preparing detailed compliance reports.
• Monitor and respond to security incidents, assist with investigations, and implement remediation measures.
• Perform patching promptly according to remediation timelines.
• Perform regular monitoring and communicate with stakeholders to remediate or mitigate cloud related findings from dashboards and alerts.
• Analyse security metrics and trends to create reports for management reporting.
[What we are looking for]
• Have experience (2+ years) in designing, implementing, and managing security solutions in cloud environments (AWS, Azure, Google Cloud, etc.).
• Understand cloud security principles, including network security, encryption, identity and access management, and security monitoring.
• Have implemented security best practices within Infrastructure-as-Code frameworks (e.g. Terraform, CloudFormation, Ansible) to ensure secure infrastructure provisioning and configuration management.
Good to Have:
• Relevant professional certifications such as Certified Cloud Security Professional (CCSP), Certified Information Systems Security Professional (CISSP), AWS Certified Security – Specialty, or equivalent.
• Proficiency in scripting or programming languages (e.g., Python, PowerShell) for security automation and orchestration.
• Experience in using containerisation technologies, such as Docker, Kubernetes, AWS ECS, and knowledge in securing containers.
• Proficiency in implementing DevSecOps and CI/CD pipelines, with experience in relevant CI technologies such as Git, Gitlab, and Jenkins. Hands-on experience with security testing tools (e.g., SAST, DAST, SCA) and vulnerability management.