Cloud Security SME
|Job Type||Permanent Full Time|
|Area||Cheshire , United Kingdom Cumbria , United Kingdom Greater Manchester , United Kingdom|
|Sector||Travel & Transport|
- The role of the Information Security Cloud Security Analyst is to act as a subject matter expert for the security requirements and capabilities of the IT foundation platforms in the cloud. This means ensuring all the components of the individual platforms and cloud hosting adhere to the security control requirements, ongoing assurance measures are in place and importantly, that specific security controls and reporting are designed and integrated in to the security platform.
The candidate must have a detailed understanding of the overall Cloud Hosting environments used by the organisation including Amazon AWS and Azure, a working knowledge of the key foundation security tools used by the organisation and ideally some additional security experience. It will be advantageous for the candidate to also have good developer and automation/scripting knowledge as the forward strategy is to utilize automation to deliver and configure Cloud IT security systems. Technical training for specific areas of IT and IT security will be available to the successful candidate.
The main accountability of this role is to support the IS Capability Manager to deliver the information security requirements and capabilities specific to cloud hosting platforms
CLOUD PLATFORM SECURITY
- Information Security technical SME and point of contact for the Cloud Security platforms.
- Ensuring that these platforms are built and operated aligned to information security control requirements as published in the organisations cloud security standards
- Seeking, defining and transitioning to cloud native information security capability opportunities within these platforms.
- Provide knowledge of the current and strategic capability of cloud hosting environments
- Provide input to the security standards framework on technology platform specifics.
ALIGNMENT AND ENGAGEMENT
- Working alongside all areas of the broader Information Security team to ensure alignment to controls, existing processes and overall strategy.
- Engagement with the Information Security programme management team to ensure effective delivery of new capabilities.
- Engagement with the Security Operations team to ensure new security capabilities are transitioned and operated effectively.
- Effective partnership with the key IT foundation platform experts.
- Engagement with internal and external project teams, including suppliers, partners and SME’s.
GOVERNANCE AND DELIVERY
- Ensure alignment to project portfolio management processes.
- Successful track record and excellent in-depth technical knowledge of one or more of the organisations cloud hosting platforms AWS/Azure
- Information Security / IT Security knowledge.
- Sound, broad knowledge of scripting, automation and coding including JSON and/or powershell
- Working in roles requiring high level of technical standards, and operating at enterprise scale
- Ability to learn and assimilate new technologies
- Excellent time management, prioritisation of tasks and quality of delivery.
- Minimum 5 years in an IT role.
- Cloud administration Certification from either of Azure/AWS
- Professional qualification in information security – e.g. CISSP, GIAC or equivalent.
- Experience within a consumer goods or retail environment preferable.
- Degree level education.