This candidate will be responsible for developing and enforcing secure cloud deployment practices for ReliaQuest's GreyMatter platform. Working as an integral part of the Product Security team, this candidate will coordinate cloud and DevOps application security initiatives and auditing activities across multiple departments to include Product, Development, DevOps, and Infrastructure teams. In addition, the candidate will collaborate to develop and/or implement both third party and “native” cloud security controls, vulnerability management, IAM configurations, and guidelines appropriate to the security requirements. The candidate will provide best practice security guidance on cloud practices, monitor and report on vulnerabilities, and assist in developing security automations to reduce cloud and container related risks.
The everyday hustle
Enhance the coverage and capability of our suite of Cloud Security and DevOps products in AWS
Triage security vulnerabilities and collaborate with Product team to prioritize and remediate findings
Assists in the development of automated security control implementations and mitigations
Assists in the development of Kubernetes and CI/CD security standards
Champions secure SDLC process and communicates process to enterprise via tooling and training
Provides guidance on cloud security solutions and best practices to stakeholders
Proposes new cloud security tools and frameworks
Reports on and aids the product security program with senior management across the enterprise
Do you have what it takes
B.S. or M.S. in Computer Science or related field, or equivalent experience
Experience with Cloud Security, DevSecOps, or Product Security
Breadth of technical experience in IAM and Kubernetes security in large production environments
Proven technical understanding and expertise of AWS security services, CSPM/CWPP tooling, Hashicorp Vault, and Kubernetes security policies
Experience with source code repositories, CI/CD pipelines, and associated security tooling (e.g., GitHub, GitLab, etc).
Experience with container orchestration
What makes you uncommon
Experience with Java Spring applications preferred
Experience securing endpoint agents and cloud SIEMs preferred
Experience in container vulnerability management preferred
Relevant Red Team/Penetration Testing certifications preferred
Experience with AWS, Kubernetes, GitLab, and Spring Boot preferred