Cloud Security Specialist

Overview

On Site
$170,000 - $190,000
Full Time

Skills

google cloud
azure
cloud security

Job Details

This role is part of the Cloud Center of Excellence (CCoE). The CCoE is a global Agile Release Train, with presence in the Netherlands, US and East-Europe. The vision is to provide a flexible and reliable cloud platform to enable accelerated and sustainable adoption of cloud across organization, and maximizing the ability to realize its benefits, while reducing risks. In this role you will work closely together with Products Owners, Cloud & Security Architects and Cloud Engineers to help build secure and robust enterprise-grade cloud platforms.
The CCoE US Team is responsible for cloud onboarding and solutioning to guide other DevOps teams in their onboarding journey to cloud, which includes aspects around architecture, cost management and security. During the cloud onboarding process there are steps that demand a Security Expert to evaluate and approve the design/solution to ensure that all workloads are fully compliant when they move to production.
When workloads are in run , the CCoE US Team monitors security vulnerabilities and address those to Workload DevOps teams, ensuring that the given recommendations are actionable and get prioritized. Operational requests related to, or with a possible impact on our security posture, are also in scope of this role. There are topics that are extremely relevant for the US region, like export control, Engineering Top Secrets in Cloud and Generative AI in Cloud. These topics demand security expertise from CCoE; we help ensure workload teams are compliant and have all cloud security requirements in place. As these topics are relatively new, a dedicated Security Architect is paramount in the US Region, ensuring we stay ahead of all requirements.

The Cloud Security Specialist will be responsible for the protection of information, Intellectual Property (IP) and assets, and that of ASML s customers and suppliers developed and used within organizations Public cloud (IaaS, PaaS), through the set-up and/or alignment of Information Security strategies
and security standards/ guidelines while interfacing with the Business, and enforcing system, application and access security controls within the cloud. This position will continuously assess and report upon the effectiveness of the security controls of the cloud at people, process and technology level.

Duties and Responsibilities

  • Serve as the single point of contact for security subjects within the Cloud Center of Excellence (CCoE) US Team.
  • Be a linking pin between CCoE US and regional security & risk.
  • Be the extension and contact person of the CCoE security team (mostly based in Netherlands) for the US region
  • Support in updating and maintaining the Cloud Security Framework.
  • Develop, design and maintain Cloud security standards, guidelines and procedures to assure effective secured Cloud services and data protection within the IaaS / PaaS domain.
  • Regularly assess Cloud workloads (people, process, technology) on security compliance and report upon findings, conclusions and propose risk reducing measures within the CCoE workload process and during the lifetime of cloud workloads.
  • Assess and support mitigation of the risks associated to organization s public cloud to assure a
continuously adequate level of security.
  • Build excellent working relationships within organization s CCoE members and all cloud service users,
including security officers and developers of new cloud services.
  • Support organization Security Incident Response Team (SIRT) activities with response on any major IT
security incidents related to organization s IAAS / PAAS domain.
  • Provide cyber security expertise in the analysis, assessment, development, and evaluation of security solutions and architectures to secure applications, operating systems, databases, and networks.
  • Hybrid role: 3 days per week in office (San Jose), 2 days per week remote, but with a flexible mindset & willing to be present more if deadlines, events, or customer facing meetings require it.
  • Other duties as assigned.

Education and Experience

  • Bachelor s/master s degree in IT, Business Management, Computer Science or Electronics.
  • Must have 8+ years of experience as an IT Security professional in:
  • Cloud security (IaaS/PaaS) governance and defining and maintaining Cloud Security Framework (Policies, Standards, processes, templates).
  • Conducting Security Assessments (reactive) and Security Risk Assessments (proactive) within a Cloud environment.
  • Scrum/Scaled Agile Framework experience
  • Understand agile and DevOps concepts in a security context such as trust but verify , central vs decentral controls, make agile teams as autonomous as possible while ensuring the teams adhere to the Non-Functional-Requirements.
  • Translating the output of security (risk) assessment into security baseline/corrective actions and proposals for the Cloud services
  • Communicating with stakeholders, users and senior management
  • Experience with Microsoft Azure and/or Google Cloud Platform is a pre.
  • Work experience from large, international companies and have dealt with or worked for global service providers.

Skills

  • Clear passion for cloud security, cloud technologies, SecDevOps and Artificial Intelligence.
  • Hands-on and can-do mentality.
  • Able to operate independently and show ownership.
  • Ability to interact with all levels including engineers, executives and senior managers.
  • Deep technical knowledge of Information Security and Cloud technology.
  • Ability to overcome organizational resistance.
  • Excellent organizational skills and the ability to prioritize multiple tasks, projects and assignments.
  • Strong communication skills, willingness to work across time zones
  • Analytical, precise, tenacious, autonomous.

Other Information

  • This position is located on-site in San Jose, CA . It requires onsite presence to attend in-person work-related events, trainings and meetings and to further ensure teamwork, collaboration and innovation.
  • A flexible workplace arrangement may be available to employees working in roles conducive to remote work (up to two days a week).
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.