Back to Jobs
RI

Principal Cloud Security Architect – hybrid at Revel IT

Revel IT Anywhere

Job Description

Job Description

OUR GOAL: 
Treat our consultants and clients the way we would like others to treat us!Interested in joining our team? Check out the opportunity below and apply today!

The Principal Cloud Security Architect contractor is responsible for developing and leading the secure cloud computing strategy. This includes working with Infrastructure and Development groups to understand their Cloud Platform adoption plans, hosted application designs, and cloud management and monitoring methods. The principal cloud security architect will define architecture patterns and standards based on industry best practices and insights regarding application architecture and deployment in cloud environments.

Combination of onsite in Irvine, CA and remote (assume at least 2-3 days/week onsite)

Responsibilities:

  • Leads the overall cloud security architecture strategy and technical framework including standards/guidelines/procedures/requirements for infrastructure and software development.
  • Enable the business through technical leadership to influence peers across Innovation Technology and Business Leadership to design and implement cybersecurity technology and assist application and infrastructure teams secure implementation of technology.
  • Lead security assessments, identify gaps in existing security architecture, and recommend changes or improvement.
  • Lead assessment of appropriate vendor relationships related to information security tools, technology and cloud services; manage proof-of-concepts that enable the business while reducing risk; maintain currency with emerging technology; maintain security roadmap. Develop and maintain enterprise security requirements and controls that drive the selection of security tools as well as assist Business Units and IT in selecting solutions to meet their needs.
  • Create solutions that align enterprise security architecture frameworks and standards (. SABSA, NIST 800-53, ISO 27002) with overall business and security strategy.
  • Participate as the primary security subject matter expert in the Information Technology Architecture Committee (ITAC) by reviewing risks of new technology, ensuring secure integration of technology and driving a secure architecture roadmap.
  • Maintain a leadership role in the Architecture Review Committee through extensive experience in security technology and cloud architecture to drive a balanced approach to overall technical architecture. This responsibility also requires mentorship of domain architects to mature their techniques and to think beyond their specific area of responsibility.
  • Establish and manage the threat management/intelligence program (including threat modeling, assessment, hunting) to support the Security Operations Center (SOC) and integrate with the risk management functions.
  • Assist Security Operations to assess and investigate security incidents, and work with application and operations teams throughout the investigation cycle to ensure remediation, eradication and lessons learned are rolled back into daily operations.
  • Build and maintain the Secure Software Development Lifecycle (SSDLC) including the development of secure coding standards, testing services, testing infrastructure, and compliance processes.
  • Manage the development and maintenance of the data protection program including discovery, data-flow/mapping and Data Loss Prevention (DLP).
  • Help identify new exploits, threats, and mitigations for detection engineering and define and maintain domain and enterprise level threat modeling.
  • Mentor junior cybersecurity staff in cybersecurity technology, architectural methods and technical process development.

  • Education & Experience: 

  • Bachelor’s degree in computer science, engineering or related field.
  • 15+ years in information risk management and information security technology, including 5+ years in security architecture and 5+ years in a cloud environment.
  • Strong written and verbal communications skills with the ability to create and present technical recommendations to executive management as well as influence and persuade peers and others.
  • Demonstrate a deep understanding of cloud concepts and architectures with a focus for how security controls are applied to cloud-based technologies. Example cloud concepts include, but are not limited to:
  • Architecture & Networking
  • Identity & Access Management
  • Securing the CI/CD Pipeline
  • Secrets and Data Protection
  • Logging, Detection, and Response
  • Security Controls for Containers (., Docker, Kubernetes)
  • Experience managing cloud projects.
  • Deep understanding and implementation of industry-leading practices for cloud security risks using frameworks and standards such as CIS Benchmarks, Cloud Security Alliance, NIST SP 800-144, 800-145, 800-291, and 800-322.
  • Experience advising business and technical leadership on cloud architecture and design concepts based on compliance and regulatory standards (., PII, PCI-DSS, PHI, GDPR, HIPAA).
  • Demonstrated experience in designing security architectures to mitigate threats including Zero Trust, cloud environments, applications, network infrastructure and data integration/management.
  • Experience in identifying gaps in existing architectures.
  • Demonstrated experience in architecting and implementing large complex security solutions and programs (. SOC, Identity Management, SSDLC, DLP).
  • Experience in architecting security for cloud environments (IaaS, PaaS, SaaS) as well as leveraging cloud-based security solutions.
  • Hands on experience with leading strategic security technology solutions to enable business flexibility including SD-WAN, Wireless networks and IoT.
  • Experience managing multiple projects of diverse scope and effectively collaborating in a cross-functional team environment.
  • Demonstrated knowledge on how business enabling technology (. IoT, increases the threat landscape, while understanding how to apply technology and process to mitigate cyber risk.
  • Knowledge of risk management processes and experience in conducting risk assessments.
  • Demonstrated ability to develop and implement the overall cybersecurity architecture in alignment with the risk posture of the organization.
  • Ability to automate common tasks in programming/scripting language and strong knowledge of application programming interface (API) interaction methods.
  • Experience being a part of a highly technical team, including Incident Response, Security Engineering, or Forensics teams.
  • Experience as an engineer in incident response efforts. This should include hands on experience completing tasks such as malware detection and analysis, memory analysis, and disk forensics. 

  • Preferred Certifications:

  • IT security certifications (CISSP, CISM, GIAC, CEH, GCIH, GCFE, GXPN, CISSP-ISSAP, SABSA or similar) preferred.
  • Reference: 1041285

    Don’t meet every single requirement? Studies have shown that women and people of color are less likely to apply to jobs unless they meet every qualification. At Revel IT, we are dedicated to building a diverse, inclusive, and authentic workplace, so if you’re excited about this role, but your experience doesn’t align perfectly with every qualification in the description, we encourage you to apply anyway. You might be the right candidate for this or our other open roles!

    Revel IT is an Equal Opportunity Employer. Revel IT does not discriminate on the basis of race, religion, color, sex, gender identity, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status or any other basis covered by appropriate law. All employment is decided on the basis of qualifications, merit, and business need.

    #gdr4900

    Job ID:

    1041285

    Resume Suggestions

    Highlight relevant experience and skills that match the job requirements to demonstrate your qualifications.

    Quantify your achievements with specific metrics and results whenever possible to show impact.

    Emphasize your proficiency in relevant technologies and tools mentioned in the job description.

    Showcase your communication and collaboration skills through examples of successful projects and teamwork.

    Explore More Opportunities