- Company Name
- TD
- Job Title
- Cloud Security Engineer (Cloud DevSecOps Engineer)
- Job Description
-
**Job Title**: Cloud Security Engineer (Cloud DevSecOps Engineer)
**Role Summary**:
Design, develop, and maintain automated compliance‑as‑code (CaC) testing frameworks for multi‑cloud environments (GCP, Azure, AWS). Integrate security validations into GitHub‑based CI/CD pipelines, ensuring continuous enforcement of banking regulatory standards (NIST, ISO 27001, SOC 2, STIG). Collaborate with policy creators, security architects, and Cloud Service Owners to deliver audit‑ready, traceable compliance evidence.
**Expectations**:
- Deliver robust, repeatable automated test suites that validate CaC policies before deployment.
- Provide clear, actionable compliance reports and dashboards; enable real‑time alerting for violations.
- Maintain high test coverage and constructive feedback loops with development and security teams.
**Key Responsibilities**:
- Build positive, negative, and edge‑case test cases for CaC policies across GCP, Azure, and AWS.
- Create and sustain a CI/CD pipeline that embeds policy checks using GitHub Actions, Terraform, and scripting.
- Develop mock cloud environments, IAM roles, and services for realistic testing scenarios.
- Coordinate with DevSecOps, security, and compliance stakeholders to define enforcement rules.
- Validate cloud resources against CIS benchmarks, NIST, ISO 27001, and SOC 2.
- Automate security scans of Terraform deployments via PowerShell and Python.
- Implement logging/monitoring with tools such as SonarQube, Wiz.IO, and Splunk for real‑time detection of violations.
- Ensure all artifacts are traceable to regulatory requirements for internal and external audits.
**Required Skills**:
- 4+ years in Cloud Security, DevSecOps, or Cloud Engineering.
- Deep knowledge of GCP, Azure, and AWS native security services.
- Proficiency in IaC (Terraform, Helm, ARM, JSON, YAML).
- Hands‑on experience with CaC tools (HashiCorp Sentinel, Azure Policy, Wiz Policy, GCP Org Policy, Open Policy Agent).
- GitHub Actions and CI/CD pipeline design; familiarity with Jenkins optional.
- Scripting: Python, Bash, Go, PowerShell; Terraform IAM automation.
- Understanding of CIS Benchmarks, NIST standards, ISO 27001, SOC 2, and STIG requirements.
- Experience with container security and Kubernetes policy enforcement (preferred).
**Required Education & Certifications**:
- Bachelor’s degree in Computer Science, Information Technology, or related field.
- Information Security certifications (e.g., CompTIA Security+, CISSP, CISM) are an asset.
- Cloud platform fundamentals or associate certifications (Azure Fundamentals, Azure Security Engineer Associate, GCP Fundamentals).