Senior Cloud Security Engineer
Join BNY’s Cloud Security team to lead implementation of security controls across cloud platforms and cloud‑native services, support Cloud Security Strategy and Governance, and advance secure cloud capabilities through technical leadership, posture management, and partnership with engineering, architecture, DevSecOps, IAM, and cyber teams.
Responsibilities
- Lead engineering, implementation, and continuous improvement of cloud security controls for identity and access management, network security, encryption, key management, secrets management, logging, monitoring, and workload protection in AWS, Azure, or GCP.
- Act as an AI enabler for cloud security by identifying, assessing, and promoting AI use cases that improve security outcomes.
- Support adoption of AI‑driven capabilities for threat detection, risk analysis, automation, incident response, and security operations.
- Translate security and control requirements into repeatable engineering solutions and implementation standards.
- Support design and implementation of technical controls aligned to NIST SP 800‑53 and related enterprise security requirements.
- Lead implementation efforts for container, Kubernetes, API, and cloud‑native workload security controls.
- Drive operational maturity of Cloud Security Posture Management (CSPM) to identify misconfigurations, policy violations, excessive permissions, exposed assets, and control drift.
- Partner with engineering and cyber teams to optimize Wiz and similar CSPM/CNAPP platforms, including workflow integration, prioritization, remediation support, and reporting.
- Design and strengthen the use of cloud‑native posture and policy services (AWS Config, AWS Security Hub, AWS Organizations SCPs, Azure Policy, Microsoft Defender for Cloud, GCP Organization Policy, Security Command Center).
- Define and implement policy‑as‑code, automated guardrails, and infrastructure‑as‑code patterns to improve control consistency and reduce manual processes.
- Provide senior technical guidance to cloud engineers, DevSecOps practitioners, and application teams on secure cloud implementation practices.
- Partner with governance stakeholders to improve standards adoption, exception handling, and control coverage.
- Help define cloud security metrics, remediation priorities, and technical reporting that support governance and risk management objectives.
- Contribute to audit, regulatory, and control review activities by explaining technical implementations, evidence, and remediation status.
- Maintain and improve documentation for cloud security standards, design patterns, engineering procedures, and operating guidance.
Qualifications
- 6‑10 years of experience in cloud security engineering, security engineering, DevSecOps, infrastructure security, or a related role.
- Strong hands‑on experience securing workloads and services in AWS, Azure, or GCP.
- Deep knowledge of cloud security principles across IAM, networking, encryption, secrets management, logging, and workload protection.
- Experience in security automation, orchestration, analytics, and AI‑driven security tooling.
- Experience implementing cloud security controls at scale in enterprise or regulated environments.
- Familiarity with NIST SP 800‑53, MCSB, and related control concepts.
- Strong understanding of CSPM concepts, continuous compliance monitoring, misconfiguration detection, exposure analysis, and governance workflows.
- Experience with CSPM/CNAPP tools such as Wiz, Prisma Cloud, Orca, Lacework, or similar.
- Experience with cloud‑native policy and posture tools (AWS Config, AWS Security Hub, AWS Organizations SCPs, Azure Policy, Microsoft Defender for Cloud, GCP Organization Policy, Google Security Command Center).
- Experience developing or supporting policy‑as‑code and automated guardrails using OPA/Rego or equivalent frameworks.
- Strong experience with Infrastructure as Code and automation using Terraform, CloudFormation, ARM, Bicep, Python, or similar.
- Experience with container and Kubernetes security, API security, vulnerability management, and cloud‑native control implementation.
- Experience contributing to cloud security strategy, governance processes, standards, exception handling, remediation tracking, and risk reporting.
- Strong technical judgment, problem‑solving ability, and cross‑functional collaboration skills.
- Strong written and verbal communication skills, including explaining technical controls in business and risk terms.
- Bachelor’s degree in computer science, engineering, cybersecurity, or related discipline, or equivalent practical experience.
- Experience in a regulated industry such as financial services.
- Familiarity with CIS Benchmarks, CSA CCM, OWASP, or NIST CSF.
- Relevant certifications such as AWS Security Specialty, Azure Security Engineer Associate, Google Professional Cloud Security Engineer, or CCSP.
Preferred Qualifications
- Experience supporting or leading cloud security strategy and governance initiatives.
- Track record of balancing security, resilience, cost, and engineering usability in decision making.
- Exposure to architecture review, risk assessments, or cloud governance processes.
- Experience with AI and ML technologies and their application in cybersecurity.
What Success Looks Like
- Cloud security controls implemented consistently, effectively, and at scale.
- AI integrated into all processes and controls to increase effectiveness and streamline operations.
- Security embedded into engineering and deployment workflows with reduced manual effort.
- Posture management findings better prioritized, actionable, and effectively remediated.
- Wiz, cloud‑native policies, and automation drive visibility and reduce cloud risk.
- Deployments align with NIST SP 800‑53 and enterprise standards.
- Engineering teams adopt secure patterns more consistently with fewer exceptions.
- Governance and audit stakeholders receive clearer technical evidence and remediation transparency.
Benefits and EEO Statement
BNY offers competitive compensation and a comprehensive benefits package including health, dental, vision, retirement, paid leave, volunteer time, and more. BNY is an Equal Employment Opportunity/Affirmative Action Employer and encourages applicants from underrepresented groups.
#J-18808-LjbffrSenior Vice President, Senior Cloud Security Engineer in new york at Unknown Company
This position is listed as full time and onsite.