Key Responsibilities:
Cloud Security Governance & Compliance
- Implement Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) best practices across cloud environments.
- Hands‑on experience with Akamai security solutions including WAF, Kona Site Defender, Prolexic, Bot Manager.
- Ensure full adherence to BSP regulations, ISO 27001, NIST, GDPR, PCI‑DSS, and internal policies.
- Participate in internal/external audits and provide required evidence and reporting on cloud controls.
- Support continuous compliance monitoring, including reporting on deviations, risks, and remediation activities.
Data Security & Protection
- Implement encryption standards for data at rest and in transit following UnionBank’s mandated controls.
- Enforce role‑based access control (RBAC), MFA, and identity governance across all cloud services.
- Deploy and manage Data Loss Prevention (DLP) controls and monitor for unauthorized access or data movement.
- Ensure compliance with data residency, data classification, and cross‑border transfer requirements.
Cloud Security Operations
- Integrate cloud logs with SIEM for threat monitoring, detection, and incident response.
- Monitor and harden cloud workloads, configurations, and network security controls.
- Support vulnerability management for cloud assets, ensuring remediation within defined timelines.
- Assist SOC teams in cloud‑related incident investigations and impact assessment.
Access Control & Identity Management
- Manage and enforce least‑privilege access, privileged access management (PAM), and MFA for cloud resources.
- Perform periodic user access reviews and recertification.
Cloud Compliance Reporting & Documentation
- Produce regular reports on cloud compliance, security posture, and audit readiness.
- Maintain documentation on cloud policies, technical controls, configurations, and security assessments.
Technical Skills
- Strong knowledge of CSPM, CWPP, cloud security frameworks, and best practices.
- Hands‑on experience with AWS, Azure, and hybrid cloud environments.
- Understanding of SIEM, EDR, DLP, IAM, PAM, encryption, logging, and security automation.
Certificates:
- Cloud Security Certifications:
- CCSP
- AWS Security Specialty
- Azure Security Engineer (AZ‑500)
Professional Experience:
- 3–7 years of experience in cloud security, compliance, cybersecurity, or IT risk management.
- Experience in regulated industries (preferably banking/financial services).