Cloud Security Operations (Cloud SecOps) Analyst in Fort Lauderdale, FL

$100K - $150K(Ladders Estimates)

Citigroup Inc   •  

Fort Lauderdale, FL 33301

Industry: Finance & Insurance

  •  

5 - 7 years

Posted 34 days ago

  • Citi Technology Infrastructure (CTI) provides the products and services that enable Citi's workforce along with the majority of the financial solutions that Citi's customers rely on. We provide the critical technical foundation for Citi's operations through the infrastructure that runs business and general user computing services. We do this by working as one-team to deliver high quality reliable and modern infrastructure technologies at the right cost. We drive to optimize the functionality and capability of the infrastructure technologies.
  • About the Position:
  • The Cloud Security Operations analyst works in a multi-disciplinary team of teams driving cyber security operational services and solutions to enable Citi to securely adopt private, hybrid, and public Cloud platforms. This role is one of the primary security interfaces with development teams, architects, engineers, and operational teams involved in Cloud-related projects. Our operating model emphasizes DevSecOps, that is, automation, integration, and agility based on Security as a Service / Security as Code concepts.
  • Day-to-Day Responsibilities:
  • Develop/Deploy/Support Application & Infrastructure security checks and guardrails throughout the lifecycle (pre-commit, commit, build-time acceptance, Prod/Post-production)
  • Design and implement technology solutions to assess, monitor, and enforce security requirements across all Cloud environments
  • Administration and management of cloud security tools and third-party Security as a Service solutions
  • Ensure end to end effectiveness of cyber security controls
  • Operation of threat and vulnerability management processes
  • Conduct security assessments and articulate identified security issues/vulnerabilities to technical and non-technical audience
  • Identify, research, and validate known and unknown vulnerabilities on Cloud environments/infrastructure
  • Work closely with the defensive teams to identify gaps, address findings, and improve breach response in Cloud environments
  • Provide security consulting services to internal users, within and outside of the CTI organization
  • Technical Skills:
  • Candidates should have knowledge of the tools and processes to provide operational security support to our Cloud ecosystem. Pre-requisites for this position are at least a Bachelor's Degree with 6-10 years of experience on most of the following areas:

  • Hands-on experience with Cloud platforms (AWS, GCP, Azure, etc.)
  • Excellent understanding of Cloud security concepts/best practices in various Cloud Service Providers (for example: AWS GCP Azure)
  • Hands-on experience with cloud security tools and Security as a Service solutions (Evident.io, Redlock, Dome9, SiftSecurity, etc.)
  • Familiarity with automation frameworks (Ansible, Terraform, Chef, Salt, Puppet, etc.)
  • Familiarity with securing containers and container orchestration frameworks
  • Fluent in one or more programming/scripting languages (Python preferred, but not required)
  • Offensive Security-oriented mindset (threat-modeling, vulnerability assessments, pen testing, etc.)
  • Industry-accredited certifications will be required. Candidates with Cloud security certifications (ex: AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, Azure Security Engineer Associate, etc.), non-security Cloud certifications (AWS SysOp Admin, AWS Solutions Architect Associate/professional, GCP Associate Cloud Engineer, GCP Professional Cloud Architect, etc.) and other security certifications (for example: OSCP,OSCE, GXPN,GPEN, GCIH, GWAPT, etc.) will be preferred. Candidates without certification must be willing to purse them during the course of employment.


Valid Through: 2019-10-11