Job Summary
CTEM Cloud and Hardening Analyst responsible for supporting cloud security, exposure management, configuration hardening, and governance across multi-cloud and on-premise environments. The role sits at the intersection of cloud engineering, vulnerability management, and regulatory compliance, with responsibility for assessing security posture, mapping controls to recognized frameworks, prioritizing remediation, implementing preventive guardrails, and communicating security risks across technical and business stakeholders.
Key Responsibilities
• Operate and tune cloud security posture management platforms to continuously assess on-premise Windows and *Nix environments, as well as AWS and Azure environments, against approved configuration baselines and industry benchmarks.
• Translate regulatory and internal control requirements into enforceable configuration standards for cloud and on-premise environments.
• Maintain mappings between technical controls and recognized security frameworks, including NIST and CIS.
• Validate and risk-rank security findings using relevant business context.
• Partner with cloud platform and application teams to drive remediation activities through closure.
• Administer exception and risk-acceptance processes.
• Codify security controls as preventive guardrails and integrate security detection and validation into infrastructure-as-code and CI/CD pipelines.
• Automate recurring security assessments and evidence collection where possible.
• Provide clear reporting on control coverage, remediation SLAs, and residual risk.
• Communicate security findings and risk information to engineering teams, business operating units, security management, and senior leadership.
• Support formal audit and assessment activities from evidence gathering through issue remediation and closure.
• Contribute to continuous improvement of cloud security posture, hardening standards, automation, and governance processes.
Required Qualifications
• 10+ years of experience in Information Security, IT audit, cloud security, or a related field, with a demonstrated focus on cloud compliance and configuration risk.
• Hands-on working knowledge of at least one major cloud provider, such as AWS or Azure.
• Understanding of cloud identity and access management, network architecture, logging, encryption, and key management.
• Proven experience mapping technical security controls to recognized security frameworks.
• Experience supporting formal audit or assessment cycles, including evidence gathering, issue management, remediation, and closure.
• Experience with cloud security posture management and compliance scanning tools such as Wiz, Prisma Cloud, Microsoft Defender for Cloud, or AWS Security Hub.
• Experience with standard operating systems, including Windows and *Nix environments.
• Ability to validate, prioritize, and communicate security findings based on risk and business context.
• Strong stakeholder engagement skills, including the ability to explain technical findings and secure remediation commitments from business, technical, and executive stakeholders.
• Bachelor's degree in Computer Science, Information Security, Network Engineering, or a related technical discipline, or equivalent experience.
Preferred Qualifications
• Experience implementing security controls as preventive guardrails.
• Experience integrating security controls and assessments into infrastructure-as-code and CI/CD pipelines.
• Experience with automated security assessment and evidence collection.
• Experience working with cloud compliance, configuration risk, and exposure management programs.
Certifications
• CCSK, CCSP, CISA, CISSP, or a cloud provider security specialty certification preferred.