Define and execute the enterprise cloud security strategy aligned to corporate risk appetite and regulatory requirements
Establish cloud security reference architectures, guardrails, and design patterns
Lead cloud security governance across AWS, Azure, GCP, and strategic SaaS providers
Own cloud security policy framework and control standards (aligned to NIST)
Present cloud risk posture and roadmap to executive leadership and key stakeholders
Lead cloud security architecture for: Landing zones and platform engineering, Identity and access management (including zero trust), Network security and segmentation, Encryption and key management, Container/Kubernetes security, API security, Cloud-native application protection
Establish secure-by-design and DevSecOps integration models in collaboration with Application Security Engineering and Secure SDLC engineers
Drive an automation first infrastructure-as-code and policy-as-code strategy in partnership with Platform Engineering and Application Security Engineering
Oversee and partner w/global support partners CSPM, CWPP, CNAPP, DSPM, SSPM and related platforms
Drive critical alignment and integration w/engineering and delivery leaders supporting capabilities such as CIEM, CASB, and SSE
Partner with SOC and Cyber Defense Engineering for cloud threat detection and response integration
Oversee cloud logging, telemetry, and SIEM/SOAR integration
Partner with Cyber Defense Engineering on the creation, validation, and testing of cloud incident response engineering playbooks
Partner with Risk Management and other key stakeholders to establish vulnerability management and misconfiguration remediation pipelines
Track and reduce enterprise cloud risk metrics
Secure multi-cloud architectures across AWS, Azure, GCP
Ensure consistent controls across on-prem, private cloud, and SaaS ecosystems
Support M&A integrations and divestitures with cloud security assessments and rapid control deployment
Ensure compliance with global regulatory regimes (e.g., HIPAA, GDPR, SOX, FDA/GxP where applicable)
Enable audit readiness and continuous control monitoring
Partner with Legal and Privacy on data residency and cross-border cloud risks
Build and lead a global team of cloud security architects and engineers
Develop succession planning and technical career paths
Establish KPIs, OKRs, and performance dashboards
Enterprise financial management and planning experience
Foster collaboration with platform engineering, SRE, and DevOps teams
Requirements
Master’s Degree in Business Administration, Computer Science, Information Technology or any other related discipline or equivalent related experience
12+ years of directly-related or relevant experience
8+ years in a managerial capacity, preferably in information security
Certified Cloud Security Professional (CCSP)
Certified Information Systems Security Professional (CISSP)
Certification in Information Security Strategy Management (CISM)
Microsoft Certified: Cybersecurity Architect Expert (SC-100)
Information Technology Infrastructure Library (ITIL)
Offensive Security Certified Professional (OSCP)
Project Management Professional (PMP) Certification
IT Risk Management, IT Controls, Cyber Attack Mitigation, Enterprise IT Management, Network Security, Service Level Maintenance, Information Security Strategy, Continuity, Threat Modelling, Information Security Standards (SOX, ISO 27001/27002, COBIT, ITIL, NIST, PCI)
Tech Stack
AWS
Azure
Cloud
Cyber Security
Google Cloud Platform
Kubernetes
PMP
SDLC
Benefits
compensation, benefits, and resources that enable a highly inclusive culture
medical, dental, and vision care
comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness
support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave
a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities