- Company Name
- UL Solutions
- Job Title
- Cloud Security Engineer
- Job Description
-
Job title: Cloud Security Engineer
Role Summary: Design, implement, and maintain secure cloud and application architectures across Azure, AWS, and GCP. Lead DevSecOps integration, threat modeling, and compliance mapping to frameworks such as NIST 800‑53, SOC 2, and CIS Controls.
Expectations: Remote working across the U.S. with optional on‑site presence 3 days a week. Operate independently while collaborating with IAM, SOC, GRC, and development teams. Deliver secure code reviews, CI/CD pipeline hardening, and remediation guidance.
Key Responsibilities:
- Architect and enforce security controls for multi‑cloud environments (hub‑and‑spoke, Zero Trust).
- Integrate cloud security tools (Wiz, Microsoft Defender for Cloud, Silverfort) and IaC (Terraform, Bicep).
- Conduct threat modeling, risk assessments, and vulnerability scans for cloud‑native services.
- Perform secure code reviews, static/dynamic analysis, and OWASP Top 10 compliance.
- Embed security into CI/CD pipelines using Snyk, Checkmarx, Veracode.
- Design API security (OAuth2, OpenID Connect, mTLS) and support incident response.
- Map controls to NIST 800‑53, SOC 2, CIS; assist audits and evidence collection.
- Maintain documentation of architecture, policies, and procedures.
Required Skills:
- 3–4 years cloud security engineering and application security experience.
- Deep knowledge of Azure security services, IAM, Azure AD Conditional Access, MFA.
- Proficiency with Terraform, Bicep, and IaC practices.
- Familiarity with Snowflake security features and data protection strategies.
- Experience with DevSecOps tools, automation, and orchestration.
- Strong analytical, problem‑solving, communication, and collaboration abilities.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Cybersecurity, or related field.
- Preferred certifications: Azure Security Engineer Associate, CISSP, CCSP, OSCP, or GIAC.
- Experience in multi‑subscription Azure environments and Zero Trust architecture.