- Company Name
- McCormick & Company
- Job Title
- Cloud Security Engineer (HYBRID)
- Job Description
-
Job title: Cloud Security Engineer (HYBRID)
Role Summary:
Design, implement, and manage cloud security solutions to enforce secure access across cloud environments. Act as the primary technical point of contact for security configuration, monitoring, incident response, and compliance within a global security team.
Expactations:
- Deliver robust cloud security posture through configuration, monitoring, and automation.
- Collaborate with engineering, DevOps, and service teams to embed security into deployment pipelines.
- Drive continuous improvement of tool coverage, alert management, and governance processes.
- Ensure compliance with internal standards and external regulatory requirements.
Key Responsibilities:
- Configure and fine‑tune native security tools (Cloud EDR, Security Center, SIEM).
- Monitor for misconfigurations, over‑permissioned identities, and non‑compliant resources; remediate with relevant teams.
- Apply secure baseline configurations to storage, compute, networking, and identity services.
- Enforce governance via policy, tagging, and access reviews; update NSGs, ASGs, firewalls.
- Maintain cloud security coverage, onboard new assets, and track tool effectiveness.
- Investigate and resolve alerts from EDR, SIEM, and other cloud tools; implement corrective actions.
- Identify operational and security risks; recommend mitigations.
- Automate alert filtering to reduce fatigue and improve signal-to-noise ratio.
- Support vulnerability management: flag outdated configurations, missing patches, and identity risks.
- Stay current on cloud threats and platform capabilities; propose posture enhancements.
- Participate in security projects, audits, compliance reviews, and architecture review boards.
- Provide guidance for new service rollouts and migrations to embed security from the outset.
- Evaluate and integrate CSPM, CIEM, and workload protection tools; drive governance and automation improvements.
- Maintain documentation of configurations, exceptions, and workflows for knowledge transfer.
Required Skills:
- Strong knowledge of cloud security architecture (AWS, GCP, Azure).
- Proficiency with native cloud security tools (Cloud EDR, Security Center, SIEM).
- Experience with security configuration management, policy enforcement, and identity governance.
- Ability to automate security processes and reduce alert fatigue.
- Familiarity with vulnerability management and compliance frameworks.
- Excellent troubleshooting, communication, and collaboration skills.
- Ability to work independently and as part of a global team.
Required Education & Certifications:
- Bachelor’s degree in Information Technology, Computer Science, or related field.
- 3–6 years of experience in endpoint/cloud security or security engineering.
- Valid security certifications: at minimum one of GIAC Certified, CCSK, OCSP, CISSP (or equivalent); or cloud certifications (AWS, GCP, Azure).
- Additional certifications (CEH, ITIL, RHCE, Security+, Microsoft, etc.) preferred.