Basic Qualifications
• 2+ years of relevant work experience and a Bachelors degree, OR 5+ years of relevant work experience
Preferred Qualifications
• 3 or more years of work experience with a Bachelor’s Degree or more than 2 years of work experience with an Advanced Degree (e.g. Masters, MBA, JD, MD)
• 5+ years of experience in cybersecurity, with hands‑on responsibility for cloud or platform security.
• Demonstrated experience securing production workloads across multiple cloud providers (AWS, Azure, and/or GCP).
• Experience operating in regulated or high‑availability environments is strongly preferred.
• Multicloud Security Expertise (Core Requirement)
Proven ability to design, review, and implement security controls across multicloud environments, including:
• Cloud Identity and Access Management (IAM), least‑privilege access, and workload identity
• Network segmentation, service‑to‑service authentication, and mTLS
• Cloud encryption models and key management (KMS, HSM, certificate authorities)
• Experience with Cloud Security Posture Management (CSPM) and misconfiguration detection.
• Understanding of cloud‑native logging, monitoring, and detection capabilities
• Infrastructure, Container & Platform Security
Hands‑on experience securing:
• Kubernetes and container platforms
• Container image scanning and runtime security
• Infrastructure‑as‑Code (Terraform, CloudFormation, ARM)
• Ability to embed security controls into CI/CD pipelines and platform guardrails.
• Familiarity with configuration‑drift detection and continuous compliance.
• Application & Data Protection
Strong understanding of:
• API security (OAuth/OIDC, token‑based auth)
• Application‑level encryption, tokenization, and hashing
• Data protection across storage, database, and file‑system layers
• Ability to support secure software development lifecycle (SSDLC) practices, including SAST, SCA, and SBOM
Risk, Compliance & Governance:
• Working knowledge of security and compliance frameworks such as PCI DSS, ISO 27001, SOC 2, GDPR, or NIST.
• Ability to translate security findings into risk‑based recommendations for engineering and leadership.
• Experience partnering with architecture, risk, and compliance teams
Tools, Technologies & Certifications (Preferred):
• Experience with cloud‑security tooling (e.g., CSPM, container security, IAM platforms).
Cloud or security certifications are preferred but not mandatory, including:
• CCSK / CCSP
• AWS, Azure, or GCP Security certifications
• CISSP or equivalent
• Continuous learning mindset aligned with evolving multicloud security practices.
• Deep Knowledge of LLM Platforms (Mandatory)
Demonstrated hands‑on and architectural knowledge of enterprise‑grade AI and LLM platforms, including:
• Anthropic Claude
• OpenAI (ChatGPT, GPT APIs, enterprise offerings)
• Comparable LLM providers and managed AI services
This includes understanding:
• Platform security models and shared‑responsibility boundaries
• API‑based consumption vs managed SaaS usage
• Enterprise controls for data handling, logging, and access enforcement