The Team
Cloud Engineering supports the firm by delivering modern platform capabilities, observability services, and engineering enablement across distributed systems. The Platform Security team safeguards cloud platforms by implementing securebydefault patterns, enforcing guardrails, and supporting threat detection, response, and continuous security improvement across digital services.
Technical Leadership
- Provide guidance to engineers on secure cloud configurations, secret management, identity governance, and platform guardrails.
- Lead security onboarding for new services, ensuring alignment with securebydefault patterns.
Policy, Governance & Access Control
- Develop and refine security policies, baseline configurations, and platform governance controls.
- Manage and review access control models including RBAC, privileged access, automation identities, and workload identities.
- Oversee automated policy checks and compliance monitoring.
DevSecOps & SDLC Security
- Embed security scanning, image validation, dependency checks, IaC scanning, and code signing into CI/CD workflows.
- Create reusable DevSecOps templates for teams to adopt (pipeline templates, scanning configs, signing steps).
IaC Review & Secure Architecture
- Lead reviews of Terraform modules to ensure secure configurations and alignment with guardrails.
- Contribute to secure architecture patterns for networking, identity, and workload isolation.
Threat Detection, IR & Automation
- Enhance detections, rule sets, and response playbooks for cloud threat intelligence signals.
- Participate in incident response activities, supporting containment and root cause analysis.
- Build automation to support access reviews, remediation workflows, and compliance reporting.
Stakeholder Engagement & Enablement
- Work closely with product, observability, SRE, and platform engineering teams to embed security early in design.
- Deliver training, guidance, and bestpractice documentation.
- Manage relationships with stakeholders to become a trusted partner.
- Lead by example by living by Our Values and embracing our culture
Shift Responsibilities & Operational Support
- Work in rotational shifts as required.
- Participate in oncall rotations to respond to and resolve highseverity incidents in a timely manner.
The Person
Strong handson experience in cloud security engineering and DevSecOps.
- Skilled in IaC assessment, policyascode, scanning tools, and secure architecture.
- Extensive knowledge of CI/CD pipelining skills using Azure DevOps or equivalent.
- Proficient in scripting/automation languages (PowerShell, Python, Bash).
- Familiar with threat detection, cloud forensics, and incident response processes.
- Effective communicator able to influence engineering teams to adopt securebydefault practices.
- Strong sense of ownership and problemsolving abilities and commitment to raising engineering standards.