* MUST currently be working for a consulting firm. Candidates coming directly from industry/product companies will not be considered*
Position Overview
We are seeking a Senior Associate to support enterprise and cloud security initiatives across complex client environments. This position will focus on strengthening cloud security architecture, implementing security controls, improving governance, and helping organizations manage risk across modern cloud and technology environments.
The ideal candidate will have strong hands-on experience across cloud security, DevSecOps, infrastructure security, identity and access management, container security, security monitoring, and automation. You will work across AWS, Azure, and/or Google Cloud environments and help design and implement secure solutions across IaaS, PaaS, and SaaS platforms.
This role also involves working directly with stakeholders, assessing security risks, developing practical solutions, mentoring less experienced team members, and helping organizations improve their overall security posture.
Key Responsibilities
- Lead the design and implementation of cloud security strategies across AWS, Azure, and/or GCP environments.
- Design and implement security controls, governance frameworks, and compliance requirements across private, hybrid, and multi-cloud environments.
- Conduct hands-on cloud and application security assessments, identifying vulnerabilities, misconfigurations, access risks, and other security gaps.
- Build and secure cloud infrastructure, landing zones, networking, IAM, and infrastructure-as-code using tools such as Terraform.
- Embed security into DevSecOps and CI/CD pipelines, including automated code, container, IaC, secrets, and dependency scanning.
- Implement and manage cloud security posture management, monitoring, logging, SIEM/SOAR, and automated remediation capabilities.
- Secure containers, Kubernetes environments, workloads, and software supply chains.
- Develop security automation using Python, Bash, and/or PowerShell.
- Implement security controls for data, AI/ML platforms, and cloud-native applications.
- Support Microsoft 365 and endpoint security initiatives, including Defender and Intune.
- Provide technical guidance to development, engineering, and operations teams on cloud security and secure development practices.
- Lead technical discussions with clients and stakeholders, communicate security risks, and recommend practical solutions.
- Mentor junior team members and contribute to the development of cloud security capabilities.
Required Qualifications
- Bachelor's degree in a relevant technical discipline.
- At least 3 years of professional experience in cybersecurity, cloud security, information security, or a closely related field.
- Hands-on experience working with cloud security technologies and enterprise security environments.
Preferred Education
A master's degree in one of the following areas is preferred:
- Computer Programming
- Computer Science
- Computer and Information Science
- Cybersecurity
- Information Technology
- Information Security
- Management Information Systems
Preferred Technical Experience
Candidates should demonstrate strong experience in several of the following areas:
- AWS, Microsoft Azure, and/or Google Cloud Platform
- Cloud security architecture and security controls
- NIST, ISO 27001, CIS Benchmarks, and CSA CCM
- Cloud governance and compliance
- IAM, RBAC, privileged access, and least-privilege models
- Cloud networking and segmentation
- Encryption, key management, data classification, and DLP
- SIEM and SOAR technologies
- CSPM platforms and cloud security posture management
- DevSecOps and secure software delivery
- Terraform and infrastructure-as-code
- CI/CD security
- SAST, DAST, secrets scanning, dependency scanning, and container scanning
- Docker and Kubernetes
- EKS, AKS, and GKE
- Jenkins and GitHub Actions
- Linux and Windows administration
- Python, Bash, and/or PowerShell
- Microsoft 365 security
- Microsoft Defender and Secure Score
- AI/ML platform security
- AI-enabled security automation and LLM integrations
Leadership and Communication
The successful candidate will be comfortable working through ambiguous and technically complex situations, asking the right questions, and developing practical solutions. Strong communication skills are required, along with the ability to explain technical security concepts to both technical and non-technical stakeholders.
The position requires someone who can understand broader business objectives, connect security initiatives to organizational priorities, interpret technical and security data, and provide actionable recommendations.