- Maintain and monitor security practices and systems within the Firm's cloud environments
- Proactively identify and mitigate cyber threats to minimize architectural and operational risk
- Develop and maintain a comprehensive security architecture framework aligned with enterprise architecture strategy and organizational objectives
- Architect, design, prioritize, coordinate, and communicate cloud security technologies
- Develop and implement architectural reference patterns for technology systems
- Perform and participate in risk and security assessments
- Enhance the security solutions lifecycle, including evaluation, purchase, build, policy configuration, integration, and operation
- Develop incident-handling strategies and coordinate responses to security breaches
- Recommend and coordinate identity and access management controls for cloud services
- Provide security guidance throughout the system development life cycle, including architectural reviews
- Contribute to security technology solutions for complex environments and architectures
- Analyze business impact and exposure from emerging threats, vulnerabilities, and risks
- Ensure cloud-based systems meet industry security standards and regulatory requirements
- Conduct cloud security solutions R&D to evaluate emerging tools and address strategic security capabilities
- Act as a subject matter expert on existing security controls
- Provide direction and thought leadership on access control, encryption, host security, cloud computing, mobile computing, and next-generation architecture
- Identify, design, review, and collaborate on deployment of new security technology solutions
- Monitor developments in security technologies, threats, tools, attack vectors, and preventative measures
- Collaborate with technology architects and engineers to integrate security into technology domains and project planning
- Communicate security architecture roadmaps and directions to stakeholders
- Provide cloud security training and guidance to Technology staff and employees
- Participate in a 7x24 on-call rotation
- Perform other assigned or required duties
- Provide customer service excellence as part of Cooley Technology, a service organization
Requirements
- After orientation at Cooley LLP, exhibit proficiency in the Microsoft Office suite, iManage and other firm applications
- Ability to work extended and/or weekend hours, as required
- Ability to travel, as required
- 3+ years direct applicable experience, such as cloud architecture security
- Extensive knowledge and experience configuring security controls and securely migrating enterprise applications to major cloud providers such as Azure and AWS
- Extensive knowledge and experience developing Cloud Security Frameworks using industry best practices such as Cloud Security Alliance (CSA) and NIST CSF
- Experience implementing cloud security tools and architecture, including access controls, DLP, WAF, Secure SDLC and Software Security, firewalls, anti-malware and anomaly detection controls, encryption, network security, and monitoring
- Experience with formal requirements definition
- Preferred: Bachelor's degree in information technology or computer information systems
- Knowledge of MITRE ATT&CK and NIST Cyber Security Framework
- Familiarity with enterprise security controls such as Firewall, Proxy, AV, and SIEM
- Experience with incident response procedures
- Extensive knowledge of security issues, techniques, and implications across multiple computer platforms
- Experience leading and developing others through technical guidance and leadership to project teams
- Knowledge of ISO 27000 family of standards
- Knowledge of systems development life cycle (SDLC)
- Experience translating business requirements into architectural deliverables and technical specifications
- Experience communicating technical information to business clients and less experienced technologists
- CISSP, CISM or equivalent preferred
- Experience with CI/CD pipelines
- Cloud Architecture and/or Cloud Security Certifications (AWS, Azure, GCP) preferred
- Cloud Security Alliance certifications, including CCSP or CCSK, preferred
- Additional security certifications preferred
- Exceptional customer service, analytical, problem-solving, project management, communication, organizational, active listening, and decision-making skills
- Ability to work independently and under high pressure with tight schedules and deadlines
- Ability to interact with all levels of business professionals and coordinate with several teams
- Ability to multi-task in a fast-paced environment
- Professional demeanor at all times
- Required to participate in a 7x24 on-call rotation
Core Competencies
Demonstrates expertise in Cloud Security Architecture, including the development and implementation of security frameworks aligned with industry standards. Proficient in risk assessment, incident response, and the integration of security controls across cloud environments.
Highest-signal resume keywords
- Cloud Security Architecture
- Risk Assessment
- Incident Response Procedures
- Cloud Security Frameworks
- Security Controls Configuration
Hard Skills
- Cloud Security Architecture
- Security Controls Configuration
- Cloud Security Frameworks
- Incident Response Procedures
- Access Controls
- DLP
- WAF
- Encryption
- Network Security
- Monitoring
Soft Skills
- Customer Service Excellence
- Analytical Skills
- Problem-Solving Skills
- Project Management
- Communication Skills
Certifications & Qualifications
- CISSP
- CISM
- Cloud Security Alliance Certifications
- CCSP
- CCSK
Industry Keywords
- NIST Cyber Security Framework
- Cloud Security Alliance
- ISO 27000
- MITRE ATT&CK
- Systems Development Life Cycle
Tools & Technologies
- Microsoft Office Suite
- IManage
- Azure
- AWS
- CI/CD Pipelines
- Firewall
- Proxy
- AV
- SIEM
- Secure SDLC