Technical, business & role skills:
- a minimum of 4 years combined experience in cybersecurity, risk management or software development.
- experience with designing and implementing cybersecurity controls to identity, protect, detect, respond, and recover from cyber threats and vulnerabilities.
- technical skills in cloud and security design in aws and azure incorporating native security controls.
desirable working knowledge with aws or azure services: security scores, key vault, secrets manager, waf, service bus, app services, lambda, etc
- experience performing security risk assessments of information systems, interfaces, and technologies to produce contextual risk ratings and recommendations to mitigate those risks.
- experience programing and scripting.
- experience creating and analyzing indicators and metrics based on risk.
- ability to communicate effectively with multidisciplinary technical teams
desirable:
- experience working with common frameworks, and security and compliance standards such as cloud security alliance (csa) cloud controls, iso 27001, owasp, and nist csf.
- certifications in the fields of information security, it risk, cloud security are desirable.
aws certified security specialty, azure security engineer associate, cissp, cism, cisa certifications are preferred.