Sr. Consultant, Cloud Security
Job Summary
The Senior Cloud Security Consultant safeguards the organizations cloud estate by leading the design implementation and continuous improvement of security controls guardrails and governance across all public cloud platforms. This role serves as a trusted advisor and technical leader driving enterprise cloud security strategy standards and posture improvement initiatives. With minimal supervision the Senior Consultant partners with cybersecurity cloud platform infrastructure engineering risk and business leaders to reduce cloud risk exposure and improve the security of cloud adoption at scale.
-Leading enterprise-wide cloud security programs across AWS Azure Google Cloud and Oracle Cloud Infrastructure.
-Designing implementing and operating preventive guardrails service control policies Azure Policy organization policies that enforce security requirements by default.
-Analyzing cloud posture data from CSPM and CNAPP platforms and prioritizing findings by exposure data sensitivity business criticality and compensating controls.
-Driving remediation accountability across platform and application teams and governing security exceptions and risk acceptances.
-Leading cloud identity and access governance including privileged access federation workload identity secrets management and least-privilege enforcement.
-Defining and maintaining enterprise cloud security standards secure baselines reference architectures and landing zone requirements.
-Leading cloud security assessments and architecture reviews and translating findings into prioritized remediation roadmaps.
-Designing automation auto-remediation and dashboards that improve control coverage program efficiency and reporting.
-Delivering executive-level reporting metrics and risk insights and partnering with Incident Response Threat Intelligence and Security Architecture teams.
-Mentoring junior engineers and maintaining currency on cloud provider service changes control frameworks such as CSA CCM and CIS Benchmarks and emerging cloud attack techniques.
ESSENTIAL FUNCTIONS
-CLOUD SECURITY STRATEGY & GOVERNANCE: Leads the design implementation operation and continuous improvement of enterprise cloud security capabilities. Establishes standards governance processes performance metrics and risk management practices to reduce cloud risk exposure.
-PREVENTIVE CONTROLS & GUARDRAIL ENGINEERING: Provides strategic and hands-on ownership of preventive cloud controls ensuring insecure configurations are blocked by default and guardrail coverage keeps pace with cloud service adoption.
-CLOUD POSTURE & MISCONFIGURATION REMEDIATION: Develops and maintains enterprise risk models for cloud posture findings ensuring remediation efforts focus on the most significant business and cybersecurity risks and advances automated remediation where appropriate.
-CLOUD IDENTITY & ACCESS GOVERNANCE: Leads the definition and enforcement of identity entitlement and privileged access controls across cloud platforms to reduce identity-driven risk.
-COMPLIANCE & CONTROL ASSURANCE: Maintains traceability between enterprise control frameworks and cloud-native enforcement and detection evidencing control effectiveness for audit regulatory and customer assurance needs.
-PROGRAM LEADERSHIP & CONTINUOUS IMPROVEMENT: Leads cross-functional initiatives that improve cloud asset visibility control coverage remediation performance governance processes and overall program maturity.
-EXECUTIVE COMMUNICATION & STAKEHOLDER MANAGEMENT: Communicates complex technical risks to executive leadership and business stakeholders influencing strategic decisions and prioritization of remediation activities.
- Bachelors degree in Computer Science Cybersecurity Information Security Information Systems or a related technical field or equivalent practical experience.
- 6 years of cybersecurity experience including 4 years focused on cloud security engineering architecture or consulting.
- Hands-on experience securing enterprise cloud environments in at least one of AWS Microsoft Azure Google Cloud or Oracle Cloud Infrastructure with working knowledge of a second.
- Proven experience designing and operating preventive cloud guardrails AWS service control policies Azure Policy Google organization policies or equivalent policy-as-code enforcement not detection and reporting alone.
- Strong expertise in cloud security architecture and cloud-native security controls across IaaS PaaS and SaaS including network security data protection and key management such as Azure Key Vault or AWS KMS.
- Deep expertise in cloud identity and access management including least-privilege role design federation and workload identity privileged access management conditional access and Zero Trust principles.
- Hands-on experience operating a CSPM or CNAPP platform at enterprise scale Wiz Microsoft Defender for Cloud Prisma Cloud AWS Security Hub or equivalent including onboarding policy tuning finding triage and remediation ownership routing.
- Hands-on experience with infrastructure as code security and policy enforcement using Terraform Bicep ARM templates or CloudFormation and integrating security controls into CI/CD pipelines and DevSecOps practices.
- Proven experience conducting cloud security assessments posture reviews threat modeling architecture reviews and security control validation and translating findings into prioritized remediation roadmaps.
- Strong knowledge of cloud security frameworks and standards including CSA Cloud Controls Matrix CIS Benchmarks NIST ISO 27001 and cloud provider Well-Architected security principles.
- Experience driving remediation accountability across platform and application teams governing security exceptions and risk acceptances and communicating cloud risk to senior leaders and executive audiences.
Cloud Incident Response
- Experience supporting cloud security incident investigations as the cloud subject matter expert in partnership with Incident Response and security operations teams including compromised cloud identities and credentials unauthorized access data exposure and misconfigured cloud resources.
- Working knowledge of cloud-native telemetry and audit sources such as AWS CloudTrail and GuardDuty Azure Activity Logs and Microsoft Defender and Google Cloud Logging and their use in investigation root cause analysis and preventing recurrence.
Preferred Certifications
- Cloud-specific certifications strongly preferred: CCSP CCSK AWS Certified Security Specialty Microsoft Certified: Azure Security Engineer Associate (AZ-500) Microsoft Cybersecurity Architect Expert (SC-100) or Google Professional Cloud Security Engineer.
- CISSP or an equivalent broad security certification is preferred.
Required Experience:
Senior IC
About Company
Cargill, Incorporated is an American privately held global corporation based in Minnetonka, Minnesota, and incorporated in Wilmington, Delaware. Founded in 1865, it is the largest privately held corporation in the United States in terms of revenue.