Job Summary
The Senior Cloud Security Engineer is responsible for coding configuring and administering cloud information security systems. This role is expected to champion processes and technology as a subject matter contributor and researcher in various cloud infrastructure and system technical areas. The Senior Cloud Security Engineer works closely with teams in other Information Security disciplines infrastructure and operations areas to help provide superior protection to Bread Financials information assets. This role serves as a cloud security practitioner that builds and operates information security controls specific to cloud processing platforms. Senior Cloud Security Engineers identify threats to cloud systems develop new features to meet security needs and build maintain upgrade and continuously improve cloud-based systems. The Senior Cloud Security Engineer does everything from planning and architecting secure cloud system requirements to constructing validating and deploying the system to monitoring and detecting malicious activity once the system is deployed. Additionally this role identifies and recommends/remediates security gaps on the platform and infrastructure.Essential Job Functions
Cloud Software Development Lifecycle Security and Tooling - Demonstrate ability to leverage agile experience by integrating security tools into the CI and CD pipeline (Dev-Sec-Ops) developing scripts monitoring results generating metrics and tracking issues to resolution. Demonstrate maturity with maintaining and enhancing a set of cyber security tools and products designed to improve and evaluate cloud security. Test new tools and products by developing use cases and performing proof of value activities. Perform automation and orchestration when possible.
Process and Project Management - Support the implementation of key cloud projects and initiatives as they pertain to the organizations long-term security strategy. Identify areas of improvement where processes do not currently exist and drive the development and delivery of new processes to address these gaps. Deliver quality results with minimal supervision in coordinating projects collaborating with others and other deliverables. Demonstrate a willingness to escalate identified issues as necessary and the ability to identify when to partner with leadership to resolve issues risks or obstacles. Build consensus for delivering results while finding common ground for collaboration and partnership. This position assists in the research design validation and implementation of systems components and technologies and provides recommendations for strategies roadmaps and solutions. Submits RFQ/RFPs obtains quotes aggregates documents and proposals maintains current and proposed End-of-Life schedules and tracks the progression of key vendors.
Documentation Metrics and Presentations Create and maintain relevant documentation including the ability to deliver run books project updates process documentation architecture and technical requirements and presentations. Develop and deliver key performance indicators (KPIs) through the understanding of the tools and deliverables by helping to develop maintain and mature the associated reporting structure. Produce meaningful and actionable metrics through data analysis. Conduct data analysis exercises using Excel pivot tables database queries and other data driven analysis tools. Produce presentations at various levels of abstraction dependent on intended audience using Microsoft Power Point Visio or equivalent tools.
Leadership and Development - Successfully work in a team-fostered fast-paced multi-threaded environment. Serve as a champion of cloud security researching tools and process specific to cloud computing. Demonstrate self-learning in gaining knowledge of new technical developments and ensure they are shared appropriately and applied within the department. Identify and understand drivers for change and be an individual champion or partner with leadership to deliver those changes. Be an effective collaborator and problem solver. Strong negotiation and oral communication skills expected.
Human Relations Maintain a high level of confidentiality and professionalism. Proactively identify potential issues and provide options for solutions. Decompose complex topics and break them down into laymens terms or analogies that help drive clarity and understanding. Be an enabling partner that provides alternative options or supporting information when saying no to business or IT requests. Be creditable trustworthy and respectful.
Reports to: Manager Information Security
Working Conditions/ Physical Requirements: Normal office environment. Some travel may be required. As the need of the business continue to evolve this role may be asked to work an on-call rotation to include evenings or weekends.
Direct Reports: None
Minimum Qualifications:
Degree Required: Bachelors degree in computer science networking or information technology
Years of Work Experience Required: 5 years
Type / focus of work experience required: Experience in Information Security or Infrastructure with large scale platforms (cloud technologies) complex inter-dependent technologies data centers AWS internal software systems and tools e.g. AWS Security Hub Prisma Jenkins etc.
Type / focus of work experience preferred: Certification: Security Network CISSP SSCP CCSP Cloud.
Preferred Working Experience:
Working knowledge of 3-4 tools listed below or their competitor tool in the same capability/category:
Imperva Venafi Valimail Sectigo Entrust Abnormal CrowdStrike Splunk Protegrity BigID Varonis
Knowledge Skills and Abilities (e.g.) REQUIRED (needs to align with minimum experience)
Networking LDAP directories vulnerability/patch management encryption and key management web application firewall (WAF) network access control (NAC) and privileged access management (PAM).
Change management Incident management server and desktop management and access management.
Cloud architecture and computing and software application general computing controls.
Business continuity/disaster recovery.
Systems development lifecycle and project management methodologies specifically Agile/Scrum.
Working knowledge of web services API REST RPC and how to properly secure them in conjunction with experience and practical application of cloud security controls based on industry frameworks e.g. Cloud Security Alliance.
Knowledge of overall Microsoft Office 365 security including knowledge of azure active directory azure information protection information rights management single sign-on and multi-factor authentication and related technologies (including Microsoft Enterprise Mobility Security)
Other Duties
This job description is illustrative of the types of duties typically performed by this job. It is not intended to be an exhaustive listing of each and every essential function of the job. Because job content may change from time to time the Company reserves the right to add and/or delete essential functions from this job at any time.
About Bread Financial
At Bread Financial youll have the opportunity to grow your career give back to your community and be part of our award-winning culture. Weve been consistently recognized as a best place to work nationally and in many markets and were proud to promote an environment where you feel appreciated accepted valued and fulfilledboth personally and professionally. Bread Financial supports the overall wellness of our associates with a diverse suite of benefits and offers boundless opportunities for career development and non-traditional career progression.
To learn more about Bread Financial our global associates and our sustainability commitments visit or follow us on Instagram and LinkedIn.
All job offers are contingent upon successful completion of credit and background checks.
Bread Financial is an Equal Opportunity Employer.
Job Family:
Information TechnologyJob Type:
RegularRequired Experience:
Senior IC
At Bread Financial, we provide simple payment, lending and saving solutions. Explore our options for personal and business needs – from credit cards to pay-over-time.