Lead Cloud Security Architect

Caesars Entertainment
Las Vegas, NV
Remote
Job Description
As a Lead Cloud Security Architect, you will design, implement, and maintain robust security measures to protect our cloud infrastructure and applications. You will lead a team of cloud security engineers and collaborate with cross-functional teams.

Requirements

  • Build and deploy security capabilities designed to secure code and production infrastructure throughout the CI/CD pipeline as well as non-production and production environments.
  • Identify and prevent the introduction of high-risk vulnerabilities to the production environment.
  • Leverage static and dynamic code analysis to security assess application and infrastructure code.
  • Implement and operationalize the AWS Security Pillar of the AWS Well-Architected Framework.
  • Implement and operationalize the GCP Google Cloud Architecture Framework.
  • Define, build, and maintain Cloud Security Policies, Standards, and Procedures that meet or exceed all required regulatory requirements.
  • Evaluate, implement, and operationalize a CSPM, CWPP, CNAPP solutions across multi-cloud.
  • Design and implement a Multi-Cloud Security Strategy (primarily for AWS and GCP).
  • Introduce commercial and vetted open-source solutions to secure and continuously monitor AWS cloud infrastructure, services, and workloads.
  • Help the application delivery and DevOps team detect and fix security vulnerabilities.
  • Leverage Terraform to automatically configure and maintain AWS cloud native and third-party security solutions.
  • Implement a strong identity foundation through least privilege policies.
  • Enable traceability/observability.
  • Apply security at all layers from PoP to endpoint.
  • Automate security best practices for scale and cost effectiveness.
  • Protect data at rest and in transit with proper classifications.
  • Keep people away from data to reduce or eliminate direct access or manual processing of data.
  • Prepare for security events to occur and build capabilities for SOC to be able to detect, contain, eradicate, and recover.
  • Leverage Python or Go to automate security acceptance testing.
  • Harden server operating systems and containers.
  • Review and analyze security event logs to support security incident response efforts.
  • Author and communicate blameless postmortems.
  • Lead and mentor a team of cloud security engineers, providing guidance and support for their professional development.
  • Collaborate with cross-functional teams to ensure security is integrated into all aspects of the development lifecycle.
  • Stay up-to-date with the latest security trends, threats, and technology solutions to continuously improve the organization's security posture.

Benefits

  • Cutting-edge security projects
  • Collaboration with industry-leading security professionals and executives
  • Opportunity to influence security programs across the entire Caesars Empire environments nationwide
]]>