Sr. Consultant, Cloud Security
Job Purpose and Impact
The Senior Cloud Security Consultant safeguards the organization's cloud estate by leading the design, implementation, and continuous improvement of security controls, guardrails, and governance across all public cloud platforms. This role serves as a trusted advisor and technical leader, driving enterprise cloud security strategy, standards, and posture improvement initiatives. With minimal supervision, the Senior Consultant partners with cybersecurity, cloud platform, infrastructure, engineering, risk, and business leaders to reduce cloud risk exposure and improve the security of cloud adoption at scale.
Key Accountabilities
-Leading enterprise-wide cloud security programs across AWS, Azure, Google Cloud, and Oracle Cloud Infrastructure.
-Designing, implementing, and operating preventive guardrails – service control policies, Azure Policy, organization policies – that enforce security requirements by default.
-Analyzing cloud posture data from CSPM and CNAPP platforms and prioritizing findings by exposure, data sensitivity, business criticality, and compensating controls.
-Driving remediation accountability across platform and application teams, and governing security exceptions and risk acceptances.
-Leading cloud identity and access governance, including privileged access, federation, workload identity, secrets management, and least-privilege enforcement.
-Defining and maintaining enterprise cloud security standards, secure baselines, reference architectures, and landing zone requirements.
-Leading cloud security assessments and architecture reviews, and translating findings into prioritized remediation roadmaps.
-Designing automation, auto-remediation, and dashboards that improve control coverage, program efficiency, and reporting.
-Delivering executive-level reporting, metrics, and risk insights, and partnering with Incident Response, Threat Intelligence, and Security Architecture teams.
-Mentoring junior engineers and maintaining currency on cloud provider service changes, control frameworks such as CSA CCM and CIS Benchmarks, and emerging cloud attack techniques.
ESSENTIAL FUNCTIONS
-CLOUD SECURITY STRATEGY & GOVERNANCE: Leads the design, implementation, operation, and continuous improvement of enterprise cloud security capabilities. Establishes standards, governance processes, performance metrics, and risk management practices to reduce cloud risk exposure.
-PREVENTIVE CONTROLS & GUARDRAIL ENGINEERING: Provides strategic and hands-on ownership of preventive cloud controls, ensuring insecure configurations are blocked by default and guardrail coverage keeps pace with cloud service adoption.
-CLOUD POSTURE & MISCONFIGURATION REMEDIATION: Develops and maintains enterprise risk models for cloud posture findings, ensuring remediation efforts focus on the most significant business and cybersecurity risks, and advances automated remediation where appropriate.
-CLOUD IDENTITY & ACCESS GOVERNANCE: Leads the definition and enforcement of identity, entitlement, and privileged access controls across cloud platforms to reduce identity-driven risk.
-COMPLIANCE & CONTROL ASSURANCE: Maintains traceability between enterprise control frameworks and cloud-native enforcement and detection, evidencing control effectiveness for audit, regulatory, and customer assurance needs.
-PROGRAM LEADERSHIP & CONTINUOUS IMPROVEMENT: Leads cross-functional initiatives that improve cloud asset visibility, control coverage, remediation performance, governance processes, and overall program maturity.
-EXECUTIVE COMMUNICATION & STAKEHOLDER MANAGEMENT: Communicates complex technical risks to executive leadership and business stakeholders, influencing strategic decisions and prioritization of remediation activities.
Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related technical field, or equivalent practical experience.
- 6+ years of cybersecurity experience, including 4+ years focused on cloud security engineering, architecture, or consulting.
- Hands-on experience securing enterprise cloud environments in at least one of AWS, Microsoft Azure, Google Cloud, or Oracle Cloud Infrastructure, with working knowledge of a second.
- Proven experience designing and operating preventive cloud guardrails – AWS service control policies, Azure Policy, Google organization policies, or equivalent policy-as-code enforcement – not detection and reporting alone.
- Strong expertise in cloud security architecture and cloud-native security controls across IaaS, PaaS, and SaaS, including network security, data protection, and key management such as Azure Key Vault or AWS KMS.
- Deep expertise in cloud identity and access management, including least-privilege role design, federation and workload identity, privileged access management, conditional access, and Zero Trust principles.
- Hands-on experience operating a CSPM or CNAPP platform at enterprise scale – Wiz, Microsoft Defender for Cloud, Prisma Cloud, AWS Security Hub, or equivalent – including onboarding, policy tuning, finding triage, and remediation ownership routing.
- Hands-on experience with infrastructure as code security and policy enforcement using Terraform, Bicep, ARM templates, or CloudFormation, and integrating security controls into CI/CD pipelines and DevSecOps practices.
- Proven experience conducting cloud security assessments, posture reviews, threat modeling, architecture reviews, and security control validation, and translating findings into prioritized remediation roadmaps.
- Strong knowledge of cloud security frameworks and standards including CSA Cloud Controls Matrix, CIS Benchmarks, NIST, ISO 27001, and cloud provider Well-Architected security principles.
- Experience driving remediation accountability across platform and application teams, governing security exceptions and risk acceptances, and communicating cloud risk to senior leaders and executive audiences.
Cloud Incident Response
- Experience supporting cloud security incident investigations as the cloud subject matter expert, in partnership with Incident Response and security operations teams – including compromised cloud identities and credentials, unauthorized access, data exposure, and misconfigured cloud resources.
- Working knowledge of cloud-native telemetry and audit sources such as AWS CloudTrail and GuardDuty, Azure Activity Logs and Microsoft Defender, and Google Cloud Logging, and their use in investigation, root cause analysis, and preventing recurrence.
Preferred Certifications
- Cloud-specific certifications strongly preferred: CCSP, CCSK, AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect Expert (SC-100), or Google Professional Cloud Security Engineer.
- CISSP or an equivalent broad security certification is preferred.
Sincronizare posturi Linkedin
Aflați unde vă încadrați în cadrul Cargill. Conectați-vă la profilul dumneavoastră LinkedIn și vom folosi aptitudinile și experiența pentru a căuta locuri de muncă potrivite pentru dumneavoastră.
Durabilitate pentru cacao
Programul 'Promisiunea Cargill privind cacaua' se angajează să securizeze un sector prosper pentru cacao, timp de generații.
Diversitate, Echitate si Incluziune
Cultura companiei cu privire la integrare ne ajută să dăm formă viitorului lumii.
