- Solid stakeholder management skills.
- Problem-solving capabilities.
- Attention to detail.
- Continuous learning attitude. Good to Have Functional &
- Technical Skills • Microsoft Defender for Cloud.
- Wiz, Prisma Cloud, Orca, Lacework, or equivalent CSPM solutions.
- Infrastructure as Code (Terraform, ARM, Bicep).
- Cloud container security and Kubernetes security.
- Knowledge of GDPR, NIS2, and DORA requirements.
Behavioral
Competencies • Project coordination skills.
- Change management experience.
Key Responsibilities Cloud Security Governance &
- Compliance • Support implementation of cloud security standards, policies, and controls.
- Monitor compliance with cloud security baselines and regulatory requirements.
- Ensure cloud environments adhere to security best practices and governance standards.
Cloud Security Posture
Management • Monitor CSPM dashboards and security posture indicators.
- Identify cloud misconfigurations, excessive permissions, exposed resources, and security gaps.
- Support remediation activities with cloud platform teams and application owners.
- Track security posture improvements and risk reduction initiatives.
Cloud Risk
Assessment • Perform cloud security assessments for current and existing cloud services.
- Identify risks associated with cloud deployments and recommend mitigation actions.
- Support cloud architecture reviews from a cybersecurity perspective. Reporting &
- Stakeholder Management • Develop cloud security dashboards, KPIs, and posture reports.
- Provide recommendations for improving cloud security maturity.
- Work closely with cloud architects, engineers, and business stakeholders.
Continuous
Improvement • Support cloud security automation initiatives.
- Contribute to cloud security awareness and best-practice adoption.
- Stay informed about emerging cloud threats and security technologies.
Required Skills &
Competencies Functional &
- Technical Skills • Cloud security fundamentals (Azure, AWS, and/or GCP).
- Cloud Security Posture Management (CSPM).
- Identity and Access Management (IAM).
- Cloud governance and risk management.
- Knowledge of security frameworks (NIST, ISO 27001, CIS Benchmarks).
- Cloud security monitoring and reporting capabilities.