The Job logo

What

Where

Associate Director - Cloud Security Architect

ApplyJoin for More Updates

You must Sign In before continuing to the company website to apply.

Smart SummaryPowered by Roshi
The Cloud Security Strategy, Architecture and Governance Architect is a senior role responsible for creating and refining the Cognizant cloud security strategy. You will draft and provide updates for cloud security standards and policies, develop and review cloud security architectures, and guide implementation teams. Additionally, you will identify gaps in current cloud implementations, handle security escalations, provide guidance on remediation plans, and act as a mentor. Minimum of ten years of progressive experience in cyber security and hands-on experience with hyper scale cloud service providers required.

The Cloud Security Strategy, Architecture and Governance Architect is a senior role. While hands on architecture skills are required, this role may also have the responsibility of managing other security architects or internal initiatives. Typically, this requires ten to twenty years of Cyber Security experience as well as at least five years managing a small group.

Responsibilities:

·       Work with Corporate Security leadership to create and refine Cognizant cloud security strategy

·       Draft and provide updates for Cognizant cloud security standards and policies

·       Develop, document, and review cloud security architectures in compliance with Cognizant standards

·       Provide guidance, direction and support to teams implementing cloud security architectures

·       Identify gaps in current cloud implementations compared to standards and policies

·       Support, manage, and handle escalations related to security review of cloud implementations

·       Provide guidance on remediation plans, solutions, and compensating controls to manage risk

·       Foster better security through encouraging teams to use automated security tools

·       Act as a cloud security subject matter expert and assist in answering cloud security questions from across Cognizant

·       Identify and participate in other cloud security initiatives for career growth and to grow Corporate Security capabilities

·       Explain practical risks associated with security risks and vulnerabilities to aid the business in decision making

·       Act as a mentor and manage other architects to ensure that processes and risk tolerance are consistent with Cognizant standards and processes

 Required Experience:

·       Minimum of ten years of progressive experience with cyber security technology design, administration, or incident response in large complex environments

·       Experience in two or more of the following: security and risk management, security architecture and engineering, communications and network security, identity and access management, security assessment and testing, security operations, software development security

·       Experience in two or more of the following: cloud concepts, architecture and design, cloud data security, cloud platform and infrastructure security, cloud application security, cloud security operations, cloud legal risk and compliance

·       Knowledge of compliance standards such as Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI DSS), Sarbanes-Oxley Act (SOX), National Institute of Standards and Technology (NIST 800-171), or equivalents

·       Minimum five years demonstrated experience mentoring, training, and developing other IT staff

·       Hands-on experience with at least one of the hyper scale cloud service providers:

o   Microsoft Azure

o   Amazon Web Services (AWS)

o   Google Cloud Platform (GCP)

·       Subject matter expertise in multiple cyber security technologies including:

o   Next-Generation Firewalls (NGFW)

o   Intrusion Detection System/Intrusion Prevention System (IDS/IPS)

o   Network Access Control (NAC)

o   Cloud Access Security Broker (CASB)

o   Security Incident Event Monitoring (SIEM)

o   email and web security

o   data protection

o   credential vaulting

o   certificate management

o   multi-factor authentication

o   cybersecurity automation

o   endpoint protection and response

o   vulnerability scanning and analysis

·       Working knowledge of:

o   Active Directory (AD) and Azure Active Directory (AAD)

o   Microsoft and/or Linux OS

o   Networking

o   Firewalls

o   Identity and Access Management (IAM)

o   Application Security

o   Penetration Testing

o   Incident Response

Employee Status : Full Time Employee

Shift : Day Job

Travel : No


 

Set alert for similar jobsAssociate Director - Cloud Security Architect role in Chennai, India
Cognizant Logo

Company

Cognizant

Job Posted

a year ago

Job Type

Full-time

WorkMode

On-site

Experience Level

8-12 Years

Category

Technology

Locations

Chennai, Tamil Nadu, India

Qualification

Bachelor

Applicants

Be an early applicant

Related Jobs

ASSA ABLOY Group Logo

Lead Cloud Security

ASSA ABLOY Group

Chennai, Tamil Nadu, India

Posted: a year ago

Lead Cloud Security Engineer position will work collaboratively with software engineering teams, infrastructure, and security teams to create and maintain partner program-specific security/audit compliance requirements. The position plays a key role in designing, developing, and implementing security automation needs.

Celestica Logo

Senior Architect, Information Security - Cloud Security Lead

Celestica

Chennai, Tamil Nadu, India

Posted: a year ago

Summary:  The Senior Architect, Information Security - Cloud Security Lead will identify and own IT Security initiatives and projects. They work closely with Stakeholders to understand the business (security initiatives and compliance) security requirements and risks and work with IT team to implement. They also ensure IT projects/initiatives are part of Security strategy and within IT roadmap. Detailed Description:  Performs tasks such as, but not limited to, the following: Establish and maintain interactive collaboration with IT Security team and Stakeholders and process owners to proactively assess risks Perform Security assessment, evaluate security controls of cloud platforms and cloud deployment Implement and manage security controls protecting the cloud systems and build capabilities against future threats Document Cloud  Security Reference Architectures and roadmaps which provide guidance for Security engineering teams Leads the engagements with Stakeholder and IT Security initiatives and projects (including security governance and compliance) Liaise with the enterprise architecture team to ensure alignment between the security initiatives and projects and security architecture Provides consultancy and guidance in all aspects of cloud security Oversee the deployment and maintenance of IT Security solutions and compliance Evaluate general and specific training needs; deliver training to support the control environment & associated control framework; communicate governance & compliance objectives, fostering a  compliance & risk aware culture Liaise with Security operation teams on cloud incident resolution, change management, and problem management   Knowledge/Skills/Competencies:  Strong background in security architecture, security design and defining security frameworks for the enterprise Experience in designing practical security solutions for multi-cloud based platforms, including identity and access management, data protection, cloud platform security and cyber controls Hands-on experience in Cloud (Microsoft Azure/GCP/AWS ) security architecture, security engineering, or equivalent experience with vendor specific cloud certification. Experience of managing Microsoft Azure, AWS Cloud platforms, GCP would be advantageous Experience in Dev-ops practice and tooling, application security threat modelling & data security. Experience in Terraform, Ansible, Azure Blueprints, ARM Templates and Azure policy or equivalent Advanced knowledge of Active Directory, Single-Sign On (SSO), and Federated Identities.  Knowledge of IT Penetration Testing  Knowledge in IT Risk Management and IT Sox Compliance  Knowledge of IT Security Architecture  Knowledge of IT Compliance Standards and best practices, IT Security Best Practices and IT Governance and Audit Procedures  Knowledge of common information security frameworks and IT controls frameworks, such as ISO/IEC 27001, ITIL, COBIT, NIST Cybersecurity, CIS Controls Knowledge and understanding of relevant legal and regulatory requirements, such as Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA) and Payment Card Industry/Data Security Standard. Knowledge of global requirements Excellent communication and business writing skills with experience in defining business requirements; ability to communicate security and risk-related concepts to technical and nontechnical audiences  Excellent problem resolution and creative problem solving skills  Strong customer management skills; ability to clearly articulate the role that IT can play in enhancing customer activities  Knowledge of Celestica’s technology, business and IT strategies