Principal Technical Consultant – Cloud and Application Security

Posted 1 day ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Oversee strategy, roadmap, design, and planning workshops for small to medium-sized service engagements.

• Implement project objectives, gather requirements, manage tasks, milestones, status reporting, dependencies, and timelines.

• Develop and finalize project deliverables, along with conducting peer reviews of team collateral.

• Present deliverables to members of the project team.

• Provide support for delivery engagements throughout the entire project lifecycle.

• Define and put into practice application security delivery plans, which include secure SDLC controls, risk-based priority findings, developer enablement, metrics, and executive reporting.

• Facilitate application security and threat modeling workshops that address secure architecture, abuse cases, application and API risks, and remediation strategies.

• Resolve technical issues and offer solutions.

• Assist in business development through client discovery meetings.

• Represent service offerings during the sales cycle, which involves scoping, proposal development, and client presentations.

• Conduct client discovery and visioning workshops.

• Identify opportunities for cross-practice collaboration and solution sets.

• Contribute to the development, enhancement, and standardization of security service offerings.

• Own and/or enable multiple service capabilities.

• Serve as a technology thought leader and advocate.

• Stay updated on current and emerging IT trends, technologies, and standards.

• Mentor team members and security practitioners.


⛳️ Requirements

• Extensive expertise in information security, cloud security, application security, DevSecOps, threat management, and associated technologies.

• Over 5 years of hands-on experience with CNAPP tools (Wiz preferred).

• More than 5 years of experience with GCP and cloud-native services.

• At least 3 years of leadership experience.

• Over 10 years of consulting experience or equivalent work experience.

• Demonstrated experience in reviewing and implementing secure cloud reference architectures and landing zones.

• Skilled in designing Zero Trust and network segmentation architectures for cloud environments.

• Strong grasp of multi-cloud governance models, IaC, policy-as-code, tagging standards, and multi-account strategies.

• Experience in operationalizing secure cloud SDLC pipelines.

• Expertise in integrating CNAPP solutions with ServiceNow, CI/CD pipelines, and ticketing/alerting workflows.

• Familiar with SAST, DAST, SCA, ASPM, secrets detection, and code-to-cloud traceability.

• Knowledge of cloud identity, IAM, federation, and RBAC across multi-cloud environments.

• Experience in securing managed cloud AI/ML services.

• Proven track record in leading secure cloud migration projects/programs.

• In-depth knowledge of CIS Benchmarks, NIST, FedRAMP, ISO 27001, and GDPR.

• Strong understanding of DevSecOps and secure coding best practices.

• Proficient in application threat modeling, including STRIDE and abuse-case analysis.

• Experienced in reviewing and remediating insecure CI/CD pipelines.

• Expertise in API security for REST and GraphQL, including OWASP API Security Top 10.

• Ability to read, comprehend, and utilize Terraform, Bicep, and AWS CloudFormation.

• Familiar with OPA, Sentinel, and IaC scanning.

• Proficient in Python, PowerShell, and Bash scripting.

• Capable of performing secure code and architecture reviews.

• Experience with Docker and Kubernetes.

• Knowledgeable in securing software supply chains, including SBOM, dependency risk governance, signing, and SLSA.

• An undergraduate degree in Computer Sciences or Business Management is preferred, but not mandatory.

• Preferred professional, technical, and application security certifications.

• Proven experience in establishing or maturing application security programs and mentoring engineers.

• Excellent verbal and written communication abilities.

• Demonstrated business acumen and executive presence.

• Aptitude for solving complex, abstract problems.


🏝️ Benefits

• Medical, Dental, and Vision Insurance.

• 401(k) plan.

• Paid company holidays.

• Paid time off.

• Paid parental and caregiver leave.

• Opportunities for cross-department training and development.

• Sponsorship for certifications and credentials to support ongoing learning.

• Initiatives promoting diversity and inclusion.

• Option to opt-out of AI application/resume review without penalty.

• Option to opt-out of interview recording and transcription.

People also viewed

Atos18 hours ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Meridian Bioscience Inc.18 hours ago

Medical Device Cybersecurity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Providence19 hours ago

Senior Security Engineer – Identity and Access Management

US flagCalifornia, +2 more statesFull-timeCybersecurity / Security Engineer$54 – $122/hour
ApplyView job
Frontera19 hours ago

Head of Information Security – Compliance

US flagColorado OnlyFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Accela19 hours ago

Cybersecurity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$90k – $110k/year
ApplyView job
Climb Channel Solutions NA22 hours ago

Senior Director, Enterprise Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$225k – $260k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers