
Principal Technical Consultant – Cloud and Application Security
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Oversee strategy, roadmap, design, and planning workshops for small to medium-sized service engagements.
• Implement project objectives, gather requirements, manage tasks, milestones, status reporting, dependencies, and timelines.
• Develop and finalize project deliverables, along with conducting peer reviews of team collateral.
• Present deliverables to members of the project team.
• Provide support for delivery engagements throughout the entire project lifecycle.
• Define and put into practice application security delivery plans, which include secure SDLC controls, risk-based priority findings, developer enablement, metrics, and executive reporting.
• Facilitate application security and threat modeling workshops that address secure architecture, abuse cases, application and API risks, and remediation strategies.
• Resolve technical issues and offer solutions.
• Assist in business development through client discovery meetings.
• Represent service offerings during the sales cycle, which involves scoping, proposal development, and client presentations.
• Conduct client discovery and visioning workshops.
• Identify opportunities for cross-practice collaboration and solution sets.
• Contribute to the development, enhancement, and standardization of security service offerings.
• Own and/or enable multiple service capabilities.
• Serve as a technology thought leader and advocate.
• Stay updated on current and emerging IT trends, technologies, and standards.
• Mentor team members and security practitioners.
• Extensive expertise in information security, cloud security, application security, DevSecOps, threat management, and associated technologies.
• Over 5 years of hands-on experience with CNAPP tools (Wiz preferred).
• More than 5 years of experience with GCP and cloud-native services.
• At least 3 years of leadership experience.
• Over 10 years of consulting experience or equivalent work experience.
• Demonstrated experience in reviewing and implementing secure cloud reference architectures and landing zones.
• Skilled in designing Zero Trust and network segmentation architectures for cloud environments.
• Strong grasp of multi-cloud governance models, IaC, policy-as-code, tagging standards, and multi-account strategies.
• Experience in operationalizing secure cloud SDLC pipelines.
• Expertise in integrating CNAPP solutions with ServiceNow, CI/CD pipelines, and ticketing/alerting workflows.
• Familiar with SAST, DAST, SCA, ASPM, secrets detection, and code-to-cloud traceability.
• Knowledge of cloud identity, IAM, federation, and RBAC across multi-cloud environments.
• Experience in securing managed cloud AI/ML services.
• Proven track record in leading secure cloud migration projects/programs.
• In-depth knowledge of CIS Benchmarks, NIST, FedRAMP, ISO 27001, and GDPR.
• Strong understanding of DevSecOps and secure coding best practices.
• Proficient in application threat modeling, including STRIDE and abuse-case analysis.
• Experienced in reviewing and remediating insecure CI/CD pipelines.
• Expertise in API security for REST and GraphQL, including OWASP API Security Top 10.
• Ability to read, comprehend, and utilize Terraform, Bicep, and AWS CloudFormation.
• Familiar with OPA, Sentinel, and IaC scanning.
• Proficient in Python, PowerShell, and Bash scripting.
• Capable of performing secure code and architecture reviews.
• Experience with Docker and Kubernetes.
• Knowledgeable in securing software supply chains, including SBOM, dependency risk governance, signing, and SLSA.
• An undergraduate degree in Computer Sciences or Business Management is preferred, but not mandatory.
• Preferred professional, technical, and application security certifications.
• Proven experience in establishing or maturing application security programs and mentoring engineers.
• Excellent verbal and written communication abilities.
• Demonstrated business acumen and executive presence.
• Aptitude for solving complex, abstract problems.
• Medical, Dental, and Vision Insurance.
• 401(k) plan.
• Paid company holidays.
• Paid time off.
• Paid parental and caregiver leave.
• Opportunities for cross-department training and development.
• Sponsorship for certifications and credentials to support ongoing learning.
• Initiatives promoting diversity and inclusion.
• Option to opt-out of AI application/resume review without penalty.
• Option to opt-out of interview recording and transcription.
Atos
Meridian Bioscience Inc.
Providence
Frontera
Get handpicked remote jobs straight to your inbox weekly.