Cloud Security Engineer
Job Description
Join Bank OZK to help secure cloud environments for a regulated financial institution through controls, compliance, and incident response.
Responsibilities
- Support onboarding and risk assessment of new Cloud Service Providers (CSPs) through the Third-Party Risk Management (TPRM) process.
- Assess CSP security controls against the Bank OZK Cloud Security Standard and regulatory requirements to ensure proposed cloud solutions meet legal and compliance criteria prior to approval.
- Implement and maintain cloud security controls across SaaS, PaaS, and IaaS, using Bank-approved secure configuration baselines (including benchmarks such as CIS) for resources like VMs, containers, and storage.
- Enforce secure-by-default settings during deployments.
- Partner with OZK Technology teams to design end-to-end cloud architectures incorporating network segmentation, encryption, and other security best practices.
- Integrate cloud platforms and applications with the Bank’s centralized Single Sign-On (SSO) and identity management systems.
- Ensure cloud activity logs are enabled, collected, and integrated with SIEM and monitoring systems (Bank OZK Security Information and Event Management).
- Develop detection mechanisms or alert rules to monitor cloud events for compromise indicators or policy violations.
- Investigate and respond to cloud security incidents in coordination with the Security Operations Center (SOC), supporting remediation and lessons learned.
- Manage security compliance and misconfiguration risk using Cloud Security Posture Management (CSPM) tools or scripts.
- Perform configuration audits and vulnerability scans of cloud assets; coordinate with infrastructure and application teams to remediate weaknesses or document risk acceptances per Bank vulnerability management standards.
- Work with software development teams and Application Security Engineers to deploy cloud-native applications securely, including threat modeling and secure SDLC practices aligned with Bank standards.
- Implement cloud-native application security controls, including WAFs for internet-facing apps and enforce proper restrictions for sensitive data stores (e.g., security groups and private endpoints).
- Embed security into CI/CD and Infrastructure-as-Code (IaC) workflows; implement automated security checks for templates and application code (e.g., IaC scanning, container image scanning, secret leakage detection).
- Advise on secure configuration of CI/CD tooling and use of secure secret management for pipeline credentials, promoting DevSecOps practices.
- Provide guidance and training to IT cloud engineers, developers, and business units on cloud security requirements and secure cloud service usage.
- Maintain documentation for cloud security controls and processes to support audits or examinations.
- Provide evidence of compliance with the Bank’s Cloud Security Standard and applicable regulations during internal, external, or regulatory audits; drive corrective actions and process improvements based on findings.
- Stay current with regulatory guidance, including FFIEC cloud computing guidance and NYDFS cybersecurity requirements.
- Keep pace with evolving cloud security threats, tools, and best practices for financial institutions.
- Recommend and implement enhancements to Bank OZK’s cloud security posture.
- Perform additional tasks and support other team members as needed.
Requirements
- Bachelor’s degree in Information Systems or related field (or commensurate work experience), required.
- 3+ years of work experience in a regulated financial institution or other heavily regulated environment, required.
- Familiarity with banking-specific security considerations and third-party risk management practices for cloud services, required.
- Knowledge of integrating security testing tools into build/deployment pipelines and managing secrets for automation.
- Ability to work with DevOps/CI-CD pipelines and use Infrastructure-as-Code (e.g., Terraform, CloudFormation) securely.
- Advanced security mindset to assess risk in cloud architectures.
- Ability to apply confidentiality, integrity, and availability principles when evaluating cloud solutions and making risk-based decisions aligned with the Bank’s risk appetite.
- Strong diligence configuring and reviewing cloud settings, logs, and processes; follow through until issues are fully resolved and verified.
- Strong critical thinking to analyze complex technical problems or security events in cloud environments.
- Ability to break down problems, identify patterns or root causes, and develop mitigations.
- Ability to communicate cloud security issues in terms of business impact.
- Excellent interpersonal skills for cross-functional collaboration and influencing secure outcomes without formal authority.
- Ability to operate in a fast-paced, evolving environment and update strategies for new cloud services, threats, and regulatory requirements.
- Self-motivated and proactive; takes ownership and drives improvements; demonstrates strong responsibility and ethics when handling sensitive systems and data.
- Demonstrated initiative to accomplish work objectives.
- Professional security certifications related to cloud and information security (e.g., CCSP, CISSP, AWS/Azure Security Engineer, or CompTIA Security+), preferred.
Technologies
- CIS
- SaaS, PaaS, IaaS
- Single Sign-On (SSO)
- SIEM
- Cloud Security Posture Management (CSPM)
- CSPs
- TPRM
- WAF
- Security groups, private endpoints
- CI/CD
- Infrastructure-as-Code (IaC)
- Terraform, CloudFormation
- DevOps
- CCSP, CISSP, AWS, Azure, CompTIA Security+
- FFIEC cloud computing guidance
- NYDFS cybersecurity requirements
Benefits
- Generous PTO
- 401(k) matching
- Health, dental, vision (and pet!) insurance
- Special perks and discounts
Job Purpose & Scope
- Ensure the secure design, implementation, and operation of Bank OZK cloud environments.
- Partner with IT, Labs, Data, Third-Party Risk Management, and application owners to implement cloud security controls and enforce compliance with Bank policies and industry regulations.
Job Expectations
- Operate customary equipment and technology used in a business environment, with or without accommodation.
- Note: description is not exhaustive; other job functions, duties, skills, and standards may be added, and management may change requirements at any time.
Similar Jobs
S