EngineerJobs.io
← Back to all jobs

Job Description

Join Bank OZK to help secure cloud environments for a regulated financial institution through controls, compliance, and incident response.

Responsibilities

  • Support onboarding and risk assessment of new Cloud Service Providers (CSPs) through the Third-Party Risk Management (TPRM) process.
  • Assess CSP security controls against the Bank OZK Cloud Security Standard and regulatory requirements to ensure proposed cloud solutions meet legal and compliance criteria prior to approval.
  • Implement and maintain cloud security controls across SaaS, PaaS, and IaaS, using Bank-approved secure configuration baselines (including benchmarks such as CIS) for resources like VMs, containers, and storage.
  • Enforce secure-by-default settings during deployments.
  • Partner with OZK Technology teams to design end-to-end cloud architectures incorporating network segmentation, encryption, and other security best practices.
  • Integrate cloud platforms and applications with the Bank’s centralized Single Sign-On (SSO) and identity management systems.
  • Ensure cloud activity logs are enabled, collected, and integrated with SIEM and monitoring systems (Bank OZK Security Information and Event Management).
  • Develop detection mechanisms or alert rules to monitor cloud events for compromise indicators or policy violations.
  • Investigate and respond to cloud security incidents in coordination with the Security Operations Center (SOC), supporting remediation and lessons learned.
  • Manage security compliance and misconfiguration risk using Cloud Security Posture Management (CSPM) tools or scripts.
  • Perform configuration audits and vulnerability scans of cloud assets; coordinate with infrastructure and application teams to remediate weaknesses or document risk acceptances per Bank vulnerability management standards.
  • Work with software development teams and Application Security Engineers to deploy cloud-native applications securely, including threat modeling and secure SDLC practices aligned with Bank standards.
  • Implement cloud-native application security controls, including WAFs for internet-facing apps and enforce proper restrictions for sensitive data stores (e.g., security groups and private endpoints).
  • Embed security into CI/CD and Infrastructure-as-Code (IaC) workflows; implement automated security checks for templates and application code (e.g., IaC scanning, container image scanning, secret leakage detection).
  • Advise on secure configuration of CI/CD tooling and use of secure secret management for pipeline credentials, promoting DevSecOps practices.
  • Provide guidance and training to IT cloud engineers, developers, and business units on cloud security requirements and secure cloud service usage.
  • Maintain documentation for cloud security controls and processes to support audits or examinations.
  • Provide evidence of compliance with the Bank’s Cloud Security Standard and applicable regulations during internal, external, or regulatory audits; drive corrective actions and process improvements based on findings.
  • Stay current with regulatory guidance, including FFIEC cloud computing guidance and NYDFS cybersecurity requirements.
  • Keep pace with evolving cloud security threats, tools, and best practices for financial institutions.
  • Recommend and implement enhancements to Bank OZK’s cloud security posture.
  • Perform additional tasks and support other team members as needed.

Requirements

  • Bachelor’s degree in Information Systems or related field (or commensurate work experience), required.
  • 3+ years of work experience in a regulated financial institution or other heavily regulated environment, required.
  • Familiarity with banking-specific security considerations and third-party risk management practices for cloud services, required.
  • Knowledge of integrating security testing tools into build/deployment pipelines and managing secrets for automation.
  • Ability to work with DevOps/CI-CD pipelines and use Infrastructure-as-Code (e.g., Terraform, CloudFormation) securely.
  • Advanced security mindset to assess risk in cloud architectures.
  • Ability to apply confidentiality, integrity, and availability principles when evaluating cloud solutions and making risk-based decisions aligned with the Bank’s risk appetite.
  • Strong diligence configuring and reviewing cloud settings, logs, and processes; follow through until issues are fully resolved and verified.
  • Strong critical thinking to analyze complex technical problems or security events in cloud environments.
  • Ability to break down problems, identify patterns or root causes, and develop mitigations.
  • Ability to communicate cloud security issues in terms of business impact.
  • Excellent interpersonal skills for cross-functional collaboration and influencing secure outcomes without formal authority.
  • Ability to operate in a fast-paced, evolving environment and update strategies for new cloud services, threats, and regulatory requirements.
  • Self-motivated and proactive; takes ownership and drives improvements; demonstrates strong responsibility and ethics when handling sensitive systems and data.
  • Demonstrated initiative to accomplish work objectives.
  • Professional security certifications related to cloud and information security (e.g., CCSP, CISSP, AWS/Azure Security Engineer, or CompTIA Security+), preferred.

Technologies

  • CIS
  • SaaS, PaaS, IaaS
  • Single Sign-On (SSO)
  • SIEM
  • Cloud Security Posture Management (CSPM)
  • CSPs
  • TPRM
  • WAF
  • Security groups, private endpoints
  • CI/CD
  • Infrastructure-as-Code (IaC)
  • Terraform, CloudFormation
  • DevOps
  • CCSP, CISSP, AWS, Azure, CompTIA Security+
  • FFIEC cloud computing guidance
  • NYDFS cybersecurity requirements

Benefits

  • Generous PTO
  • 401(k) matching
  • Health, dental, vision (and pet!) insurance
  • Special perks and discounts

Job Purpose & Scope

  • Ensure the secure design, implementation, and operation of Bank OZK cloud environments.
  • Partner with IT, Labs, Data, Third-Party Risk Management, and application owners to implement cloud security controls and enforce compliance with Bank policies and industry regulations.

Job Expectations

  • Operate customary equipment and technology used in a business environment, with or without accommodation.
  • Note: description is not exhaustive; other job functions, duties, skills, and standards may be added, and management may change requirements at any time.

Similar Jobs