We're seeking top talent passionate and provide technical expertise in the maintenance and support of the company’s Cloud SAAS Applications and Information security department. Identify and resolve issues, improve system security and search for security improvement opportunities. Additionally, maintain and follow all relevant procedures and documentation, reviewing and updating where required.
Your Team
Our Information Security department is to protect Invesco’s information and Information assets from all internal and external, deliberate, or accidental threats. The information security team will protect data from unauthorized access while maintaining the confidentiality, integrity, and availability of information. In addition, designing and maintaining the Security Policies and Standards while adhering to legislative and regulatory requirements, providing information security training for all employees, and ensuring the business continuity of Invesco.
Your Role:
Design and implementing, managing, and monitoring security measures to protect our SaaS applications and the data of our customers. You will work closely with cross-functional teams to ensure our cloud security practices meet industry standards and comply with relevant regulations. As a SAAS Security Specialist, the individual will be a member of the Global Information Security team ensuring that Invesco’s landscape is secure.
You Will Be Responsible For:
Develop and implement security strategies, policies, and procedures for SaaS applications.
Monitor and respond to security incidents, vulnerabilities, and threats in the cloud environment.
Defining technical security requirements related to cloud workloads that require integration with IAM, Security Groups, Data and Information Protection, CI/CD pipelines, Kubernetes, Security Information Event Monitoring (SIEM) systems integration, and others
Researching and designing current and future cloud security solutions to improve compliance with NIST Framework and Cloud Security Alliance guidance by working to identify common patterns for template provisioning
Developing and deploying infrastructure as a code scripts to implement and optimize security controls and mechanisms of a cloud infrastructure
Supporting cloud projects, tactical initiatives and provide hands on implementation of various security technologies & processes with focus on cloud security. Support key business and tech projects related to Cloud Transformation.
Providing appropriate support activities such as patches, upgrades, break fix and improvements
Providing appropriate cloud security engineering and support activities such as patches, upgrades, enhancements
Providing metrics and periodic updates on various projects assigned
Investigating, documenting, and reporting on information security issues and emerging trends related to cloud environments globally
Optimize existing automation solutions for performance and reliability.
Staying updated with the latest technologies and tools in automation and continuously improving skills.
Other
Attend scheduled meetings with Team Lead/Department/Town Hall representation
Become familiar with company methodologies
Actively participate with Team Lead in creating personal development plan
Provide the Team Lead with ideas to enhance or improve team processes and procedures and ensure agreed procedures are followed
Attend scheduled training sessions
Administrative activities – time sheets/compliance requests
The Experience You Bring: Work Experience / Knowledge:0 - 2 years’ experience in an information security role, supporting security programs and security engineering/architecture in complex enterprise environments0 - 2 years of hands-on experience designing, configuring, and implementing enterprise-wide Cloud security solutions across AWS, Azure, Oracle and other major cloud providers, including microservices security1 year practical experience working in DevSecOps team with applied Agile development methodologyExperience with cloud deployment orchestration, automation, and security configuration managementProficiency in one or more scripting languages such as Python and Powershell, including JSONExperience with blueprints, patterns, and guidelines that standardize and accelerate organizational cloud adoption and align to industry compliance frameworks such as SOX, PCI-DSS, HIPPA, NIST, ISO, GDPR, SOC1/2, etc.Knowledge of various security methodologies and processes, and technical security solutions, such as Prisma Cloud, Wiz, Container security, McAfee CASB, SIEM (Qradar/Splunk), IAM, Virtual Palo Alto, and other workload protection and security solutionsundefined
Formal Education:BTech in Computer Science or Bachelor's degree in Computer Science