Tasks:
collaborate with our customers and suppliers to model security requirements against cloud capabilities.
work closely with engineering teams, program management and senior stakeholders to translate requirements into achievable designs that raise the bar.
function across teams ensuring that the strategic architecture is met across design, implementation, deployment and operation; playing a key role in defining the mechanisms that the company will use to validate how services are meeting all the security operational controls.
work closely with the product and platform engineering teams to architect, implement, and operate effective cloud security controls
Partner with internal IT & Product Engineering stakeholders to assess gaps in products and platforms, design mitigating controls, and train and educate staff on remediations.
Partner with the Business Technology and IAM teams to build a new Access Management and User Access Review system based on Lumos.
Maintain inventory of cloud assets and ensure secure bootstrapping of deployed assets while monitoring for drift and potential threats across product engineering environment.
Design and build the security components of the next phase of Sonder Security Roadmap.
Basic Qualifications:
- 3+ years total technical or security engineering experience with security focus
- 2+ years of AWS or GCP experience implementing security and hardening activities, especially in a large or complex environments
- 2+ years working in a CI/CD DevSecOps environment (Jenkins, Travis, Jira, GitHub, GitLab, etc.)
- Experience with IAM solutions such as Okta and deep knowledge of AWS or GCP IAM and how to configure and maintain least-privilege and segregation of duty across boundaries
- Knowledge and experience with EC2, ECS, S3, LBS, API Gateways, Bastion Hosts, VPC, Cloud Trail, Cloud Watch, Data Dog, SIEM and other cloud technologies
- Nice to Have: Programming in Python or Ruby, Experience with Kubernetes, AWS Certifications, Static and/or Dynamic code analysis tooling, Experience writing SDLC related policy