Cloudera

posted 19 days ago

Full-time - Mid Level
Professional, Scientific, and Technical Services

About the position

Cloudera is seeking a Security Architect to join its Product Security and Application Security team. This role focuses on automating and integrating security practices throughout the software development lifecycle, ensuring the security of Cloudera's products in multi-cloud and on-prem environments. The Security Architect will collaborate with various teams to influence product design, conduct security reviews, and mentor junior team members, all while driving the adoption of security best practices.

Responsibilities

  • Design and deploy new cloud environments using automation.
  • Perform security architecture reviews of new products and features, develop threat models, and perform risk assessments.
  • Work closely with the Site Reliability Engineering (SRE) team to continually monitor and maintain the security of production cloud systems.
  • Develop, refine, and drive the adoption of security best practices.
  • Influence decision-makers and stakeholders to continually raise the bar for security.
  • Develop and deliver security training and outreach to internal development teams.
  • Work collaboratively with the compliance and platform security teams to improve processes and drive changes back into the product design stage for the next new product or feature.
  • Mentor junior members of the Security team in DevSecOps practices and procedures.
  • Mentor security advocates who are embedded in software development teams to understand security principles and best practices.
  • Lead security projects (including security reviews, tool development, and creation of new security practices) with end-to-end ownership.

Requirements

  • Experience performing security reviews, developing and reviewing threat models, and risk assessments against complex systems.
  • Experience with AWS, Azure, and Google Cloud network and security best practices.
  • Experience partnering closely with high-velocity engineering teams.
  • Ability to communicate complicated security concepts with both technical and non-technical audiences.
  • Ability to lead through influence within a Secure Software Development Life Cycle for multiple products and technologies, meeting customer expectations for security.
  • Demonstrated ability to listen to other's diverse points of view and work together to find the best solution.
  • Demonstrated experience working in a situation where you must balance business needs with security risks.
  • Deep understanding of networking principles and how network architecture interacts with security (Standard networking stack, TLS, IPSEC, HTTP, DNS, etc.).
  • Deep understanding of cryptography, web service frameworks, and service architectures (such as event-driven, service-oriented, or serverless architecture).
  • In-depth knowledge of standard attacks and countermeasures.
  • Deep understanding of Kubernetes operations and security.
  • Moderate to advanced Linux knowledge.
  • Experience conducting security assessments, including some familiarity with pentesting.
  • Experience with code review of one or more programming languages (Java, Python, Go, JS/TS).
  • Experience with Terraform, Unix shell scripting, Hashicorp Vault, etc.
  • Knowledge of standard Security Operations Center (SOC) tools.

Nice-to-haves

  • Security certifications (CISSP, CISA, etc.) are a bonus but not required.
  • Familiarity with Cloudera's products or other distributed computing systems is a strong bonus, or a willingness to dig into our products to truly understand how they work.

Benefits

  • Generous PTO Policy
  • Support work life balance with Unplugged Days
  • Flexible WFH Policy
  • Mental & Physical Wellness programs
  • Phone and Internet Reimbursement program
  • Access to Continued Career Development
  • Comprehensive Benefits and Competitive Packages
  • Paid Volunteer Time
  • Employee Resource Groups
Job Description Matching

Match and compare your resume to any job description

Start Matching
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service