Logo of Huzzle

Cloud Security - Threat Model Architect, VP (C13)

image

Citi

19d ago

  • Job
    Full-time
    Senior Level
  • Software Engineering
  • $125.8K - $188.6K
  • Irving, +1

AI generated summary

  • You need 5+ years in Cloud tech and 3+ in Cybersecurity, strong Cloud Security Architecture skills, Threat Modeling experience, scripting knowledge, and relevant certifications for this VP role at Citi.
  • You will review cloud architectures, identify threats, specify controls, maintain threat models, deliver tasks, provide feedback, train team members, develop automation tools, and work independently.

Requirements

  • Minimum requirement of 5 years' experience working on Cloud technology with at least 3 years' experience in Cybersecurity/Information Security
  • Strong experience with Cloud Security architecture in Cloud environments (AWS, Azure/M365, GCP)
  • Exposure to and firm understanding of Threat Modeling (STRIDE, PASTA, MITRE Att&ck, Attack trees, tooling, etc.) in Cloud environments (AWS, Azure/M365, GCP)
  • Exposure to security practices pertaining to authentication, authorization, logging/monitoring, encryption, infrastructure security, network/segmentation
  • Jira or other ticketing systems
  • Strong understanding of scripting languages, Infrastructure as Code (Terraform, CloudFormation/CFT)
  • Exposure to design and ability to review technical architectures
  • Identifying vulnerabilities using CWE or OWASP
  • Certification requirements as detailed below
  • Education:
  • Bachelor's degree in computer related field or equivalent work experience
  • Ideal candidate is expected to have a foundational or practitioner level cloud certification from either AWS, GCP or Azure
  • Certifications:
  • Ideal candidate must have 1 or more foundational cybersecurity certification(s) as defined below:
  • Associate level cloud certification:
  • AWS Certified Developer, AWS Certified Solutions Architect, AWS Certified SysOps Administrator
  • CompTIA Cloud+
  • Google Associate Cloud Engineer or other professional GCP certification
  • Oracle Cloud Infrastructure Certified Architect Associate, Oracle Cloud Infrastructure Certified Cloud Operations Associate
  • Microsoft Certified: Azure Developer Associate
  • Associate or professional cybersecurity:
  • ISACA Certified Information Systems Auditor (CISA)
  • GIAC Security Essentials (GSEC)
  • ISC2 Systems Security Certified Practitioner (SSCP)
  • CompTIA CySA+
  • Microsoft Certified: Security Operations Analyst Associate; Information Protection Administrator Associate

Responsibilities

  • Review Cloud architectures to identify security threats using a documented process
  • Maintain a high standard of work in identifying threats and specifying mitigating controls
  • Attending to the lifecycle of identified threats and controls
  • Delivery of threat models and supporting tasks within existing timeframes
  • Provide feedback, support, and improvements to the existing threat modeling process
  • Present work to seniors, the team, and other technical teams
  • Train newer members of the team
  • Development of automation tools as required
  • Work with little supervision to complete work

FAQs

What are the main responsibilities of a Cloud Security - Threat Model Architect, VP?

The main responsibilities include reviewing Cloud architectures to identify security threats, maintaining a high standard of work in specifying mitigating controls, attending to the lifecycle of identified threats and controls, delivering threat models within existing timeframes, providing feedback and support to the existing threat modeling process, presenting work to seniors and technical teams, training newer team members, developing automation tools as required, and working with little supervision to complete tasks.

What qualifications are required for this role?

The qualifications include a minimum of 5 years' experience working on Cloud technology with at least 3 years' experience in Cybersecurity/Information Security, strong experience with Cloud Security architecture in AWS, Azure/M365, GCP, exposure to and understanding of Threat Modeling in Cloud environments, knowledge of security practices such as authentication, authorization, encryption, etc., experience with scripting languages and Infrastructure as Code, familiarity with design and technical architectures, identifying vulnerabilities using CWE or OWASP, and relevant certifications.

What education is needed for this position?

A Bachelor's degree in a computer-related field or equivalent work experience is required. Ideally, the candidate should have a foundational or practitioner level cloud certification from AWS, GCP, or Azure.

What certifications are required for this role?

Ideal candidates must have one or more foundational cybersecurity certifications, such as AWS Certified Developer, CompTIA Cloud+, Google Associate Cloud Engineer, ISACA CISA, GIAC GSEC, ISC2 SSCP, etc.

Finance
Industry
10,001+
Employees
1998
Founded Year

Mission & Purpose

Citigroup Inc. or Citi is an American multinational investment bank and financial services corporation headquartered in New York City. Citi's operation is to provide financial services that enable growth and economic progress. Core activities are safeguarding assets, lending money, making payments and accessing the capital markets.

Benefits

  • Live Well, Stay Healthy

    Citi provides programs and services for your physical and mental well-being including access to telehealth options, health advocates, confidential counseling and more. Coverage varies by country.

  • Paid parental leave

    We believe all parents deserve time to adjust to parenthood and bond with the newest members of their families. That’s why in early 2020 we began rolling out our expanded Paid Parental Leave Policy to include Citi employees around the world.

  • Save well, for now and your future

    We empower our employees to manage their financial well-being and help them plan for the future.

  • Keep learning

    Citi provides access to an array of learning and development resources to help broaden and deepen your skills and knowledge as your career progresses.

  • Be well, take time off

    We have a variety of programs that help employees balance their work and life, including generous paid time off packages.

  • Support Your Community

    We offer our employees resources and tools to volunteer in the communities in which they live and work. In 2019, Citi employee volunteers contributed more than 1 million volunteer hours around the world.