United States - Hybrid•United States (East Coast Time Zone) - Remote
Remote
Senior
Full Time
about 1 month ago
💰$209,664 - $220,699
cloud securityGCPAWSTerraformDataDogInfrastructure as CodeJust-in-Time accessincident responseremote workhybrid work
Requirements
- •Extensive experience in Cloud Security with deep expertise in GCP and AWS
- •Strong understanding of Threat Modelling principles and their application to cloud infrastructure and architectural designs
- •Hands-on experience with cloud security tools and technologies including DataDog for security monitoring and Terraform for Infrastructure as Code
- •Proven experience in designing, implementing, and managing cloud security controls and configurations
- •Experience with Identity and Access Management (IAM) in cloud environments including implementation and management of Just-in-Time (JIT) access solutions
- •Proven ability to establish and manage incident response programs specifically for cloud environments
- •Comfortable explaining technical security concepts, vulnerabilities, and mitigations to diverse audiences
- •Self-motivated and able to work independently and effectively in a remote setting while maintaining a team-focused mindset
- •Highly skilled in documenting security processes and configurations and sharing knowledge with other teams
What You'll Do
- •Perform Threat Modelling of architectural infrastructure changes and new cloud infrastructure and Kubernetes deployments in GCP and AWS
- •Design, implement, and manage robust security controls and configurations for GCP and AWS environments
- •Develop and maintain secure Infrastructure as Code (IaC) using Terraform and tools
- •Implement, manage, and enhance Cloud Security monitoring using DataDog, including alert configuration and response procedures
- •Implement and manage Just-in-Time (JIT) access solutions for elevated privilege access to cloud resources
- •Establish and manage the cloud incident management process and program, including leading incident response activities for cloud security events
- •Collaborate with infrastructure and development teams to integrate cloud security best practices throughout the infrastructure lifecycle
- •Research and evaluate emerging cloud security threats and vulnerabilities, and develop effective mitigation strategies
- •Develop and deliver cloud security training and awareness programs to engineering and relevant teams
- •Contribute to the development and maintenance of cloud security standards, policies, and documentation
- •Manage the future of cloud security posture, driving continuous improvement and strategic initiatives
- •Accurately document cloud security configurations, processes, and knowledge, and disseminate this information to other teams
- •Conduct vulnerability assessments and drive remediation for cloud infrastructure
- •Support requirements and evidence requested from auditors, compliance and regulators
Nice to Have
- •Proficiency in scripting or programming languages relevant to cloud automation and security (e.g., JavaScript, Python, Go)
- •Good understanding of cryptography and its applications in cloud security
- •Contributions to the security community (e.g., open source projects, conference talks, CTFs)
- •Relevant security certifications (e.g., GCP Professional Cloud Security Engineer, AWS Certified Security - Specialty, SANS)
- •Background experience in disruptive technology environments such as FinTech, SaaS, or Crypto
Benefits
- •Competitive salary package
- •Equity package with employee ownership at MoonPay
- •Pay for performance equity bonus
- •Moonshot award with $250,000 equity grant for exceptional impact
- •Unlimited holidays
- •Hybrid working schedule with option to work fully remotely or at nearest Moonbase
- •Private Healthcare benefits
- •Enhanced parental leave
- •Annual training budget
- •Home office setup allowance
- •Remote working allowance
- •Monthly budget to spend on company products and zero fee crypto transactions
- •Employee referral programme with $10K in USDC
- •Regular remote company offsites
