
Senior Vice President, Senior Cloud Security Engineer
BNY Mellon4 months ago
Base Salary
$83k - $209k/yr
Responsibilities
- Lead the implementation and continuous improvement of cloud security controls across AWS, Azure, or GCP.
- Implement controls for IAM, network security, encryption, key management, secrets management, logging, monitoring, workload protection, containers, Kubernetes, APIs, and cloud-native workloads.
- Drive CSPM maturity using Wiz or similar platforms and native cloud policy and posture services to detect, prioritize, and remediate misconfigurations, exposure risks, excessive permissions, and policy violations.
- Design and implement policy-as-code, automated guardrails, and infrastructure-as-code patterns using tools such as OPA/Rego and Terraform.
- Align technical controls with NIST SP 800-53 and enterprise security requirements, and strengthen control evidence, traceability, and consistency.
- Partner with cloud engineering, DevSecOps, IAM, platform, architecture, application, and cyber teams to embed secure patterns into engineering workflows.
- Provide senior technical guidance on secure cloud implementation, standards adoption, exception handling, remediation priorities, and risk-based decision-making.
- Support cloud security strategy, governance forums, audits, regulatory reviews, metrics, reporting, and documentation.
- Identify and promote responsible AI use cases for threat detection, posture analysis, risk prioritization, automation, incident response, and security operations.
- Use and improve cloud-native policies, Wiz rules, KQL, Splunk, Microsoft Sentinel, Log Analytics, Bash, PowerShell, gcloud, Terraform, and GitLab in an enterprise setting.
Requirements
- 6–10 years of experience in cloud security engineering, security engineering, DevSecOps, infrastructure security, or a related security engineering role.
- Strong hands-on experience securing workloads and services in AWS, Azure, or GCP.
- Strong knowledge of IAM, networking, encryption, secrets management, logging, workload protection, resilience, and secure cloud service consumption.
- Experience implementing cloud security controls at scale in enterprise or regulated environments.
- Strong familiarity with NIST SP 800-53, MCSB, and related control areas including access control, audit and accountability, configuration management, identification and authentication, incident response, risk assessment, communications protection, and information integrity.
- Strong understanding of CSPM, including continuous compliance monitoring, misconfiguration detection, exposure analysis, remediation, and governance workflows.
- Experience with CSPM/CNAPP platforms such as Wiz, Prisma Cloud, Orca, Lacework, or similar tools.
- Experience with AWS Config, AWS Security Hub, AWS Organizations SCPs, Azure Policy, Microsoft Defender for Cloud, GCP Organization Policy, or Google Security Command Center.
- Experience developing or supporting policy-as-code and automated guardrails using OPA/Rego or equivalent frameworks.
- Strong experience with infrastructure as code and automation using Terraform, CloudFormation, ARM, Bicep, Python, or similar tooling.
- Experience with container and Kubernetes security, API security, vulnerability management, security automation, orchestration, analytics, and AI-driven security tooling.
- Experience supporting cloud security strategy, governance, standards, exception handling, remediation tracking, risk reporting, architecture reviews, or cloud governance processes.
- Bachelor’s degree in computer science, engineering, cybersecurity, or a related discipline, or equivalent practical experience.
- Experience in a regulated industry such as financial services.
- Familiarity with CIS Benchmarks, CSA CCM, OWASP, or NIST CSF.
- Relevant certifications such as AWS Security Specialty, Azure Security Engineer Associate, Google Professional Cloud Security Engineer, or CCSP are preferred.
- Strong technical judgment, problem-solving, written and verbal communication, and cross-functional collaboration skills.
Benefits
- The role is based in New York, NY or Pittsburgh, PA.
- BNY offers competitive compensation, benefits, wellbeing programs, flexible global resources, generous paid leave, and paid volunteer time.
- Benefits and programs support employee health, resilience, financial goals, and family needs.