Private Cloud Security Specialist (Container exp. required)
Bank of America · Chicago, IL · 1 wk ago
Information TechnologyFull-time
About the role
This role supports Container Information Security activities for Bank of America, including identifying potential security configuration issues, risks, and vulnerabilities within container environments, and supporting container vulnerability assurance efforts.
Responsibilities
- Support efforts to improve vulnerability identification quality and consistency across container environments.
- Collaborate with teams across Vulnerability Management, Cloud Security, and Container Security to support strategic initiatives and roadmap execution.
- Assist with gap analyses of existing controls, documenting findings and recommendations for improvement.
- Provide technical support and consultation related to container vulnerability identification and remediation activities.
- Learn and evaluate emerging technologies that may support cloud and container vulnerability management capabilities.
- Support audit, risk, and regulatory activities by gathering information and responding to requests.
- Assist engineering teams in addressing security-related technical challenges.
- Demonstrate strong organization, accountability, and a willingness to learn new technologies and processes.
- Support efforts to identify vulnerabilities and misconfigurations in container platforms, Continuous Integration/Continuous Delivery (CI/CD) pipelines, and workloads.
- Assist with the daily operations and administration of container security solutions such as Aqua, Wiz, Qualys, and CrowdStrike.
- Participate in efforts to improve vulnerability identification processes across hybrid cloud platforms.
- Support cloud and container security initiatives aligned with the Bank’s security strategy and industry best practices.
- Assist in the implementation and monitoring of security controls designed to protect company systems and information.
- Conduct research on emerging threats and security trends and share findings with team members.
- Monitor security alerts and assist with investigations of potential threats and vulnerabilities.
- Apply secure-by-design principles and assist with activities focused on identifying vulnerabilities early in the development lifecycle.
- Build partnerships with technology teams by providing operational support and security guidance.
Requirements
- Understanding of container and software supply chain security risks.
- 3+ years of foundational experience in cloud-native services, tools, and architecture.
- Understanding of application security principles.
- Experience or coursework in infrastructure, cloud, or security technologies.
- Familiarity with DevSecOps concepts and CI/CD pipeline security practices.
- Ability to create and maintain technical documentation.
- Basic understanding of threat modeling concepts and security frameworks.
- Familiarity with vulnerability management concepts and security scanning tools.
- Strong analytical and problem-solving skills.
- Ability to work independently on assigned tasks while seeking guidance when needed.
- Strong desire to learn and develop technical expertise.
- Ability to communicate technical concepts clearly to both technical and non-technical audiences.
Qualifications
- Progress toward or interest in obtaining industry certifications such as Security+, CCSP, CISSP, or CISM.
- Cloud or container-related certifications such as AZ-900, AZ-500, AWS Cloud Practitioner, CKA, or similar.
- Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or a related technical field.
- Internship, academic, or hands-on experience with cloud, container, or cybersecurity technologies.
Skills
- Problem Solving
- Information Systems Management
- Threat Analysis
- Critical Thinking
- Customer and Client Focus
- Cyber Security
- Policies, Procedures & Guidelines
- Technology Systems Assessment
- Risk Analytics
- Quality Assurance
- Business Acumen
- Stakeholder Management
- Data Privacy and Protection
- Data and Trend Analysis
Schedule
1st shift (United States of America), 40 hours per week.