Roche – Cloud Security Engineer specializing in Cloud Workload ProtectionJob ResponsibilitiesCloud Workload Protection (CWPP): Architect, deploy, and manage Cloud Workload Protection Platforms across multi-cloud environments (AWS, Azure, and/or GCP).Container & Kubernetes Security: Implement runtime defense, vulnerability scanning, and configuration hardening for containerized applications and orchestration platforms (EKS, AKS, GKE).Extending Core Services to the Cloud: Adapt our existing strategies for EDR and Application Control to function effectively in ephemeral, cloud-native workloads without degrading performance.DevSecOps Integration: Embed security controls directly into CI/CD pipelines (Shift-Left), ensuring images, registries, and Infrastructure as Code (IaC) templates are scanned and secured before deployment.Automated Remediation:
Develop automated response playbooks for cloud misconfigurations and workload alerts using serverless functions and native cloud APIs.QualificationsBachelor's degree in Computer Science, Software Engineering, Cybersecurity, or equivalent practical experience.3+ years of dedicated experience securing public cloud workloads, with a strong understanding of the shared responsibility model.Deep technical knowledge of Docker, Kubernetes, and container orchestration; ability to secure a pod, restrict container privileges, and manage network policies.Proven, hands-on experience deploying and tuning cloud security platforms (CWPP / CNAPP).Strong grasp of cloud-native networking (VPCs, Security Groups) and Identity and Access Management (least-privilege roles, service accounts).Proficiency in written and spoken English (C1 or above).
#J-18808-Ljbffr