招聘
必备技能
AWS
Kubernetes
Go
Terraform
GCP
Azure
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
Job Title: Senior Cloud Security Specialist
Role Overview:
The Senior Cloud Security Specialist will serve as a technical leader in cloud security operations, responsible for designing and implementing advanced threat detection and mitigation strategies across multi-cloud environments. This role demands deep expertise in cloud-native and CNAPP technologies, incident response, and forensic investigation. The SME will collaborate with Security Engineering & Architecture, CSOC, and governance teams to ensure a resilient and compliant cloud security posture.
Key Responsibilities:
-
Threat Detection & Investigation
-
Deploy and optimize cloud-native and third-party threat detection platforms (e.g., AWS Guard Duty, Azure Defender, GCP SCC).
-
Investigate alerts using telemetry, behavioral analytics, and AI/ML-based anomaly detection.
-
Align detection logic with MITRE ATT&CK, NIST SP 800-53, and CSA CCM frameworks
-
Rule Creation & CNAPP Integration
-
Author and tune detection rules leveraging CNAPP platforms (e.g., Wiz, Prisma Cloud, Orca).
-
Integrate CNAPP telemetry into SIEM/SOAR workflows for automated response
-
Mitigation Strategy Development
-
Design and implement dynamic playbooks for threat containment and remediation.
-
Collaborate with DevOps and product teams to embed security controls into CI/CD pipelines.
-
Incident Response & Forensics
-
Lead incident triage and root cause analysis across cloud environments.
-
Conduct forensic investigations using cloud-native tools and third-party platforms.
-
Document findings and contribute to post-incident reviews and continuous improvement
-
Security Architecture & Governance
-
Provide guidance on secure cloud architecture, access controls, and data protection.
-
Ensure compliance with ISO 27001, HIPAA, GDPR, and internal governance policies
Required Skills & Abilities:
-
Deep expertise in AWS, Azure, GCP, and OCI cloud security services.
-
Hands-on experience with CNAPP platforms (e.g., Wiz, Prisma Cloud, Orca).
-
Proficiency in threat detection rule creation, tuning and alert response leveraging tools such as Crowd Strike, Wiz Defend, AWS Guard Duty, etc.
-
Respond to Kubernetes and Cloud Container threat alerts (e.g., unusual API invocations) and tune detection rules accordingly
-
Strong knowledge of SIEM/SOAR platforms (e.g., Splunk, Sentinel, Elastic, Tines).
-
Experience in cloud forensics and incident response workflows.
-
Familiarity with infrastructure-as-code (IaC) tools (Terraform, CloudFormation).
-
Strong analytical, investigative, and documentation skills.
-
Excellent communication and leadership abilities.
Preferred Qualifications:
-
8+ years in cybersecurity, with 3+ years focused on cloud security.
-
Certifications: CISSP, CCSP, AWS Security Specialty, Azure Security Engineer, GCIH, GCIA.
-
Experience in a 24x7 SOC or threat management environment.
-
Proven track record of mentoring and leading technical teams.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
总浏览量
0
申请点击数
0
模拟申请者数
0
收藏
0
相似职位

Information Security Engineering Senior Manager
Wells Fargo · ISELIN; IRVING; CHANDLER; SAN FRANCISCO; CHARLOTTE

Senior Product Associate, Fraud - Trust & Security
JPMorgan Chase · Columbus, OH, United States, US

Staff Cloud Security Engineer
Warner Bros. Discovery · Atlanta, Georgia, United States of America

IT Senior Manager - Information Security Office
Enterprise · St. Louis, MO

Sr. WAF Security Engineer
Warner Bros. Discovery · Atlanta, Georgia, United States of America
关于EY

EY
PublicEY, previously known as Ernst & Young, is a British multinational professional services network based in London, United Kingdom. Along with Deloitte, KPMG and PwC, it is one of the Big Four professional services firms.
10,001+
员工数
London
总部位置
评价
3.4
10条评价
工作生活平衡
2.3
薪酬
3.7
企业文化
4.1
职业发展
3.8
管理层
3.2
65%
推荐给朋友
优点
Good learning opportunities and career advancement
Supportive culture and kind people
Professional environment and good benefits
缺点
Long working hours and poor work-life balance
Hectic and taxing work environment
Limited support for interns and technical growth
薪资范围
31,254个数据点
Mid/L4
Mid/L4 · Operations Research Analyst
1,738份报告
$142,571
年薪总额
基本工资
$136,899
股票
-
奖金
$5,673
$100,128
$203,912
面试经验
7次面试
难度
3.0
/ 5
时长
14-28周
录用率
57%
面试流程
1
Application Review
2
HR Screen
3
Hiring Manager Interview
4
Technical/Case Interview
5
Partner/Director Interview
6
Offer
常见问题
Behavioral/STAR
Case Study
Technical Knowledge
Past Experience
Culture Fit
新闻动态
Five questions banks must ask to unlock tech value - EY
EY
News
·
3d ago
Five hallmarks of effective AI strategies in banking - EY
EY
News
·
3d ago
How a healthcare company tackles third-party risk with tech and data - EY
EY
News
·
3d ago
Alum sues GW, former employer alleging discrimination, defamation after graduation speech - The GW Hatchet
The GW Hatchet
News
·
4d ago