Aws Cloud Security Assurance Manager

Bank of America Bank of America · Banking · Charlotte, NC +4

Manager for AWS Cloud Security Assurance program, focusing on strategy, governance, risk management, and vulnerability identification within AWS environments. Leads a team of cloud security specialists and collaborates with various engineering and risk teams.

What you'd actually do

  1. Design and execute the Cloud Security Assurance (CSA) strategy for AWS environments in alignment with enterprise security objectives and cloud adoption goals.
  2. Integrate CSA activities with cloud governance routines, ensuring consistent governance, transparency, and leadership visibility into cloud risk and control effectiveness.
  3. Maintain ongoing visibility into the cloud business roadmap to anticipate emerging risks, influence secure architecture decisions, and align security priorities with business initiatives.
  4. Drive cloud security technology requirements and lead technology initiative efforts, including tool selection, implementation, integration, and operational maturity.
  5. Provide oversight of vulnerability identification, security posture management, and vulnerability analysis processes across AWS accounts, regions, and services.

Skills

Required

  • Deep understanding of AWS native services, architectures, and security controls.
  • Strong knowledge of cloud security posture management, vulnerability management, and workload protection concepts.
  • Experience integrating cloud security assurance with governance, risk, and compliance frameworks.
  • Working knowledge of cloud threat landscapes, attack paths, and risk based prioritization.
  • Experience leading CSPM, CWPP, and related cloud security platforms and tooling.
  • Understanding of DevSecOps practices and integration of security controls into CI/CD pipelines.
  • Ability to translate technical cloud risk into clear business impact for leadership and audit audiences.
  • Proven experience leading and developing technical security teams.
  • Strong analytical, qualitative, and quantitative reasoning skills.
  • Ability to operate independently on complex, high visibility initiatives.
  • Excellent written and verbal communication skills, with the ability to influence across technical and non-technical audiences.

Nice to have

  • CISSP, CISM, CCSP
  • AWS Security Specialty or equivalent cloud security certifications
  • SANS or GIAC cloud and security certifications
  • Experience supporting regulated environments and audit engagements
  • Bachelor’s degree in a technical or security related field

What the JD emphasized

  • AWS native services
  • cloud security posture management
  • vulnerability management
  • cloud governance
  • risk management
  • DevSecOps practices
  • regulated environments