Cloud Security Lead

Island Island · Enterprise · Tel Aviv, Israel · Engineering

This role focuses on designing, implementing, and enhancing the security of a company's cloud infrastructure and enterprise browser. Responsibilities include cloud security architecture, hardening, security engineering and automation, monitoring, incident response, and security enablement. Requires deep expertise in secure cloud architectures, DevSecOps, scripting, detection engineering, and CSPM tools.

What you'd actually do

  1. Design and enforce security baselines, configurations, and reference architectures across our multi-cloud footprint (AWS/GCP/Azure). Evaluate new cloud services and features for security implications and create hardened deployment standards for IaaS, PaaS, and serverless components.
  2. Develop and deploy security-as-code solutions, integrating security controls directly into CI/CD pipelines and leveraging Infrastructure-as-Code (IaC) tools to ensure continuous configuration integrity and compliance. Develop custom automation for detection, alerting, and triage workflows, leveraging cloud SDKs and APIs.
  3. Design, implement, and maintain cloud-native security monitoring solutions (e.g., utilizing services like CloudTrail, GuardDuty, Security Command Center) to ensure comprehensive visibility across the cloud control plane and data plane.
  4. Support the security team in investigating and responding to critical security events and vulnerabilities, creating runbooks, and contributing to post-incident remediation and architectural improvements.
  5. Collaborate with product, engineering, and IT teams to improve security awareness, deliver training, and drive adoption of security best practices across Island, specifically for IaaS, PaaS, and secure DevOps practices.

Skills

Required

  • Secure cloud architecture design
  • Cloud security hardening
  • DevSecOps practices
  • Kubernetes/containerized workload security
  • Cloud identity management (IAM)
  • Security baselines establishment
  • Scripting and automation (Python, Bash, PowerShell)
  • Infrastructure-as-Code (IaC) security
  • Policy-as-code tools
  • Detection engineering
  • Security operations workflows
  • Cloud infrastructure and services protection
  • Cloud Security Posture Management (CSPM) tools
  • Cloud security monitoring solutions
  • Security Information and Event Management (SIEM)
  • Modern attack techniques in cloud environments
  • Threat actor behaviors in cloud environments
  • Vulnerability exploitation patterns in cloud environments

Nice to have

  • Purple teaming
  • Penetration testing of cloud infrastructure
  • Identifying design flaws

What the JD emphasized

  • Deep expertise
  • vulnerability management
  • Cloud Security Posture Management (CSPM) tools