Cloud Security Vulnerability Management Program Specialist

Bank of America Bank of America · Banking · Denver, CO +2

This role focuses on cloud security vulnerability management within an enterprise environment, ensuring secure configurations and continuous monitoring of cloud workloads across hybrid and multi-cloud setups. It involves identifying vulnerabilities, misconfigurations, and suspicious runtime activities, partnering with infrastructure and DevOps teams for remediation, and providing risk-based reporting. The role supports audit and regulatory requirements and contributes to workload security standards.

What you'd actually do

  1. Ensure cloud workloads are protected and monitored in alignment with CSA security standards and defined baselines.
  2. Maintain continuous visibility into workload security posture across virtual machines, containers, and compute platforms.
  3. Identify workload vulnerabilities, misconfigurations, and insecure operating system or platform settings.
  4. Monitor runtime activity to detect suspicious behavior, privilege escalation, policy violations, and drift from security baselines.
  5. Build, maintain, and tune vulnerability detections aligned to vulnerability management and runtime protection requirements.

Skills

Required

  • Understanding of Cloud Native security concepts and runtime security principles.
  • Experience identifying and managing workload vulnerabilities and insecure configurations.
  • Knowledge of cloud compute services, operating systems, and containerized workloads.
  • Familiarity with vulnerability management and runtime detection techniques.
  • Strong analytical, documentation, and collaboration skills.

Nice to have

  • Experience supporting cloud or workload security assurance programs.
  • Hands-on experience with Cloud Security Vulnerability Management tools (e.g., Aqua, Prisma Cloud, Wiz, Defender).
  • Familiarity with Linux security fundamentals.
  • Experience supporting audit or compliance-driven security reviews.
  • Bachelor’s degree in a technical or security-related field.
  • Relevant cloud or security certifications preferred.

What the JD emphasized

  • enterprise cloud workloads
  • runtime lifecycle
  • workload-level vulnerabilities
  • insecure configurations
  • runtime behaviors
  • hybrid and multi-cloud environments
  • workload security posture
  • virtual machines, containers, and supporting compute services
  • vulnerability assessment
  • configuration validation
  • runtime monitoring
  • security baselines
  • suspicious or policy-violating activity
  • cloud workload architectures
  • operating system security fundamentals
  • shared responsibility models
  • risk and prioritize remediation
  • infrastructure, platform, engineering, and operations teams
  • vulnerability findings
  • actionable, risk-assessed, and remediated
  • workload security maturity
  • Cloud Security tooling
  • audit and regulatory requirements
  • risk-based reporting
  • workload security posture
  • fast-paced, enterprise-scale environments
  • workload security standards, baselines, and documentation
  • consistent governance and assurance
  • in-scope compute platforms