Cloud Security Engineer
Role details
Job location
Tech stack
Job description
Cloud Security Engineer, AXA DCP Location: London - UK / Paris - France / Milan - Italy / Barcelona or Madrid - Spain / Wroclaw - Poland
AXA's Management Committee is driving a unique strategic initiative - Digital Commercial Platform (DCP) - designed to transform AXA's value proposition. Through DCP, AXA will serve existing and new clients and partners through an evolving business model, where the focus is on risk prediction, prevention and management.
AXA DCP relies on creating a platform of AXA's risk insights, risk management, and risk prevention capabilities to enhance and support our service offering to commercial clients and third parties. End users will be able to access a broad selection of data built on existing or developing AXA assets. The platform will also create value by monetizing unique capabilities and services for our customers, aggregating, and delivering insights from unique data sets with external partners, and fostering end-customer relationships in alignment with brokers.
AXA DCP aims to:
- Improve our underwriting pricing and claims capabilities across the commercial lines book of business of AXA Group
- Create a platform for risk management and prevention services
- Build an ecosystem of business partners
As Cloud Security Engineer, your main mission will be to ensure the security and integrity of our applications and infrastructure in the cloud. You will be responsible for implementing and supervising security architectures and controls throughout the software development lifecycle, collaborating closely with development and operations teams to enforce security standards.
DISCOVER your opportunity What will your essential responsibilities include?
- Act as a trusted advisor for solution architects and development teams, providing approval and guidance on secure practices and patterns
- Conduct security assessments and audits, identifying potential risks in software and cloud blueprints and proposing improvements
- Design, maintain and integrate security into the CI/CD pipeline, automating security checks and testing processes following the principle "Shift Left"
- Establish and monitor KPIs and KRIs related to infrastructure and application security in an AWS context.
- Engage with stakeholders (especially Technology office, Product Office and data management team) to facilitate and manage resolution, with tracking of work to report on progress
- Utilize a variety of DevSecOps tools (Qualys WAS, CheckMarks SCA for SAS & DAST, Checkov) and cloud services (AWS Inspector, GuardDuty, CloudTrail, IAM, Config, SecurityHub, WAS Manager) to identify, assess, prioritize and manage security vulnerabilities across the organization's applications, systems and networks to automate and standardize configurations
- Foster strong partnerships with other teams (internal and external) to enhance the organization's overall security posture and minimize potential threats and to identify threats, vulnerabilities, and control improvements
- Support the stakeholders to enable informed decision making
- Design, implement and improve secure coding related practices, processes and standards
- Collaborate with development and operations teams to implement security controls and best practices in the development and deployment processes
- Participate in development and continuous improvement of security processes, policies, standards and other governing documents and ensure compliance.
- Participate in and support delivery of security audits, threat modelling and assessments and remediation of findings
- Participate to AXA DCP Architecture Review Board and other governance bodies/meetings related to Security activity
- Perform in-depth analysis of application code and infrastructure, architecture, and configurations to ensure compliance with security standards
- Assist in the investigation and resolution of security incidents in Production and Non Production environments
- Define and implement Infrastructure as Code patterns and practices using Terraform in the context of AWS
You will report to the Chief Security Officer, AXA DCP.
Requirements
-
General skills
-
At least 6 years of proven experience in IT security engineering, cloud security engineering or related roles (offensive security, blue team, red team, etc)
-
Good understanding of security standards such as ISO 27001, GDPR, OWASP Top 10, OWASP SAMM, OWASP ASVS, common web application vulnerabilities and security best practices (API Security, Container Security, Cloud Security)
-
Knowledgeable with some hands on experience on everything related to security on Amazon Web Services (AWS)
-
Experience with security architecture, Cloud technology and threat modelling
-
Self driven qualities and able to work independently with a high degree of autonomy, as well as part of a team
-
You are fluent in English
-
Good communication (verbal/written) and influencing skills, with an ability to manage internal and external relationships up to senior levels of management
-
Will be a plus:
-
Security Certifications (e.g., CISM, CISSP)
-
Cloud Certifications (e.g. AWS Solutions Architect level Associate or higher, AWS Security Specialty)
-
Auditing and Compliance Certifications (e.g., CISA)
-
Experience with machine learning tools and models
-
Cloud Security (Ideally in AWS)
-
Strong technical understanding of Cloud Security using serverless and containerized architectures
-
Experience with scalable secure architectures for applications and networks deployed in cloud environments
-
Significant knowledge on implementing tools and processes to improve automation and potential vulnerabilities and risks
-
Experience using Infrastructure as Code engines, such as Terraform, in cloud environments
-
Application development
-
Experience application development in Python and TypeScript/JavaScript that are the main programming languages used by the team
-
Experience in relational and NoSQL databases
-
Experience in secure software development practices