Cloud Security Analyst
Posted 1 hour 33 minutes ago by Uniting Holding
Reporting to: Senior IT Security Manager
About the RoleWe're looking for a hands on Cloud Security Analyst with deep expertise in cloud native and container security. This role sits at the core of securing large-scale, multi cloud and Kubernetes driven environments.
You will play a critical role in defining security standards, implementing hardened baselines, and enhancing detection and response capabilities-working closely with DevOps, Networking, and SOC teams to embed security into every layer of design and automation.
Key ResponsibilitiesStrengthen and optimize cloud-native security controls across IAM, network security (WAF, VPC), and data protection (KMS, Vault)
Deploy and manage CSPM, CNAPP, and CWPP solutions to maintain continuous security posture across multi cloud and Kubernetes environments
Integrate cloud telemetry (GCP Audit Logs, AWS CloudTrail, Azure Monitor, Kubernetes audit logs) into SIEM/SOAR platforms for centralized visibility
Define and enforce cloud security architectures and guardrails aligned with Zero Trust and Least Privilege principles
Develop and maintain Security-as-Code practices using Terraform, CloudFormation, or Bicep, including policy-as-code frameworks
Own and enhance the security posture of containerized environments (GKE, AKS, EKS), including image, registry, and runtime security
Harden Kubernetes clusters through RBAC, NetworkPolicies, Admission Controllers, and secure configurations
Lead cloud security incident response activities including triage, containment, and forensic investigations
Continuously monitor emerging threats, vulnerabilities, and attack vectors within cloud-native ecosystems
Experience
5+ years in Information Security
Minimum 3+ years in Cloud Security
At least 2+ years working with Kubernetes / container security
Cloud Expertise
Hands on experience with at least two major cloud platforms (GCP and Azure preferred; AWS/OCI a plus)
Container & Kubernetes Security
Strong understanding of Kubernetes security controls (RBAC, Secrets, Ingress, TLS)
Familiarity with container runtime security and orchestration
Technical Skills
Proficiency in scripting (Python preferred; Bash or Go is a plus)
Working knowledge of Infrastructure as Code (IaC) and automation
Security Frameworks & Compliance
Knowledge of ISO 27001, SOC 2, NIST, and CIS Benchmarks
Certifications (Preferred)
CISSP
CKS (Certified Kubernetes Security Specialist)
GCP Professional Cloud Security Engineer
Microsoft Azure Security Engineer / Cybersecurity Architect
AWS Certified Security - Specialty
Soft Skills
Strong stakeholder management and ability to influence engineering teams
Experience working in global or multi-national environments
Experience securing microservices, APIs, and serverless architectures
Background in penetration testing or red teaming (cloud/container focus)
Experience in large-scale SaaS, networking, or cloud-first organizations
Additional certifications across GCP, Azure, AWS, or OCI
Kubernetes certifications such as CKA or advanced security-focused credentials