Job Details

ID #51918213
Estado Virginia
Ciudad Reston
Full-time
Salario USD TBD TBD
Fuente FANNIE MAE
Showed 2024-06-16
Fecha 2024-06-17
Fecha tope 2024-08-16
Categoría Etcétera
Crear un currículum vítae
Aplica ya

Cloud Security Architecture Principal (Hybrid)

Virginia, Reston, 20190 Reston USA
Aplica ya

Job Description As a valued contributor to our team, you will consult with management on the development of processes and procedures for designing and implementing components of technological structures. In this role, you will create solutions with a process-driven view, as well as maintain and/or update existing structures. THE IMPACT YOU WILL MAKEThe Cloud Security - Architecture - Principal will leverage broad technical knowledge of cloud security best practices of key public cloud offerings of providers such AWS, Azure, and GCP to establish secure design patterns, to architect integrations among cloud and/or on-premises infrastructures. The individual must have deep understanding of cloud policy, security technical architecture and have implemented solutions in a cloud environment. Knowledge of industry best practices around cloud security compliance and architect cloud security practices. This individual must be able to assist in ensuring the security and compliance of the cloud environment based on enterprise cloud security policies, standards, and procedures. The role will ensure that solutions operating on the cloud comply with enterprise security requirements in both off-premises and hybrid environment models. The role will report to the Director of Cloud Security Architecture will collaborate with Enterprise Architects and Application Dev teams to come up with Security Architecture for applications and enterprise tech capabilities migrating to Cloud.

Determine the needs of diverse and complex customer groups by applying understanding and resolution of complex or unusual business problems.

Translate functional requirements into technical solutions, and may lead matrixed teams.

Oversee existing structures, as well as the implementation and ongoing monitoring of governance.

Perform modeling, analysis, and planning to solve technical business problems and identify opportunities and risks.

Qualifications THE EXPERIENCE YOU BRING TO THE TEAM Minimum Required Experiences

8 years of experience

Desired Experiences

Bachelor degree or equivalent

5+ Years of experience in Cyber Security field as an Information Security Architect or Cloud Security Architect

4+ years of experience in AWS as a Cloud Security Architect/Engineer and must be certified in the cloud technologies/infrastructures.

Preferred industry recognized experience in security (e.g., CISSP, CCSK, CISA, CISM, CEH)

Minimum of 5 years of experience in IT security risk assessments and related frameworks (e.g., NIST 800 series, ISO 27000 series, IT General Controls

Strong knowledge of the AWS Infrastructure services.

Strong communication, proactive methods for problem solving, strong documentation and collaboration skills across the enterprise.

Excellent coordination skills and must be detail oriented.

Key Areas of Responsibility

Partner with Enterprise/Portfolio Architecture team and Business Units development squads to collaboratively develop security architectures/designs leveraging approved patterns that ensure applications migrating from on-premises to Cloud, achieving high standards of security practices and compliance.

Drive the development and adoption of cloud security standards, best practices, and technologies within Enterprise IT infrastructure

Liaise on security-related issues with internal business stakeholders, InfoSec, Enterprise Architecture, and application development squads.

Work to develop, enhance, and document security architecture, security policies, patterns, procedures, guidelines, and standards required to design cloud-based solutions.

Educate application, portfolio and solution architects on secure solution design and industry best security practices.

Work on assessments of compliance and standards including and not limited to NIST, FedRAMP, FIPS, etc.

Perform threat modeling and update application security architecture as needed.

Support application development squads with Security implementations and issues

Skills

Serve as an expert in Fannie Mae’s Information Security capabilities, solutions policies, procedures, and standards.

Act to apply NIST frameworks on all cloud patterns, capabilities, and application migrations.

Influence technical patterns and capabilities to apply security and cloud policy to shift left in the development processes.

Act as a central point of contact for all conceptual knowledge of regulations for PCI, Sarbanes-Oxley, GLBA, and FISMA

Responsibilities include setting the compliance strategy for infrastructure and application build, deploy, monitor, and operate applications.

Candidate should have architected applications at scale on modern cloud native architectures (AWS).

The candidate needs expertise to architect cloud native infrastructure using containerization and microservices transformation in application APIs and address platform operational security concerns.

Plan and document design methods for the optimization and integration of various technology platforms, tools, policies, and principles that lead to target state implementation with cloud policy and compliance.

Tools

Deep Knowledge in containerization of applications, design, and deployment

Skilled in Amazon Web Services (AWS) offerings, development, and networking platforms

Experience with Agile Tools and methodologies.

Experience in object-oriented programming preferrable JAVA, Python, etc.,

Knowledge of storage software platforms such as NetApp, Nimble, and Pure Storage

Knowledge of ITSM Tools e.g., ServiceNow to manage digital workflows.

Experience using APIs for developing or programming software.

Skilled in CICD Tools and Pipelines

Knowledge of virtualization software such as Microsoft Hyper-V, VMWare vSphere, or Citrix XenDesktop.

Nice-to-Haves

Cloud agnostic security architecture experience a plus

Container Security experience to protect container workloads during build and run-time.

API Security architecture experience with industry standard API Gateways

Security engineering/administration background leveraging SIEM, Network firewalls, host-based security, and security configuration

The group of skills related to Security including designing and evaluating security systems, identifying security threats, securing computers, assessing vulnerability, etc.

The group of skills related to Relationship Management including managing and engaging stakeholders, customers, and vendors, building relationship networks, contracting, etc.

Skilled in presenting information and/or ideas to an audience in a way that is engaging and easy to understand.

The group of skills related to Risk Assessment and Management including evaluating and designing controls, conducting impact assessments, identifying control gaps, remediating risk, etc.

Experience identifying and determining levels of risk to an organization's networks and systems using cybersecurity techniques

Working with people with different functional expertise respectfully and cooperatively to work toward a common goal.

Skilled in cloud technologies and cloud computing

The group of skills related to Influencing including negotiating, persuading others, facilitating meetings, and resolving conflict.

Fannie Mae is an Equal Opportunity Employer, which means we are committed to fostering a diverse and inclusive workplace. All qualified applicants will receive consideration for employment without regard to race, religion, national origin, gender, gender identity, sexual orientation, personal appearance, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation in the application process, email us at [email protected].

Aplica ya Suscribir Reportar trabajo