Cloud Security Expert (GCP)
leadtech
- España
- Permanente
- Tiempo completo
- Monitor networks: and systems for suspicious activity or unauthorized access.
- Analyze security alerts: and investigate potential security incidents.
- Conduct threat hunting: to identify and address potential threats before they cause damage.
- Perform vulnerability assessments: to identify weaknesses in computer systems and networks.
- Conduct penetration testing: to simulate attacks and evaluate the effectiveness of security measures.
- Evaluate compliance: with regulatory requirements and industry standards
- Respond to security breaches, investigating the cause and mitigating damage in real-time.
- Document incidents: and provide reports to management and other stakeholders.
- Develop and implement: security policies, procedures, and best practices.
- Advise management: on cybersecurity risks and provide recommendations for improvement.
- Stay current: on the latest cybersecurity trends, threats, and new security technologies.
- Bachelor/ Master's degree in Cybersecurity, Information Security, Computer Science, or a similar discipline
- Knowledge of Security frameworks such as ISO 27001, NIST, CIS, SOC2, OWASP
- Knowledge of technical concepts such as cloud computing, code review, application security, cryptography with expertise in GCP (Google Cloud Platform)
- Familiarity with attack and exploitation techniques involving operating systems, applications, and devices (CISSP, Comptia, CEH)
- Understanding of security in mobile & web application development including:
- Secure coding practices (input validation review, code obfuscation, etc)
- Authentication & authorisation
- Data protection (encryption, key management, etc)
- Update & Monitoring
- Understanding of security best practices for data and systems protection
- Familiarity with vulnerability scanning tools such as SonarQube, AWS Inspector, Qualys, Nessus, others is a plus
- Knowledge of programming and scripting languages such as Java and PhP
- Ability to evaluate, track, and manage information security threats and vulnerabilities in situations where analysis of well-understood information is required.
- Understanding and ability to perform pentest over applications and to identify and assess attack vectors on different applications
- Strong analytical and problem-solving skills
- Effective communication skills to collaborate with cross-functional teams
- Ability to report and create KPIs for the Security Department
- Familiarity with ticketing tools such as Jira
- Expertise in Security applied to Cloud Computing.
- Knowledge in GCP is a must. Any certification in GCP and/or AWS is a plus
- Relevant certifications, such as CompTIA Security+, Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or others is a plus
- Top-notch private health insurance — includes dental and psychological services
- Full-time, permanent contract
- Flexible time off, no blackout dates, plus your birthday, Christmas’ Eve and New Year’s Eve off
- Remote work OR come into the office if you prefer!
- Flextime (7 – 9:30 a.m. / 3:30 – 7:30 p.m)
- Free Friday afternoons (a 7-hour workday!) + 35-hour week in July and August (free afternoons here we come!)
- Enhanced career path designed just for you
- External training budget
- Other: ticket restaurant, nursery tickets
- Budget for team-building activities
- We celebrate all company landmarks