
Cloud Security Remediation Specialist
- Barcelona
- Permanente
- Tiempo completo
- Manage Wiz CNAPP to ensure availability and functionality of the solution and its integrations.
- Identify cloud security risks and vulnerabilities.
- Support Cloud and Application/Development teams to ensure secure deployment of applications and infrastructure in the cloud by providing guidance on cloud security best practices.
- Advocate for security awareness and educate stakeholders across the organization on cloud security.
- Keep track of and report cloud security KPIs.
- Ensure cloud security alignment with internal policies and standards.
- Education: Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience.
- Industry certifications such as Microsoft Certified: Azure Security (AZ-500), Microsoft Azure Administrator (AZ-104), or other relevant qualifications.
- Minimum of 3 years of experience in cloud security, ideally within Microsoft Azure environment.
- Familiarity with ITIL best practices within a professional setting.
- Prior experience with regulatory compliance and industry standards in a public cloud context.
- Good understanding of cloud computing security concepts, including architecture, governance, compliance, and operations and service types (e.g. IaaS, PaaS and SaaS).
- Prior working experience using CNAPP or CSPM tools, ideally Wiz.
- Understanding of Azure Identity and Access Management (IAM), including RBAC, encryption options, logging, networking and data protection mechanisms in Azure.
- Familiarity with security standards and frameworks such as ISO 27001, NIST CSF, CIS Benchmarks and similar.
- Ability to create and maintain comprehensive documentation of security and remediation activities.
- Working experience with ServiceNow for change management.
- Experience with Terraform or other IaC tools would be considered an advantage.
- Hands-on experience with Oracle OCI and Google GCP cloud platforms would be considered an advantage.
- Self-organized and able to work independently and make decisions under minimal supervision.
- Strong analytical skills to evaluate the effectiveness of security measures.
- Committed to staying current with emerging security threats and technologies.
- Good communicator: able to explain security misconfigurations and their impact to non-technical stakeholders.