At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism. We give our best effort to our work, and we put people first. We're looking for people who are determined to make life better for people around the world.
What You'll Be Doing:
As a Cloud Security Engineer at Lilly on the Security Architecture and Engineering team, you will play a pivotal role in a dynamic environment. Your responsibilities include managing cloud security tools (CNAPP/CSPM), conducting security reviews of cloud accounts and projects, generating proactive guidance, reviewing and creating IaC/policy as code templates, and participating in cloud design discussions. You will also contribute to the development and implementation of cloud security controls, create integrations and automations for cloud security detection and response actions, and collaborate with various stakeholders across the organization.
How You'll Succeed:
* Technical expertise: As a Cloud Security Engineer, you will leverage your deep technical knowledge of cloud ecosystems (AWS or Azure) to implement tailored security solutions and effectively mitigate threats and risks.
* Problem-solving skills: Adept problem-solving abilities are crucial in quickly identifying and addressing security issues, ensuring the development and delivery of robust cloud security solutions in a timely manner.
* Collaboration and communication skills: You will actively collaborate with both local and remote team members, playing a pivotal role in defining, designing, and executing cloud security strategies. Excellent communication skills are essential for this role, as you will need to engage with both technical and non-technical audiences.
* Agility: The ability to quickly adapt to the changing threat landscape and move at the pace of the adversary is critical to success in this role.
* Knowledge of cloud security trends: This role requires staying abreast of the latest developments in cloud security and integrating these insights into our practices.
* Balancing security and operational needs: You will balance stringent security guidelines with operational requirements, maintaining the desired corporate security posture while demonstrating empathy and understanding towards the engineering teams' challenges and needs.
Key Responsibilities:
* Manage cloud security tools (CNAPP/CSPM) and implement cloud security controls in a multi-cloud environment (AWS and Azure).
* Conduct security reviews of cloud accounts and projects, generate proactive guidance, and participate in cloud design discussions.
* Review IaC/policy as code template proposals and provide recommendations for secure cloud deployments.
* Develop integrations and automations for cloud security detection and response actions to support the Cyber Defense Operations.
* Partner with cloud foundation teams, Cyber Defense Operations, Tech@Lilly, business areas, and suppliers to ensure secure cloud adoption and operations.
* Perform threat analysis and modeling to enable business and technical partners to deliver secure solutions integrated with the SecOps lifecycle.
* Apply threat modeling and analysis frameworks such as MITRE ATT&CK and STRIDE (or STRIDE-LM) in security practices.
* Maintain and expand technical knowledge across cloud security concepts and technologies, driving knowledge growth across security domains.
* Identify technical solutions and drive implementation to support strategic direction, focusing on value, impact, risk mitigation, security controls, privacy controls, detection, response, and quality.
* Prioritize mitigations in relation to technology upgrades, enhancements, and process improvements within the respective domains of accountability.
Your Basic Qualifications:
* Bachelor's degree in Cyber Security, Computer Science, Information Technology, or related field Or
* High School Diploma/GED with 4+ years of experience in Cyber Security, Information Technology, or related field. And
* 2-6 years of demonstrated experience in cloud architecture and engineering, with a focus on AWS or Azure (slight preference for Azure).
Additional Skills:
* Strong understanding of cloud security concepts, services, and logs, including Identity and Access Management, Networking, and Security in a public cloud environment.
* Experience with cloud security services such as Security Hub, GuardDuty, CloudTrail, Config, VPC Flow Logs, Amazon Inspector, Amazon Detective, Cloud Custodian, Azure Policy, Azure Activity log, Defender for Cloud, Azure Sentinel, or Security Copilot.
* At least basic proficiency in a programming language (e.g., Python) and some experience with cloud automation and integration using tools such as Lambda, Step Functions, Glue, Azure Functions, Terraform, or CloudFormation.
#J-18808-Ljbffr