TC-CS-Cyber Architecture- OT and Engineering-Devops- Cloud Security-Senior
EY
EY
Join EY as a Cyber Security Engineer, contributing to our mission of building a better working world. This role focuses on creating and maintaining secure virtual machine images within AWS and Azure cloud environments. You'll leverage your expertise in CI/CD pipelines, scripting, and cloud security technologies to enhance our infrastructure's resilience and compliance.
We are seeking an innovative engineer with a robust understanding of security best practices and a passion for automation. Your work will directly impact the security posture of our cloud deployments, ensuring adherence to industry standards and enterprise requirements.
Develop and automate the creation of hardened VM images for AWS and Azure. Implement and manage robust CI/CD pipelines for efficient image deployment and lifecycle management. Design end-to-end automation workflows covering image creation, validation, testing, and deployment. Create comprehensive documentation, including runbooks and hardening guides. Perform OS hardening across various Linux distributions (RHEL, Rocky, OEL, Amazon Linux, Ubuntu) and Windows Server versions.
Troubleshoot pipeline errors, OS issues, and service deployment challenges. Build and maintain automated patching solutions for both Linux and Windows images. Apply CIS L1/L2 frameworks to identify and remediate vulnerabilities through automated means. Monitor and align with evolving CIS benchmark updates. Support audits and compliance reviews by providing necessary evidence and remediation strategies. Enhance pipelines with integrated security validation, including vulnerability scanning and compliance checks. Conduct peer reviews for scripts and IaC templates, ensuring quality and consistency. Collaborate with cloud infrastructure, architecture, and security teams to meet enterprise requirements.
A minimum of 5 years of overall IT experience is required, with at least 3 years specifically in image hardening. You should have a minimum of 2 years of application development experience in Python, coupled with at least 2 years of experience using Terraform. Essential experience includes managing and securing multi-cloud environments (AWS, Azure, GCP) using native security tools, with a minimum of 3-5 years in this area.
Proficiency in scripting languages such as Python, PowerShell, and Bash is crucial. Experience with Azure DevOps, Ansible, and Packer is also essential. A deep understanding of CIS Benchmarks (L1/L2), OS hardening principles, and automated security remediation is expected. Strong problem-solving skills, effective communication abilities, and a proactive approach to security are highly valued. A commitment to continuous learning in cybersecurity is a must.
EY Global Delivery Services ( EY GDS)
Management Consulting