Cloud Security Engineer
IE: Global Business Solutions - Cork, Ireland
Eli Lilly and Company
Lilly is a medicine company turning science into healing to make life better for people around the world.At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism. We give our best effort to our work, and we put people first. We’re looking for people who are determined to make life better for people around the world.
Eli Lilly Cork is made up of a talented diverse team of over 2000 employees across 60 nationalities who deliver innovative solutions that add value across a variety of Business Service functions including Finance, Information Technology, Medical, Clinical Trials and more. Eli Lilly Cork offers a premium workspace across our campus in Little Island, complete with flexible hybrid working options, healthcare, pension and life assurance benefits, subsidised canteen, onsite gym, travel subsidies and on-site parking. Inhouse People Development services, Educational Assistance, and our ‘Live Your BEST Life’ wellbeing initiatives are just some of the holistic benefits that enhance the career experience for our colleagues.
Eli Lilly Cork is committed to diversity, equity and inclusion (DEI). We cater for all dimensions ensuring inclusion of all ethnicities, nationalities, cultural backgrounds, generations, sexuality, visible and invisible disabilities and gender, with four pillars: EnAble, Age & Culture, LGBTQ+ and GIN-Gender Inclusion Network. EnAble, our pillar for people with disabilities and those that care for them, partners with the Access Lilly initiative to make our physical and digital environment accessible and inclusive for all. Together they are committed to promoting awareness to create a disability confident culture both at Eli Lilly Cork and beyond.
Come join our team - Be Creative, Be an Innovator, and most of all, Be Yourself!
What You'll Be Doing:
As a Cloud Security Engineer at Lilly on the Security Architecture and Engineering team, you will play a pivotal role in a dynamic environment. Your responsibilities include managing cloud security tools (CNAPP/CSPM), conducting security reviews of cloud accounts and projects, generating proactive guidance, reviewing and creating IaC/policy as code templates, and participating in cloud design discussions. You will also contribute to the development and implementation of cloud security controls, create integrations and automations for cloud security detection and response actions, and collaborate with various stakeholders across the organization.
How You'll Succeed:
Technical expertise: As a Cloud Security Engineer, you will leverage your deep technical knowledge of cloud ecosystems (AWS, Azure, and GCP) to implement tailored security solutions and effectively mitigate threats and risks.
Problem-solving skills: Adept problem-solving abilities are crucial in quickly identifying and addressing security issues, ensuring the development and delivery of robust cloud security solutions in a timely manner.
Collaboration and communication skills: You will actively collaborate with both local and remote team members, playing a pivotal role in defining, designing, and executing cloud security strategies. Excellent communication skills are essential for this role, as you will need to engage with both technical and non-technical audiences.
Agility: The ability to quickly adapt to the changing threat landscape and move at the pace of the adversary is critical to success in this role.
Knowledge of cloud security trends: This role requires staying abreast of the latest developments in cloud security and integrating these insights into our practices.
Balancing security and operational needs: You will balance stringent security guidelines with operational requirements, maintaining the desired corporate security posture while demonstrating empathy and understanding towards the engineering teams' challenges and needs.
Key Responsibilities:
Manage cloud security tools (CNAPP/CSPM) and implement cloud security controls in a multi-cloud environment (AWS, Azure, and GCP).
Conduct security reviews of cloud accounts and projects, generate proactive guidance, and participate in cloud design discussions.
Review IaC/policy as code template proposals and provide recommendations for secure cloud deployments.
Develop integrations and automations for cloud security detection and response actions to support the Cyber Defence Operations.
Partner with cloud foundation teams, Cyber Defence Operations, Tech@Lilly, business areas, and suppliers to ensure secure cloud adoption and operations.
Perform threat analysis and modelling to enable business and technical partners to deliver secure solutions integrated with the SecOps lifecycle.
Apply threat modelling and analysis frameworks such as MITRE ATT&CK and STRIDE (or STRIDE-LM) in security practices.
Maintain and expand technical knowledge across cloud security concepts and technologies, driving knowledge growth across security domains.
Identify technical solutions and drive implementation to support strategic direction, focusing on value, impact, risk mitigation, security controls, privacy controls, detection, response, and quality.
Prioritize mitigations in relation to technology upgrades, enhancements, and process improvements within the respective domains of accountability.
Your Basic Qualifications:
Bachelor's degree in Cyber Security, Computer Science, Information Technology, or related field Or
Leaving Certificate/High School Diploma/GED with 6+ years of experience in Cyber Security, Information Technology, or related field.
2-6 years of demonstrated experience in cloud architecture and engineering, with a focus on GCP
Experience with evaluating, mitigating and prioritizing security vulnerabilities, using manual testing methods and/or industry standard commercial or open-source tools.
Experience with automating processes for security testing, escalating, and reporting through scripting and working with APIs.
Knowledge of and ability to apply frameworks such as OWASP Top 10 and MITRE ATT&CK Framework.
Experience with Infrastructure as Code (IaC).
Experience in a programming or scripting language (E.g. Python).
Additional Skills:
Experience in other CSPs is of great benefit (AWS and Azure in particular).
Strong understanding of cloud security concepts, services, and logs, including Identity and Access Management, Networking, and Security in a public cloud environment.
Experience with cloud security services.
Experience with DevSecOps (E.g. Securing a CI/CD pipeline, securing secrets, secret rotation)
Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form (https://careers.lilly.com/us/en/workplace-accommodation) for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response.
Lilly does not discriminate on the basis of age, race, color, religion, gender, sexual orientation, gender identity, gender expression, national origin, protected veteran status, disability or any other legally protected status.
#WeAreLilly
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs AWS Azure CI/CD Cloud CNAPP Computer Science CSPM DevSecOps Finance GCP IAM MITRE ATT&CK OWASP Privacy Python Scripting SecOps Vulnerabilities
Perks/benefits: Career development Fitness / gym Flex hours
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.