Sr. Manager Cloud Services
Job Description
As a Sr. Manager of Cloud Services, you will be leading a group of talented individuals within Morningstar, to build robust cloud foundation(s) which enables and supports our product teams. This role is critical to our cloud journey. You will partner closely with other technology teams for alignment on strategy, approach, and execution.
Job Responsibilitiesβ’ Partner with teams on strategy and designing and implementing secure and scalable solutions that take full advantage of cloud computing.β’ Serve as a subject matter expert (SME) on cloud engineering, operations, and security for Morningstar.β’ Educate business and technology stakeholders on value propositions of cloud and participate in deep architectural discussions to ensure solutions are designed for successful deployment in the cloud (AWS, Azure, GCP).β’ Capture and share leading-practice cloud engineering knowledge amongst the technology community.β’ Develop a vision for the cloud services team and encourage each member to fully engage their talents and energy to achieve it.β’ Review and approve reference architectures for cloud-native high-performance environments and ensure that rapid adoption takes place with maximum support.β’ Remediate the operational and security posture of existing cloud environments and ensure that newly created cloud systems meet evolving standards.β’ Oversee Cloud security engagements during different phases of the lifecycle - assess, design, and implementation.β’ Promote industry leading practices through the design and mentorship of other technology teams and team-members.β’ Oversee/Lead cloud cybersecurity assessments and review/develop strategic and tactical security remediation recommendations / cyber risk roadmap to address identified security gaps.β’ Oversee/Lead cybersecurity controls testing across client's cloud environments to determine control effectiveness and adherence to both internal cybersecurity policies and standards and external requirements (e.g. certifications, laws, regulations and contracts).β’ Deliver end-to-end automation of deployment, monitoring and infrastructure management in the cloud.β’ Ensure DevSecOps systems we build are robust in the sense they can scale, handle rapid growth, and limit exposure to single points of failure and security vulnerabilities.β’ Demonstrate deep understanding of testing methodologies, test automation and software development principles.β’ Champion Agile leading-practices, processes, and tools in support of DevSecOps processes.β’ Support and enable team members across both technical and management leadership capacities.β’ Leverage experience and knowledge in cloud platform technologies such as Amazon's VPC, Elastic Load balancing, Global Accelerator, Transit Gateway, Security Groups, Identity and Access Management IAM, Route 53, Key Management Service (KMS), PrivateLink Direct Connect, Virtual Private Network, CloudFront and API Gateway.
Qualificationsβ’ 10+ years of information technology and/or information security experienceβ’ 5+ years in an engineering role designing and supporting public clouds - AWS, Azure.β’ 5+ years of hands-on technical experience with at least one cloud platform in security or infrastructure implementation and operations.β’ Experience with previous cloud migrations.β’ 5+ years of hands-on technical experience with infrastructure systems such as networking (e.g. WAF, Firewall and load balancing), operating systems, SCCM and endpoint engineering, and infrastructure automation implementation or operations.β’ 5+ years of working with different Cloud platforms (Software as a Service (SaaS), Platform as a Service (PaaS) and Infrastructure as a Service (IaaS)) and environments (Public, Private, Hybrid).β’ Depth of experience with multiple security technologies such as Firewalls, Intrusion Detection/Prevention Systems, Vulnerability Scanning, WAF, Wireless LAN, NAC, DLP, DDoS Mitigation, WAN security, CASB, SIEM, Content Filtering, Cloud Security gateways, Secure Proxies, SSL crypto solutions, and automation.β’ Demonstrated capability to design, deploy, operationalize and automate secure and highly scalable enterprise systems on public cloud - AWS, Azure and Google.β’ Expert-level understanding of cloud service provider's "well architected" frameworks.β’ Experience with secure software development, data protection, cryptography, key management, identity and access management (IAM), network security (VPNs) within cloud environments.β’ Experience in architecting and deploying secure software defined and virtualized networks.β’ Knowledge in designing, implementing, and managing DevSecOps capabilities in cloud offerings using CALMS (culture, automation, lean, measurement, and sharing) - including building security checks to developer workflows.β’ Experience in managing pipelines and working with tools such as Jenkins, Ansible, Chef, Puppet, SaltStack and Terraform.β’ Experience in installing and configuring native and third-party databases in the cloud such as MongoDB, MYSQL, Couchbase, Oracle.β’ Experience in agile leading-practices, processes, and tools in support of DevSecOps processes with respect to Test Automation.β’ Understanding of industry regulatory and compliance requirements (i.e., FedRAMP, PCI-DSS, NIST, HIPAA) and skilled at interpreting the compliance and security requirements into specific implementable and reusable controls.β’ Experience in the creation and maintenance of concise and achievable security policies, standards, and procedures, managing the protection of information systems and assets as well as the preservation of privacy rights in all applicable jurisdictions.β’ Experience with engaging C-Level executives and developing cyber risk strategies to address broad security issues in a timely manner.β’ Experience with leading multiple distributed teams across different geographies.
Nice to have
Experience with cloud automation and container tools like bash scripting, Ansible, Docker, Chef or Puppet.β’ Experience with securing containers and container orchestration platforms (Kubernetes).β’ Experience responding to widespread zero-day vulnerabilities that often impact cloud systems, such as Log4Shell and Spring4Shell.β’ Experience with JSON, Python, XML and ability to write cloud automation scripts desired.β’ Certifications such as: AWS Certified Solutions Architect, AWS Certified Security - Specialty, Azure Solutions Architect, Azure Security Engineer, GCP Cloud Architect, GCP Cloud Security Engineer, CCSP, CISSP.β’ Knowledge of security and privacy-related industry standards and frameworks (e.g., ISO 27001/2, NIST 800-53, NIST CSF, CSA CCM) is a plus.β’ Ability to develop compelling proposals for client to clearly articulate the need for information security.β’ Excellent writing and verbal communication skills.β’ Strong project management and organizational skills.
001_MstarInc Morningstar Inc. Legal Entity
Date Posted
09/06/2022
Views
5
Similar Jobs
Account Manager (Advertising Sales Team) - Chicago - CafeMedia
Views in the last 30 days - 6
This is an excellent opportunity to get broad experience in all aspects of digital media The position is based in Chicago IL and requires excellent co...
View DetailsAssociate Principal, Windows Services - OCC
Views in the last 30 days - 5
The job posting is seeking a Windows server engineer to administer and enhance the Windows server infrastructure The successful candidate must have pr...
View DetailsSite Operations Manager - Tempus
Views in the last 30 days - 12
The company is looking for a Site Operations Manager to lead the development of their research site operations team The team will be responsible for c...
View DetailsAVP, Internal Audit - CNA
Views in the last 30 days - 11
The job description is for an Assistant Vice President Internal Audit position at CNA The role involves leading a team to provide risk management gove...
View DetailsSoftware Product Consultant - CSC Corptax
Views in the last 30 days - 10
The job description is for a fulltime consultant to join the Corptax Professional Services Team The consultant will provide implementation and best pr...
View DetailsSr. Software Engineer - OEMS Team - Enfusion
Views in the last 30 days - 8
Enfusion is a pioneer in developing innovative cloud investment management software analytics and managed services They help fund managers streamline ...
View Details