Cloud) Security Engineer / Consultant – Team Protect
Team ProTect is the security and privacy unit within the Technology division at KPN, responsible for B2C and Enterprise IT, including cloud, container, and DevOps platforms. We oversee security and privacy for more than 500 applications managed by over 100 teams in the Netherlands and offshore. Our team ensures that all innovation within our scope meets stringent security and privacy standards. On a daily basis, we analyze and advise business units regarding their security and privacy inquiries and developments.
Within this role, it is described as a consultant role within the IT security team, where the team advises IT business on their implementations and works closely with the CISO by taking their policies, aligning on certain topics, and translating these towards the DevOps teams. There is also some hands-on involvement in implementing policies and configuration items in the cloud, but it is explicitly mentioned that the role is not super hands-on on a daily basis and should not be seen as a pure engineering role.
We are seeking a Senior (Cloud) Security Consultant with a strong technical security background and extensive experience to assess security challenges and provide expert guidance to business units regarding their cloud workloads. The role is described with a focus on infrastructure security, where it is mentioned that someone without experience in how cloud works, especially at infrastructure level, will not be suitable for this position. It is also stated that they are looking for someone experienced in this setup and specifically for a mid to senior level profile who can also act as an example for others in the team and bring outside-in knowledge. Additionally, demonstrated soft skills are required to influence DevOps teams and IT managers towards enhanced security awareness and best practices.
Responsibilities
- Assist business/devops teams to migration their workload to public cloud and container platform with right secuirty quality and validate their implementation
- Secure containerized environments (Docker, Kubernetes) and serverless architectures.
- Perform threat modeling in the system architecrture to find and to mitiagate threats
- Analize cloud security non-compliances to determine their root causes and define solutions to address the root causes of non-compliance and validate the implementation
- Collaborate with the cloud platform engineering team to design and integrate into day-by-day operation (operationalize) new cloud security features and services
- Manage vulnerabilities and misconfigurations in a regular basis
- Implement cloud security solutions to help the team with hands on expertise on WAF, End Point Protect, System Hardening and IAM.
- Analyse technical security questions and provide right advice and measure
- Create templates, automations and paved roads to facilitate scalable and faster delivery
- Working with the modern ci/cd pipeline and security toolings in the pipeline for automated security checks to uphold DevSecOps practices
- Support security training and awareness programs when needed.