Senior Cloud Security Engineer
Our Opportunity:
Chewy is looking for a Senior Cloud Security Engineer to join the Information Security organization to join our team in Boston, MA. This engineer will help develop and execute the architectural vision for their team, and thereby help Chewy to accelerate technological growth and reach new customers. This is a high visibility and high impact role with influence that cuts across all of Chewy. The Information Security organization is responsible for securing all hybrid cloud workloads, providing the business with information assurance and establishing security best-practices.
What You’ll Do:
- Write cloud security requirements and guidelines, documenting processes and procedures ranging from access control of users and resources to risk mitigation
- Create and monitor security alerts, and assisting the Security Operations Center (SOC) team with investigations in the cloud
- Serve as the primary security interface with the Platform Engineering (PE) and Site Reliability Engineering (SRE) teams
- Interface with SDLC instrumentation (SAST/DAST) and application/SRE teams to ensure adherence to OWASP and company development standards, reproducing and demonstrating vulnerabilities as needed
- Work with Platform Engineering team to integrate automated testing within the SDLC and help teams build automated testing tooling as part of a CI/CD pipeline
- Supplement cloud monitoring tool(s) by adding new capabilities, security checks, and automating using the tools extension capabilities and/or SDK/APIs
- Run cloud continuous monitoring reporting/metrics governing all security issues across the cloud ecosystem
- Develop and deploy security guardrails through reusable patterns using standardized development frameworks
- Support the implementation of Infrastructure as Code (IaC) security checks as part of the cloud systems lifecycle management workflows
What You’ll Need:
- Bachelor’s degree in computer science or engineering related field or equivalent work experience
- Minimum of 7 years IT architect or senior engineer experience
- Public Cloud infrastructure expertise
- Primary: Amazon Web Services (AWS)
- Secondary: Azure, Google Cloud Platform
- Experience working in a hybrid cloud environment
- Hands-on experience leading the design, development and deployment of public cloud infrastructure at scale and current hands on technology infrastructure, network, compute, storage, and virtualization experience
- Experience leading highly-available and fault-tolerant enterprise and web-scale platform and/or software deployments
- Background in DevOps, Software Development, Site Reliability, or Systems Engineering
- Working knowledge of Terraform, Jenkins, and other DevOps/Service tools
- Experience with configuration management and continuous deployment
- Expertise in developing fault-tolerant, highly-available, and geographically diverse systems
- Experience with software development life cycle (SDLC) and agile/iterative and agile/scrum methodologies required
- Basic understanding of OWASP frameworks
- Experience coding in higher level programming language, Python, Ruby, JSON, etc.
- Ability to collaborate with stakeholders in order to ensure development efforts align with stakeholder needs
- Strong verbal and written communication skills with demonstrated technical leadership
- Experience driving discussions with senior personnel regarding trade-offs, best practices, project management and risk mitigation
- Demonstrated ability to think strategically about business, product, and technical challenges
- Experience mentoring and coaching colleagues
- Track record of identifying and driving opportunities for continuous improvement
- Comfortable working in cross functional and multidisciplinary teams
- Excellent written and spoken communication
- Position may require some or minimal travel
Bonus (if applicable):
- Experience with Agile Scrum and/or Kanban methodologies
- Linux System Administration experience, ideally CentOS, RedHat or SuSE
- Experience with Akamai
- Experience with Service Oriented Architecture concepts/architectural approach
- Experience in ecommerce
Chewy is committed to equal opportunity. We value and embrace diversity and inclusion of all Team Members. If you have a disability under the Americans with Disabilities Act or similar law, or you require a religious accommodation, and you wish to discuss potential accommodations related to applying for employment at Chewy, please contact [email protected]. To access Chewy’s Privacy Policy, which contains information regarding information collected from job applicants and how we use it, please click here: https://www.chewy.com/app/content/privacy).