BankUnited, Inc.

Cloud Security Engineering Manager

BankUnited, Inc. Miami Lakes, Florida, United States

Banking · 1,001-5,000 employees

5 h ago
engineering-manager Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Cloud Security Engineering Manager will lead the design, implementation, and operation of security solutions across cloud, SaaS, and hybrid environments. They are responsible for managing security professionals, driving vulnerability remediation, and ensuring compliance with regulatory standards.

What they look for

Cloud Security AWS Azure GCP Vulnerability Management IAM SaaS Security Risk Management Cybersecurity Strategy Automation Python PowerShell Compliance Incident Response Network Security Project Management

Requirements

Candidates must have 4-6 years of experience in cloud security and 1-3 years of leadership experience in technical security programs. A bachelor's degree in a related field is preferred, along with relevant certifications like CCSP or AWS Certified Security Specialty.

Full description

JOB SUMMARY: We are seeking a talented, passionate Cloud Security Engineering Manager to join our team and help lead efforts to secure the Bank's cloud-based banking and support applications, infrastructure, SaaS platforms, and hybrid environments.

 

As a Cloud Security Engineering Manager, you will be responsible for helping to develop, execute, and continuously improve the Bank's cloud security strategy in collaboration with Enterprise Architecture, Cloud Architecture, IAM, Application Security, Cyber Threat Intelligence, Infrastructure, Technology Risk, Data Platform, and Software Engineering teams.

 

Responsibilities include designing, implementing, and operating modern cloud-first security solutions and best practices across AWS, Azure, GCP, SaaS, and hybrid environments. The role also drives vulnerability remediation, security platform lifecycle ownership, control execution, executive reporting, and audit/regulatory readiness in alignment with the Technology Security operating model.

 

You will manage and mentor security professionals while partnering across IT and Security to reduce enterprise risk, improve remediation accountability, and maintain effective security operations.

This role is expected to operate in close alignment with the Director of Technology Security and the broader CIO / CISO operating model.

 

This role may require occasional work outside standard business hours to support security incidents, critical remediation activities, audit/regulatory requests, or high-priority technology initiatives.

 

ESSENTIAL DUTIES AND RESPONSIBILITIES

  • Designs, develops, and deploys modular cloud-first security and support systems across cloud, SaaS, and hybrid environments.
  • Develops and enforces cloud security policies, standards, and guidelines to ensure compliance with regulatory and industry requirements, including NIST, FFIEC, GLBA, PCI-DSS, and related cybersecurity standards.
  • Leads execution of cloud security strategy, standards, and operational controls across AWS, Azure, GCP, SaaS, and hybrid technology environments.
  • Identifies opportunities to reduce cloud security risk for the Bank and lead the team in implementation of risk-reducing solutions.
  • Accountable for identification, prioritization, tracking, and remediation coordination of cloud-hosted vulnerabilities, misconfigurations, exposed services, and security control gaps.
  • Partners with enterprise Vulnerability Management teams develop and implement risk-based remediation strategies across cloud, SaaS, application, and hybrid environments.
  • Establishes remediation standards, service level objectives, escalation paths, and reporting metrics for cloud vulnerabilities and security findings.
  • Supports enterprise initiatives focused on reducing critical vulnerabilities, improving patch and configuration hygiene, and reducing overall technology risk exposure.
  • Participates in security assessments and audits of cloud environments and assists with identification and remediation of potential security gaps and/or vulnerabilities.
  • Validates remediation efforts through security assessments, configuration reviews, continuous monitoring, testing, and evidence collection.
  • Plans, architects, and implements cloud security tools and technologies, such as firewalls, IDS/IPS, identity and access management, logging and monitoring, CSPM, CNAPP, CASB, and cloud-native security services.
  • Owns lifecycle management of cloud security technologies, including evaluation, implementation, operation, optimization, roadmap planning, and retirement.
  • Ensures integration between cloud security platforms, identity services, vulnerability management solutions, logging solutions, SIEM/SOAR capabilities, and security monitoring technologies.
  • Drives automation initiatives to improve security operations, reporting, remediation workflows, control validation, and operational efficiency.
  • Evaluates and develops a framework for SaaS security baselining and standardization, inclusive of IAM, data security, configuration, and access control considerations.
  • Assists with security incidents or events in cloud and hybrid environments and collaborate with other teams to resolve issues and mitigate risks.
  • Partners with Cyber Threat Intelligence, Security Operations, and Incident Response teams to operationalize threat intelligence and emerging threat information.
  • Evaluates threats impacting cloud platforms and coordinate proactive mitigation activities for critical vulnerabilities, zero-day threats, and actively exploited issues.
  • Research and stays updated on the latest cloud security trends, threats, attack patterns, and best practices, especially as they relate to Financial Services.
  • Educates and trains other staff on cloud security awareness, secure engineering practices, standards, and operational expectations.
  • Integrates, as appropriate, AWS and other vendor security services and features to enhance the security posture of cloud environments.
  • Apply API security principles and techniques, such as authentication, authorization, encryption, rate limiting, and monitoring, to protect cloud-based APIs from unauthorized access and abuse.
  • Uses cloud security posture management and related tools and processes to monitor and remediate misconfigurations and security risks across cloud environments.
  • Uses cloud access security broker or other Internet traffic filtering solutions to enforce security policies and controls for cloud-based applications and data.
  • Develop and maintain cloud security dashboards, KPIs, KRIs, remediation metrics, and executive reporting packages.
  • Prepares and presents cloud security posture updates, remediation progress, risk trends, operational metrics, and recommendations to Technology Security leadership.
  • Creates, maintains, and presents documentation as it relates to cloud security operations designs/configurations, processes, standards, risks, and recommendations.
  • Supports internal audits, external audits, and regulatory examinations through production of security evidence, documentation, operational metrics, and remediation status reporting.
  • Partners with Risk Management, Compliance, Internal Audit, Legal, and CISO-governance functions to address findings and drive corrective actions.
  • Oversee the performance and development of a team of cloud engineers and other Cybersecurity professionals while providing feedback, coaching, and mentoring.
  • Understands network security policies and introduce and implement security standards and best practices for cloud engineering.
  • Manages project budgets and schedules and ensures timely and quality delivery of security solutions.
  • Provides support and guidance to team members and resolves any issues or conflicts.
  • Collaborates with Network, Enterprise Architecture, Cloud Architecture, Data Platform, IAM, Application Security, Cyber Threat Intelligence, Infrastructure, Technology Risk, and Software Engineering teams to design, implement, and support an enterprise-class cloud security strategy.
  • Adheres to and complies with applicable, federal and state laws, regulations and guidance, including those related to anti-money laundering (i.e. Bank Secrecy Act, US PATRIOT Act, etc.).
  • Adheres to Bank policies and procedures and completes required training.
  • Identifies and reports suspicious activity.

SUPERVISORY RESPONSIBILITIES

  • Supervises function, projects or services and/or one or more employees, as applicable.
  • Carries out supervisory responsibilities in accordance with the organization's policies and applicable laws.
  • Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance coaching; rewarding and disciplining employees; addressing complaints and resolving problems.

QUALIFICATIONS Education

  • Bachelor's degree in cybersecurity, computer science, information systems, engineering, or related field, or equivalent work experience preferred.
  • Master's degree preferred.

Experience

  • 4-6 Years Experience in cloud security, engineering, and/or administration required.
  • Strong understanding of cloud-based infrastructure components with specific understanding of security risks presented in decentralized and hybrid environments required.
  • Experience with cloud native security related tools such as AWS Guard Duty, AWS WAF, Azure Defender for Cloud, GCP Security Command Center, or similar required.
  • Experience managing or supporting enterprise vulnerability management or exposure management programs required.
  • Experience driving remediation efforts across infrastructure, cloud, application, and SaaS environments required.
  • Experience developing security metrics, dashboards, remediation reporting, and leadership updates required.
  • Experience supporting audits, regulatory examinations, and compliance assessments in regulated environments required.
  • Experience with IaC tools such as Terraform preferred.
  • 4-6 Years Experience in the banking industry, or knowledge of banking regulations and standards, such as GLBA, FFIEC, OCC, FDIC, SOX, PCI-DSS, etc., is a significant plus preferred.
  • 1-3 Years Experience leading cloud security engineering teams or technical security programs required.
  • Experience with cloud security posture management, CNAPP, CASB, SaaS posture management, firewall, or Internet traffic filtering solutions preferred.
  • Experience with automation technologies supporting security operations and remediation workflows preferred.
  • Experience integrating threat intelligence into vulnerability prioritization and risk reduction activities preferred.

Licenses and Certifications

  • Certification in cloud security, such as CCSK, CCSP, AWS Certified Security Specialty, or equivalent, is a plus at hire but mandatory within 12 months of hire within 1 Year required.
  • Certification in general Cybersecurity, such as CISSP, CISM, CRISC, CISA, Security+, GSEC, or equivalent, is a plus within 1-1/2 Yrs preferred.
  • Microsoft Azure Security Engineer Associate, GIAC cloud/security certifications, or similar technical certifications preferred.

Knowledge, Skills, and Abilities

  • Proficiency with cloud platforms and services, such as AWS, Azure, and GCP.
  • Knowledge of cloud security frameworks and standards, including NIST CSF, FedRAMP, CIS, CSA, FFIEC, GLBA, PCI-DSS, etc.
  • Experience with cloud security tools and technologies, such as AWS Security Hub, Azure Security Center.
  • Defender for Cloud, GCP Security Command Center, CSPM, CNAPP, CASB, and SaaS security posture tools.
  • Strong understanding of vulnerability management concepts including CVE, CVSS, exploitability, asset criticality, risk prioritization, remediation workflows, compensating controls, and exposure management.
  • Experience with scripting languages, such as Python, PowerShell, etc.
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills, including ability to translate complex technical findings into business-focused risk statements, remediation priorities, and executive-level reporting.
  • Ability to work independently and as part of a team.
  • Ability to lead cross-functional initiatives involving Infrastructure, Cloud, IAM, Application Development, Risk, Audit, Compliance, and Security teams.
  • Leadership skills, such as delegation, motivation, coaching, and conflict resolution.
  • Project management skills, such as planning, organizing, prioritizing, and delivery accountability.

Additional Information

Candidates residing in locations within BankUnited's footprint may be given preference.

Similar roles