Strong grasp of security engineering (IAM design, secrets, key management, network security, container security, vulnerability mgmt) and policy-as-code. * Establish multi-cloud landing zones (AWS Organizations + Control Tower; Azure Management Groups + Landing Zones) with policy, identity, and network guardrails. * Drive pipeline-native IaC (GitOps principles, PR-based workflows, security scans, unit/integration tests, drift detection, and change approvals). Security, Governance, and Compliance * Build secure-by-default blueprints: network segmentation, private endpoints, encryption, vulnerability mgmt, and SBOM/SLSA practices. * Proficiency with CI/CD (GitHub Actions, Azure DevOps, GitLab CI), artifact registries, and pipeline security. * Security by Default: Defense-in-depth, least privilege, provable compliance. * Stakeholder Leadership: Align across security, networking, data, finance, and product teams.
mehr