{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/cloud-security-principles"},"x-facet":{"type":"skill","slug":"cloud-security-principles","display":"Cloud Security Principles","count":4},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_417bc97b-b9a"},"title":"Lead Business Analyst","description":"<p>Some careers have more impact than others. If you&#39;re looking for a career where you can make a real impression, join HSBC and discover how valued you&#39;ll be.</p>\n<p>We are currently seeking an experienced professional to join our team in the role of Lead Business Analyst.</p>\n<p>Key Responsibilities:</p>\n<ul>\n<li>Develop, maintain, and implement IT risk management policies, standards, and control frameworks (e.g., ISO27001, NIST, COBIT).</li>\n<li>Conduct regular risk assessments and Control Self-Assessments (CSA) for technology initiatives, infrastructure, and information assets.</li>\n<li>Establish, monitor, and update Key Risk Indicators (KRIs) and Key Controls to ensure operating effectiveness.</li>\n<li>Ensure IT practices comply with local regulations (e.g., HKMA, GDPR, PCI-DSS) and act as a focal point for internal and external audit examinations.</li>\n<li>Lead IT incident investigation, perform root cause analysis (RCA), and ensure prompt rectification of control weaknesses.</li>\n<li>Oversee information security risk management for vendor onboarding and off-boarding.</li>\n</ul>\n<p>Requirements:</p>\n<ul>\n<li>Bachelor&#39;s degree in Information Technology, Computer Science, Information Security, or a related field.</li>\n<li>5+ years of relevant experience in technology risk management, IT audit, or IT security within the banking/financial services industry.</li>\n<li>Professional certifications such as CISA, CISSP, CISM, CRISC, or similar are strongly preferred.</li>\n<li>Understanding of IT general controls (ITGC), cybersecurity best practices, data protection, and cloud security principles.</li>\n<li>Familiarity with local financial authority regulations and technical risk management guidelines.</li>\n</ul>\n<p>Core Skills:</p>\n<ul>\n<li>Analytical Thinking: Ability to identify and quantify complex technology risks.</li>\n<li>Communication: Excellent interpersonal skills to influence and collaborate with first-line business units and stakeholders.</li>\n<li>Problem-Solving: Proven ability to define and drive the implementation of remediation plans.</li>\n<li>Leadership: Ability to lead IT risk awareness initiatives and work under pressure.</li>\n</ul>\n<p>You&#39;ll achieve more when you join HSBC. HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_417bc97b-b9a","directApply":true,"hiringOrganization":{"@type":"Organization","name":"HSBC","sameAs":"https://portal.careers.hsbc.com","logo":"https://logos.yubhub.co/portal.careers.hsbc.com.png"},"x-apply-url":"https://portal.careers.hsbc.com/careers/job/563774610677563","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Analytical Thinking","Communication","Problem-Solving","Leadership","IT General Controls","Cybersecurity Best Practices","Data Protection","Cloud Security Principles","Local Financial Authority Regulations","Technical Risk Management Guidelines"],"x-skills-preferred":[],"datePosted":"2026-04-18T22:10:24.076Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Guangzhou"}},"employmentType":"FULL_TIME","occupationalCategory":"IT","industry":"Finance","skills":"Analytical Thinking, Communication, Problem-Solving, Leadership, IT General Controls, Cybersecurity Best Practices, Data Protection, Cloud Security Principles, Local Financial Authority Regulations, Technical Risk Management Guidelines"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_bdf9dc88-fbe"},"title":"Infrastructure Security Engineer","description":"<p>We are seeking a talented and motivated Cloud/Infrastructure Security Engineer to join our security team.</p>\n<p>In this role, you will design, implement, and maintain secure cloud infrastructure and ensure the integrity of our cloud-native applications.</p>\n<p>Responsibilities:</p>\n<ul>\n<li>Design and implement secure cloud architectures across multiple cloud platforms (e.g., AWS, GCP, Azure)</li>\n<li>Develop and maintain Infrastructure as Code (IaC) templates with embedded security controls</li>\n<li>Conduct regular security assessments and audits of cloud infrastructure and services</li>\n<li>Implement and manage cloud security tools and services (e.g., CSPM, CWPP, CASB)</li>\n<li>Collaborate with development teams to ensure security best practices are integrated into CI/CD pipelines</li>\n<li>Monitor and respond to security events and incidents in cloud environments</li>\n<li>Develop and maintain cloud security policies, standards, and procedures</li>\n<li>Stay current with emerging cloud security threats and mitigation strategies</li>\n</ul>\n<p>Basic Qualifications:</p>\n<ul>\n<li>Bachelor&#39;s degree in Computer Science, Cybersecurity, or a related field</li>\n<li>3-5 years of experience in cloud security or related roles</li>\n<li>Strong understanding of cloud security principles, compliance frameworks, and best practices</li>\n<li>Proficiency in at least one cloud platform (AWS, GCP, or Azure) and associated security services</li>\n<li>Experience with Infrastructure as Code tools (e.g., Terraform, CloudFormation)</li>\n<li>Familiarity with containerization technologies and their security implications</li>\n<li>Knowledge of network security concepts and protocols</li>\n<li>Experience with scripting languages (e.g., Python, Bash) for automation and tool development</li>\n</ul>\n<p>Preferred Skills and Experience:</p>\n<ul>\n<li>Relevant security certifications (e.g., CCSP, CSSK, AWS Security Specialty)</li>\n<li>Experience with multi-cloud environments and cloud-to-cloud security</li>\n<li>Knowledge of DevSecOps practices and tools</li>\n<li>Experience with Kubernetes and container security</li>\n<li>Experience in building custom cloud security tools or integrations</li>\n<li>Interest in leveraging AI for cloud security monitoring and automation</li>\n<li>Contributions to open-source cloud security projects</li>\n<li>Experience with securing AI/ML workloads in cloud environments</li>\n</ul>\n<p>Compensation and Benefits:</p>\n<p>$200,000 - $340,000 USD</p>\n<p>Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short &amp; long-term disability insurance, life insurance, and various other discounts and perks.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_bdf9dc88-fbe","directApply":true,"hiringOrganization":{"@type":"Organization","name":"xAI","sameAs":"https://www.xai.com/","logo":"https://logos.yubhub.co/xai.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/xai/jobs/5090998007","x-work-arrangement":"onsite","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":"$200,000 - $340,000 USD","x-skills-required":["Cloud security principles","Compliance frameworks","Best practices","Cloud platform (AWS, GCP, or Azure)","Infrastructure as Code tools (Terraform, CloudFormation)"],"x-skills-preferred":["Relevant security certifications (CCSP, CSSK, AWS Security Specialty)","Multi-cloud environments and cloud-to-cloud security","DevSecOps practices and tools","Kubernetes and container security","Building custom cloud security tools or integrations"],"datePosted":"2026-04-18T15:23:29.833Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Palo Alto, CA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Cloud security principles, Compliance frameworks, Best practices, Cloud platform (AWS, GCP, or Azure), Infrastructure as Code tools (Terraform, CloudFormation), Relevant security certifications (CCSP, CSSK, AWS Security Specialty), Multi-cloud environments and cloud-to-cloud security, DevSecOps practices and tools, Kubernetes and container security, Building custom cloud security tools or integrations","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":200000,"maxValue":340000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_395c1cc1-6a4"},"title":"Security Engineer","description":"<p>We are seeking a Security Engineer to join our growing security team. This role will have a huge impact on maintaining and improving Greenlight&#39;s security posture by developing and implementing automated workflows or AI toolings.</p>\n<p>The successful candidate will design, build, and maintain high-scale automation workflows and AI-assisted capabilities that proactively mature Greenlight&#39;s security posture. They will also architect and implement security guardrails for internal AI usage, ensuring LLM integrations and automated agents operate within company risk tolerances.</p>\n<p>Key responsibilities include:</p>\n<ul>\n<li>Developing custom integrations across the security and business systems stack (SaaS, FinTech tools, and internal APIs) to eliminate manual silos.</li>\n<li>Building and configuring automated tooling for real-time monitoring of data security, privacy, and vulnerability management.</li>\n<li>Partnering with IT, Engineering, and Business Owners to identify operational bottlenecks and deploy AI-powered solutions that enhance both security and efficiency.</li>\n<li>Collaborating with DevOps to bake automated security controls into the CI/CD pipeline and cloud environments.</li>\n<li>Creating high-quality designs, workflow diagrams, and playbooks to ensure automated systems are maintainable and transparent.</li>\n</ul>\n<p>Requirements include:</p>\n<ul>\n<li>4+ years of professional experience in Cybersecurity, DevOps, or Software Engineering.</li>\n<li>Strong proficiency in Python (preferred) or Go for building custom security tools and API-heavy integrations.</li>\n<li>Solid understanding of cloud security principles (AWS/GCP), containerization (Docker/K8s), and securing distributed systems.</li>\n<li>Deep familiarity with the OWASP Top 10 (including LLM-specific risks) and CI/CD security best practices.</li>\n<li>Hands-on experience with CI/CD platforms (GitHub Actions, GitLab CI) and no-code/low-code automation platforms (e.g., Tines, Torq, or Tray.io).</li>\n<li>Proven experience using AI-assisted tools (Copilot, Cursor, etc.) to accelerate development and a curiosity for deploying AI-driven security solutions.</li>\n</ul>\n<p>Nice to have:</p>\n<ul>\n<li>Experience with Infrastructure-as-code (IaC)</li>\n<li>Direct experience implementing security controls within both AWS and GCP.</li>\n<li>Security certifications such as CISSP, Security+, or specialized GIAC certifications.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_395c1cc1-6a4","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Greenlight","sameAs":"https://www.greenlight.com/","logo":"https://logos.yubhub.co/greenlight.com.png"},"x-apply-url":"https://jobs.lever.co/greenlight/2a76b288-50ec-4b8c-82b8-bf9543fcf054","x-work-arrangement":"remote","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Python","Go","Cloud security principles","Containerization","Securing distributed systems","OWASP Top 10","CI/CD security best practices","CI/CD platforms","No-code/low-code automation platforms","AI-assisted tools"],"x-skills-preferred":[],"datePosted":"2026-04-17T12:36:46.694Z","jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Finance","skills":"Python, Go, Cloud security principles, Containerization, Securing distributed systems, OWASP Top 10, CI/CD security best practices, CI/CD platforms, No-code/low-code automation platforms, AI-assisted tools"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_4b414123-045"},"title":"Product Security Engineer II","description":"<p>We are seeking a Product Security Engineer II to join our growing security team. This role will be critical in ensuring the security of our products across the entire software development lifecycle (SDLC) and provide support on different security initiatives.</p>\n<p>You will work closely with engineering, product, and operations teams to embed security best practices from design through to deployment.</p>\n<p>Key responsibilities include:</p>\n<p>Supporting the execution of a comprehensive product security strategy that aligns with the company&#39;s goals and risk appetite.\nWorking hands-on across code, infrastructure, and CI/CD to create agents, services, and pipelines that detect, prevent, and remediate risks leveraging AI where it adds value.\nDesigning, building, and operating security automation for the SDLC (code scanning, dependency risk management, secrets detection, policy-as-code) integrated into CI/CD.\nPerforming manual design and implementation reviews of Greenlight products and services from a security perspective.\nEstablishing and enforcing secure development standards (i.e., API security, security patterns, IaC, etc.) and best practices across the organization.\nServing as a subject matter expert on the practical security of our AI and LLM ecosystem. Leading threat modeling exercises for novel AI systems applying advanced security and privacy best practices.\nLeveraging automations and tools to continuously test, fuzz, and validate products and platform components for security issues.\nPerforming penetration testing and retesting to validate fixes.\nResponsible for triaging findings from security researchers and leading incident response for PSIRT.\nOn-call support for incident response and leading product-related security events and vulnerabilities.\nFostering a culture of security awareness and ownership across the Engineering and Product organizations.\nStaying current with the latest security threats, vulnerabilities, and industry best practices to continuously evolve our security controls and processes.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_4b414123-045","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Greenlight","sameAs":"https://www.greenlight.com/","logo":"https://logos.yubhub.co/greenlight.com.png"},"x-apply-url":"https://jobs.lever.co/greenlight/6daa8340-f262-454c-be7d-e3adc813fe0e","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Node.js","Java/Kotlin","React","Redux","Swift","SwiftUI","AWS","MySQL","DynamoDB","Redis","Kubernetes","Ambassador","Helm","Rancher","SAST","DAST","IAST","Penetration testing","Fuzzing","Scripting","Automation","Exploit writing","Cloud security principles"],"x-skills-preferred":["Security assessment of IoT hardware/firmware","Contribution to security community","Experience at Fintech or similar regulated companies","Startup Agility"],"datePosted":"2026-04-17T12:36:02.056Z","jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Finance","skills":"Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI, AWS, MySQL, DynamoDB, Redis, Kubernetes, Ambassador, Helm, Rancher, SAST, DAST, IAST, Penetration testing, Fuzzing, Scripting, Automation, Exploit writing, Cloud security principles, Security assessment of IoT hardware/firmware, Contribution to security community, Experience at Fintech or similar regulated companies, Startup Agility"}]}