CybersecurityJobs.io
← Back to all jobs

Job Description

The Cloud Security Engineer at Bank OZK helps ensure the secure design, implementation, and ongoing operation of the organization’s cloud environments. Working across IT and multiple technology teams, the role supports security control implementation, compliance enforcement, and coordinated incident response.

Role Purpose & Scope

This position is accountable for securing Bank OZK’s cloud environments through the implementation and operation of cloud security controls. The engineer partners with IT, Labs, Data, Third-Party Risk Management, and application owners to apply Bank policies and relevant industry regulations.

Responsibilities

  • Supports onboarding and risk assessment of new Cloud Service Providers (CSPs) through the Third-Party Risk Management (TPRM) process.
  • Evaluates CSP security controls against Bank OZK’s Cloud Security Standard and regulatory requirements to confirm legal and compliance readiness prior to approval.
  • Implements and maintains cloud security controls across SaaS, PaaS, and IaaS using Bank-approved secure configuration baselines, including industry benchmarks such as CIS, for resources including VMs, containers, and storage.
  • Builds cloud architecture with technology teams by incorporating security best practices such as network segmentation and encryption from design through delivery.
  • Integrates cloud platforms and applications with the Bank’s centralized Single Sign-On (SSO) and identity management systems.
  • Ensures cloud activity logs are enabled, collected, and integrated with Bank OZK’s SIEM and monitoring systems.
  • Develops detections or alert rules to monitor cloud events for indicators of compromise and policy violations.
  • Investigates and responds to cloud security incidents in coordination with the Security Operations Center (SOC), supporting remediation and capturing lessons learned.
  • Uses automated Cloud Security Posture Management (CSPM) tools or scripts to manage security compliance and identify misconfigurations.
  • Performs configuration audits and vulnerability scans of cloud assets, coordinating remediation with infrastructure and application teams or documenting risk acceptance in line with Bank vulnerability management standards.
  • Collaborates with software and application security teams to deploy cloud-native applications with secure deployment and coding practices aligned to Bank standards, including threat modeling and secure SDLC requirements.
  • Implements cloud-native application security controls such as web application firewalls (WAFs) for internet-facing applications and ensures appropriate network restrictions (for example, security groups and private endpoints) for sensitive data stores.
  • Embeds security into CI/CD pipelines and Infrastructure-as-Code (IaC) processes by working with DevOps to implement automated security checks, including IaC scanning, container image scanning, and secret leakage detection.
  • Advises on secure configuration of CI/CD tooling and secure secret management for pipeline credentials, promoting DevSecOps practices across cloud deployment workflows.
  • Provides guidance and training to IT cloud engineers, developers, and business units on cloud security requirements and secure use of cloud services.
  • Maintains documentation of cloud security controls and processes to support audits or examinations.
  • Provides evidence of compliance with the Bank’s Cloud Security Standard and applicable regulations during internal, external, or regulatory audits, addressing audit findings through corrective actions or process improvements.
  • Stays current with relevant regulatory guidance (including FFIEC cloud computing guidance and NYDFS cybersecurity requirements) and evolving cloud security threats, tools, and practices relevant to financial institutions.
  • Recommends and implements enhancements to Bank OZK’s cloud security posture.
  • Performs or assigns other tasks and assists team members as necessary.

Job Expectations

  • Operate customary equipment and technology used in a business environment, with or without accommodation.
  • Note: This description is not an exhaustive list of all job functions, duties, skills, and job standards required. Other duties may be added, and management reserves the right to add or change requirements at any time.

Required Qualifications

  • Bachelor’s degree in Information Systems or related field, or commensurate work experience, required.
  • Three (3) years of work experience in a regulated financial institution or other heavily regulated environment, required.
  • Familiarity with banking-specific security considerations and third-party risk management practices for cloud services, required.

Preferred Qualifications

  • Professional security certifications related to cloud and information security (e.g., CCSP, CISSP, AWS/Azure Security Engineer, or CompTIA Security+), preferred.

Additional Requirements

  • Knowledge of integrating security testing tools into build and deployment pipelines and managing secrets for automation.
  • Ability to work with DevOps/CI-CD pipelines and securely use Infrastructure-as-Code tools such as Terraform and CloudFormation.
  • Advanced, security-minded risk assessment ability for cloud architectures.
  • Ability to consistently apply confidentiality, integrity, and availability when evaluating cloud solutions and making risk-based decisions aligned with the Bank’s risk appetite.
  • Strong diligence in configuring and reviewing cloud settings, logs, and processes, including follow-through until issues are fully resolved and verified.
  • Strong critical thinking skills to analyze complex technical problems or security events in cloud environments.
  • Ability to break down problems, identify patterns or root causes, and develop effective solutions or mitigations.
  • Ability to communicate technical cloud security issues in terms of business impact.
  • Excellent interpersonal skills and ability to collaborate across cross-functional teams, articulate recommendations, and influence secure outcomes without formal authority.
  • Ability to adapt in a fast-paced, evolving environment, updating strategies and tactics as new cloud services, threats, and regulatory requirements emerge.
  • Self-motivated and proactive approach with ownership of projects and problems; drives improvements in cloud security practices without waiting for direction, demonstrating strong responsibility and ethics when handling sensitive systems and data.
  • Demonstrated initiative to accomplish work objectives.

Technologies

  • CIS
  • SaaS, PaaS, IaaS
  • Single Sign-On (SSO)
  • SIEM
  • Cloud Security Posture Management (CSPM)
  • CSPs, TPRM
  • WAF
  • Security groups, private endpoints
  • CI/CD
  • Infrastructure-as-Code (IaC), Terraform, CloudFormation
  • DevOps
  • CCSP, CISSP, AWS, Azure, CompTIA Security+
  • FFIEC cloud computing guidance, NYDFS cybersecurity requirements

Location & Experience

  • Location: Little Rock, AR (onsite)
  • Minimum Experience: 3 years
  • Minimum Education: Bachelor’s degree in Information Systems or related field (or commensurate work experience)

Benefits

  • Generous PTO
  • 401(k) matching
  • Health, dental, vision (and pet!) insurance
  • Special perks and discounts

Similar Jobs