hackajob is partnering with GSK to fill this position. Create a profile to be automatically considered for this role—and others that match your experience.
Senior Manager, Cloud and Container Security
We have an exciting opportunity for an experienced cloud and container security manager to join a growing cloud security team in GSKs Cyber Security Office (CSO). You will work closely with senior stakeholders and cross-functional product teams to embed and enhance GSKs cloud and container security governance and capabilities, accelerating delivery of our business objectives, cloud migration and digital transformation initiative.
You will need to be comfortable working in a fast-paced agile environment and have experience working with multiple security and governance groups, central IT, developer and system integrator teams, based across multiple geographies and in different organisations.
This role offers the opportunity to use a wide range of skills to deliver an enterprise cloud and container security program supporting modern architecture patterns and technologies.
The ideal candidate will combine excellent technical skills and communication expertise with a collaborative approach to ensure optimal stakeholder alignment with our cloud and container security strategy.’
In this role you will
Develop and maintain cloud and container security governance frameworks for multi-cloud environments, including Azure, GCP, and Kubernetes
Align security standards, frameworks, and policies with business and technology strategies, and implement processes and tools for compliance monitoring
Create and update Cloud and Container Security reference architecture and capability roadmaps
Build a network of stakeholders across security, IT, and developer teams to understand future cloud requirements
Periodically review and update security controls and guidance for Kubernetes and IaaS/PaaS services, balancing business and security needs
Define best practices for Kubernetes and IaaS/PaaS services to enhance security controls
Lead cloud and container security discussions with cyber security, IT teams, senior leadership, and workload owners
Conduct security architecture reviews for large-scale cloud projects, recommending changes to align with secure-by-design principles
Provide security consultancy to cyber risk and governance teams for solution architecture reviews
Identify and communicate emerging security threats
Stay updated on market trends and competitive insights in cloud and container security
Qualifications & Skills:
Extensive experience in information security and significant experience in cloud and container security
Relevant educational background or equivalent experience.
Expert knowledge of Azure, GCP, and AWS security
Strong understanding of securing Kubernetes platforms and container-hosted workloads
Proven expertise in security architecture and design reviews for cloud-native solutions, including containers, micro-services, APIs, PaaS capabilities, and IAM suites on Azure, GCP, and AWS
Experience in security reviews and threat modelling for cloud solutions using Generative AI services
In-depth understanding of cybersecurity principles, IT security controls, and related technologies
Knowledge of network security for cloud network virtualization, Kubernetes networking, and associated controls
Experience in identity and access management for cloud and container platforms
Strong stakeholder management skills
Excellent verbal and written communication skills in English, with the ability to interact effectively with technical and non-technical professionals at all levels
Ability to work with virtual teams across different countries, aligning and adapting to various work, culture, and communication styles
Preferred Qualifications & Skills:
Kubernetes and Cloud Native Associate (KCNA)
Kubernetes and Cloud Security Associate (KCSA)
Certified Kubernetes Administrator (CKA)
Certified Kubernetes Security Specialist (CKS)
Certified Kubernetes Application Developer (CKAD)
Security based industry certification such as ISC2 CISSP
Pharmaceutical industry experience would be a benefit but not essential.
Cloud agnostic industry certification in cloud security such as ISC2 CCSP and/or CSA CCSK
Cloud Service Provider security certifications such as Microsoft AZ-500, Google Security Engineer, AWS Security Engineer
Experience with SABSA and Archimate
hackajob is partnering with GSK to fill this position. Create a profile to be automatically considered for this role—and others that match your experience.
Level up the hackajob way. Verify your skills, learn brand new ones and test your ability with Pathways, our learning and development platform.