Cyber Security - Associate
NopalCyber Cyber Security - Associate
- Deliver architecture and security assessments across cloud, applications, and infrastructure.
- Drive implementation of security controls aligned to modern architectures (microservices, cloud-native)
- Act as technical advisor to client engineering and infrastructure teams.
- Improve security posture across key domains (cloud, IAM, AppSec, network)
Requirements
- Perform security architecture reviews across cloud, on-prem, and hybrid environments
- Assess and secure modern application architectures, including microservices and APIs
- Provide hands-on advisory for cloud security (AWS/Azure/GCP), including configurations and posture improvements
- Drive implementation and validation of security controls across infrastructure, applications, and identity layers
- Work closely with engineering, DevOps, and infrastructure teams to embed security into design and deployment
- Identify security gaps, misconfigurations, and architectural risks, and define remediation approaches
- Support secure design patterns for IAM, network segmentation, data protection, and workload security
- Act as a technical escalation point for complex security issues, incidents, and design decisions
- Guide clients on tool selection, integration, and optimization across security domains
- Coordinate and, where required, directly contribute to areas such as AppSec, IAM, cloud security, and SOC improvements
- Reduce reliance on external SMEs by providing cross-domain expertise for common use cases
- Support client engagements including solution discussions, technical workshops, and advisory sessions.
- Translate technical findings into clear, actionable recommendations for stakeholders
- Collaborate with vCISO and Analysts to ensure alignment between strategy, execution, and technical implementation
- Bachelor’s degree in engineering, IT, or related field
- AWS / Azure Security Certifications (Associate or Specialty)
- CISSP / CCSP / CISM (preferred)
- Kubernetes / Container Security certifications (good to have)
- 5–10 years in cybersecurity with strong technical depth
- Experience in cloud security, application security, or security architecture roles
- Background in consulting, MSSP, or multi-client environments preferred
- Hands-on experience with modern architectures (cloud-native, microservices, APIs)
- Strong knowledge of:
- Cloud security (AWS / Azure / GCP)
- Application security (SAST, DAST, API security)
- Microservices and container security (Docker, Kubernetes)
- IAM and Zero Trust architectures
- Network security (segmentation, firewalls, WAF)
- Experience with:
- Security architecture design and reviews
- DevSecOps and CI/CD security integration
- Vulnerability management and remediation strategies
- Ability to engage with technical and engineering teams
- Strong problem-solving capability
- Ability to translate security requirements into implementable solutions
- Experience conducting technical workshops and advisory sessions
- Strong technical ownership and hands-on mindset
- Ability to operate across multiple domains without silos
- Structured and solution-oriented thinking
- Comfortable in client-facing and advisory roles
- Ability to balance depth with speed in delivery