Search by job, company or skills

Cloud Security Engineer

Cloud Security Engineer

McCormick & Company
3-6 Years
Not Disclosed
  • Posted 15 hours ago
  • Be among the first 10 applicants

Job Description

Cloud Security Engineer –Technology and Engineering

McCormick & Company, Inc., a world leader in the spice, flavor and seasonings industry, is seeking a full time Cloud Security Engineer – Technology and Engineering. This position will report to the Sr. Manager Cybersecurity - Technology and Engineering.

Position Overview:

The Cloud Security Engineer is an individual contributor role focused on improving the security posture of McCormick's cloud environments. The role will help implement and operate cloud-native security controls, identify and reduce cloud risk, and enable secure adoption of cloud services.

Working closely with cloud platform, infrastructure, DevOps, application, identity, and Security Operations teams, this engineer will support secure cloud configurations, identity and access controls, posture management, automation, and remediation of security findings.

This role is suited to a hands-on cloud security professional with strong practical knowledge of one primary cloud platform and the ability to collaborate effectively across a global organization.

This is an opportunity to help shape and mature cloud security capabilities in a global organization. The role will directly contribute to secure cloud adoption, improved visibility of cloud risk, stronger governance, and more efficient remediation through practical security automation and engineering partnerships.

Key Responsibilities:

Description

  • Operate and improve cloud security posture management capabilities, including visibility of cloud assets, configuration risks, vulnerabilities, and policy compliance. Prioritize findings based on business impact and risk, and work with cloud and application teams to drive remediation.
  • Design, implement, and maintain practical cloud security standards, guardrails, and baseline configurations for identity, networking, storage, compute, logging, encryption, and workload protection. Help prevent security drift through policy enforcement and repeatable secure configuration patterns.
  • Support least-privilege access across cloud environments by identifying excessive permissions, inactive identities, risky access paths, and service-account risks. Partner with IAM and platform teams on access reviews, privileged access, and secure identity design.
  • Partner with cloud platform, infrastructure, and DevOps teams to embed security controls into infrastructure-as-code and deployment workflows. Develop or enhance automation that improves control coverage, reduces manual effort, and enables timely remediation.
  • Help improve cloud security monitoring, alert quality, and investigation readiness through cloud-native logging, security tooling, and integrations with the SIEM and Security Operations teams. Support investigation and remediation of significant cloud security findings, while SOC retains primary incident-response ownership.
  • Provide cloud security input for new services, migrations, and significant design changes. Review proposed architectures against established patterns and identify practical controls for secure deployment, data protection, segmentation, resilience, and regulatory requirements.
  • Maintain cloud security documentation, standards, exceptions, and operating procedures. Track control coverage, remediation progress, policy compliance, and key risk trends; provide concise updates to management and recommend improvements to cloud security capabilities.
  • Participate in internal workshops and architecture review boards for cloud platforms.
  • Maintains certifications and hands on experience in evolving cloud technologies.

Preferred Qualifications:

  • Bachelor's degree in information technology, Computer Science or relevant field.
  • Relevant cloud or security certifications are preferred, such as Microsoft Azure, AWS, Google Cloud, CCSP, Security+, or equivalent credentials.
  • Three to six years of experience in cloud security, cloud engineering, systems administration, security engineering, or a related technical role.
  • Hands-on experience securing at least one major cloud platform, such as Microsoft Azure, AWS, or Google Cloud Platform.
  • Experience with cloud security posture management, cloud-native security services, configuration baselines, vulnerability management, and identity and access management.
  • Working knowledge of cloud networking, encryption, logging, monitoring, and secure workload configuration.
  • Experience supporting infrastructure-as-code, policy-as-code, CI/CD, or cloud automation is preferred.
  • Scripting or automation experience using PowerShell, Python, Terraform, or similar technologies is preferred.
  • Familiarity with security frameworks and standards, such as NIST CSF, CIS Benchmarks, ISO 27001, and cloud-provider security guidance.
  • Comprehensive technical knowledge of all areas within IT plus a comprehensive understanding of all business functions and how their processes and resources interact is required.

Other skills and competencies:

  • Ability to prioritize work and manage multiple security activities in a fast-paced environment.
  • Strong analytical and problem-solving skills, with the ability to translate cloud security findings into practical remediation actions.
  • Effective written and verbal communication skills, including the ability to explain technical risks to technical and non-technical stakeholders.
  • Demonstrated ability to work collaboratively across globally distributed, cross-functional teams.
  • Strong attention to detail, ownership, follow-through, and commitment to continuous improvement.
  • Positive customer-service mindset and ability to support high-priority issues calmly and professionally.
  • Ability to maintain confidentiality and handle sensitive information appropriately.
  • Demonstrated leader of continuous improvement ideas and implementations
  • English fluency is critical.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

policy-as-code

cloud security posture management

NIST CSF

cloud-native security services

CI CD

secure workload configuration

infrastructure-as-code

configuration baselines

CIS Benchmarks

About Company

Similar Jobs

5-7 yrs
Noida, India
Skills:
Docker, Iam, Firewalls, Siem, Security Groups, Azure, Kubernetes, AWS, Vulnerability Management, Network security, VPC Security Groups, Agent-based Deployment Installation, Wiz, Adaptive Shield, Container security, Prisma Cloud Compute
3-5 yrs
Gurugram, India, Gurugram
Skills:
Cloudformation, Dlp, Cloudwatch, Terraform, Siem, AWS Security Hub, Azure, AWS, GuardDuty, VPC Flow Logs, Bicep, Microsoft Sentinel, Azure Monitor, CloudTrail
5-10 yrs
Hyderabad, Bengaluru, Noida
Skills:
Ceh, Cisco, Azure, Aws, Cissp