Cybersecurity Consultant - AWS Cloud, Payments & Compliance
emagine · Portugal · remote
Job Title: Senior Cybersecurity Consultant - AWS Cloud, Payments & Compliance
Reporting Line: Security Department, reporting directly to the CISO. The consultant is positioned directly below the CISO within the Security Department.
Key Stakeholders: Work with the Security Department team, IT leadership, Development and DevOps/SRE teams, Compliance, Legal, Finance, service providers, and national regulators.
Location: Remote, Portugal based
Availability: Support to the crisis-management team in the event of a major incident.
Primary Mission: Support the Security Department in addressing existing security issues and enhancing the organization's security maturity, from governance through to technical implementation on AWS.
The consultant will work hands-on, diagnosing, prioritizing, designing solutions, and ensuring knowledge transfer to empower the Security Department upon completion of the assignment.
Main Responsibilities:
Core duties include:
- Design a secure AWS multi-account architecture with strict segmentation.
- Harden identity management and ensure least-privilege access.
- Manage the security posture using various AWS security services.
- Integrate security into CI/CD processes.
- Implement centralized logging and detection systems.
- Lead compliance initiatives with PCI DSS and ISO 27001.
- Conduct risk analysis and manage supplier relationships.
- Deploy an awareness program covering security threats.
- Define and govern AI usage policies.
Key Requirements:
- Master's degree in Computer Science, Cybersecurity or equivalent.
- Minimum 10 years of experience in information-systems security.
- At least 5 years of experience in production AWS environments.
- Proven experience in regulated environments such as payments or banking.
- One end-to-end PCI DSS compliance project and ISO 27001 project.
- Experience with hands-on consulting assignments in security and development teams.
- Proficiency in AWS security services, DevSecOps, and application security.
- Fluency in French and English is essential.
Nice to Have:
- CISSP, AWS Certified Security - Specialty, ISO 27001 certifications.
- Experience in risk management and incident response.
- Knowledge in automation and scripting languages.
Other Details:
A focus on compliance with established frameworks such as PCI DSS and ISO 27001 is emphasized, alongside risk management practices in the cybersecurity domain.