Pesquisa de palavras-chave (visually hidden)
Cidade, estado ou CEP (visually hidden)
Raio de pesquisa (visually hidden) Raio 5 km 15 km 25 km 35 km 50 km
ABOUT GREYSTAR
Greystar is a leading, fully integrated global real estate platform offering expertise in property management, investment management, development, and construction services in institutional-quality rental housing. Headquartered in Charleston, South Carolina, Greystar manages and operates over $350 billion of real estate in more than 260 markets globally with offices throughout North America, Europe, South America, and the Asia-Pacific region. Greystar is the largest operator of apartments in the United States, managing over one million units/beds globally. Across its platforms, Greystar has nearly $79 billion of assets under management, including over $34 billion of development assets and over $36.5 billion of regulatory assets under management. Greystar was founded by Bob Faith in 1993 to become a provider of world-class service in the rental residential real estate business. To learn more, visit www.greystar.com.
JOB DESCRIPTION SUMMARY
JOB DESCRIPTION
Cloud Security Architecture & Standards
Define and own cloud security architecture patterns across cloud platforms - IAM guardrails, network segmentation, encryption standards, and secrets management - that the Infrastructure, Delivery, and Reliability tracks build against.
Own cloud Policy as code, including custom policy definitions, initiative assignments, and enforcement-mode governance across the cloud estate.
Establish secure-by-default reference patterns - landing zone security baseline, mandatory private endpoint use, default-deny network posture - in direct partnership with the Principal Cloud Engineer.
Partner with Information Security architecture so enterprise security policy translates correctly into cloud-native controls, acting as the translator of record between enterprise policy and cloud implementation.
Application, Pipeline & Supply-Chain Security
Build and configure security tooling directly into CI/CD pipelines - standing up IaC scanning, container image scanning, and SAST/DAST tools hands-on alongside the Delivery team.
Own supply-chain risk review for third-party CI/CD integrations (GitHub Actions, MCP servers, external connectors), partnering with the Senior DevOps Engineer on remediation.
Work hands-on with application development and AI/ML teams to harden new cloud-native and AI workloads before they ship - configuring network isolation, securing model endpoints and API keys, and directly fixing findings during the build.
Personally triage and remediate critical pipeline findings, working directly in the codebase or configuration with engineering teams to fix root causes.
Identity & Access Security (Cloud-Specific)
Define least-privilege RBAC and conditional access standards for cloud resources, partnering with Cloud Engineering on execution against established naming and group-based delegation conventions.
Own the just-in-time / privileged identity model for privileged cloud roles.
Own recurring access reviews and offboarding validation for service principals, managed identities, and human RBAC assignments across the cloud estate.
Detection, Response & Operations
Partner with Cybersecurity Operations to tune Defender for Cloud recommendations and Sentinel analytics rules for cloud-specific signal, reducing noise and closing detection gaps as new services and connectors come online.
Recommend and help prioritize which cloud workloads and connectors get phased into Sentinel next, based on risk and blast radius across the estate.
Contribute cloud-specific escalation criteria to the runbooks the Operations Command Center and Cybersecurity Operations execute against.
Deliver initial and ongoing training to Cybersecurity Operations on cloud-native anomalies - managed identity misuse, unusual resource provisioning, anomalous Entra ID sign-ins - so detection and tuning quality improve over time.
Governance, Risk & Compliance
Actively work down the CSPM and vulnerability backlog - rewriting Terraform to close a misconfiguration, migrating a plaintext secret to Key Vault, reconfiguring an identity - personally closing critical and high findings.
Map cloud infrastructure controls to relevant compliance frameworks (SOC 2, PCI, CIS Benchmarks) in partnership with enterprise Information Security, translating framework language into actual Azure/AWS configuration.
Architecture Review & Technical Authority
Serve as the primary cloud security voice in cloud architecture design reviews across Infrastructure, Application Development, and Data Engineering, providing the security assessment that informs whether a design moves forward.
Maintain security documentation, reference architectures, and runbooks specific to the cloud estate.
Qualifications:
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
8+ years of experience in cloud security, security architecture, or cloud infrastructure engineering with a security focus, including demonstrated experience operating at a senior or principal level.
Deep, hands-on, expert-level experience securing Azure environments specifically - Azure Policy, Defender for Cloud, Sentinel, network security groups, and private endpoints - sufficient to set enterprise standards.
Solid working knowledge of AWS security services (IAM, Security Hub, GuardDuty, Config) sufficient to extend the same rigor as the estate expands beyond Azure.
Experience embedding security into Infrastructure as Code - reviewing and hardening Terraform, ARM, or Bicep - not only auditing after deployment.
Experience defining and enforcing CI/CD pipeline security gates: SAST/DAST, container image scanning, dependency scanning, and secrets detection.
Expert-level understanding of cloud identity security - Entra ID, RBAC and least-privilege design, just-in-time access, and workload identity federation - deep enough to author an identity architecture.
Experience identifying and triaging cloud-specific security signals - anomalous sign-ins, managed identity misuse, unusual resource provisioning - sufficient to train and hand off to an incident response team.
Proficiency in scripting and automation (PowerShell, Python, or Bash) for security tooling and remediation at scale.
Excellent executive communication skills, with the demonstrated ability to defend a security position persuasively to senior technical leadership and to explain risk and remediation priority to both engineers and non-technical stakeholders.
Preferred Qualifications:
Experience securing Databricks or data platform environments specifically, including Unity Catalog permissions models and data plane network isolation.
Experience with container and Kubernetes security (AKS), including image provenance and runtime security.
Familiarity with securing AI/ML and LLM-adjacent infrastructure - model serving endpoints, API key and secret exposure patterns, and agentic tool or third-party integration risk.
Direct experience mapping cloud controls to compliance frameworks (SOC 2, PCI DSS, CIS Benchmarks) in a real audit context.
Cloud security certifications (e.g., Microsoft Certified: Cybersecurity Architect Expert, AWS Certified Security - Specialty, CCSP) are a plus but not required.
#LI-BB1
The salary range for this position is $140,000 - $170,000 USD Annually.
#LI-Remote
Additional Compensation:
Many factors go into determining employee pay within the posted range including business requirements, prior experience, current skills and geographical location.
Robust Benefits Offered*:
*Benefits offered for full-time employees. For Union and Prevailing Wage roles, compensation and benefits may vary from the listed information above due to Collective Bargaining Agreements and/or local governing authority.
Greystar will consider for employment qualified applicants with arrest and conviction records.
Greystar is an equal opportunity employer and does not discriminate in employment on the basis of race, color, religion, sex (including pregnancy, sexual orientation, and gender identity), national origin, age, disability, genetic information, military or veteran status, or any other characteristic protected by applicable law.
This position may be performed remotely anywhere within the United States except the state of Alaska.
Important Notice: Greystar will never request your banking details or other sensitive personal information during the interview process. Greystar does not conduct any interviews via text or messaging, and all communication will come from official Greystar email addresses (@greystar.com). If you receive suspicious requests, please report them immediately to AskHR@greystar.com.
ANTICIPATED CLOSING DATE
This date may be subject to change due to evolving business needs.
Você não visualizou nenhuma vaga recentemente.
Você ainda não tem nenhuma vaga salva? Então comece a procurar! Depois de encontrar uma vaga de seu interesse, clique no botão ou ícone Salvar vaga nos resultados da pesquisa ou nas páginas de descrição de vagas.
Inscreva-se para receber novos alertas de vagas com base em suas preferências.
Nome
Sobrenome
Endereço de e-mail
Código do país+1+1242+1246+1264+1268+1284+1340+1441+1473+1649+1664+1670+1671+1684+1758+1767+1784+1849+1868+1869+1876+1939+20+211+212+213+216+218+220+221+222+223+224+225+226+227+228+229+230+231+232+233+234+235+236+237+238+239+240+241+242+243+244+245+248+249+250+251+252+253+254+255+256+257+258+261+262+264+265+266+267+268+269+27+290+291+297+298+299+30+31+32+33+34+345+350+351+352+353+354+355+356+357+358+359+36+370+371+372+373+374+375+376+377+378+379+380+381+382+385+386+387+389+39+40+41+420+421+423+43+44+45+46+47+48+49+500+501+502+503+504+505+506+507+508+509+51+52+53+54+55+56+57+58+590+591+593+594+595+596+597+598+599+60+61+62+63+64+65+66+670+672+673+674+675+676+677+678+679+680+681+682+683+685+686+687+688+689+690+692+7+77+81+82+84+850+852+853+855+856+86+872+880+886+90+91+92+93+94+95+960+961+962+963+964+965+966+967+968+970+971+972+973+974+975+976+977+98+992+993+994+995+996+998Número de telefone
Carregar currículoRemover
Promoção de adesão
Confirm Email
Ao me inscrever, reconheço que li o aviso de privacidade da Greystar e desejo receber comunicações por e-mail e SMS. Entendo que posso optar por deixar de receber comunicações por e-mail e SMS a qualquer momento.
ENVIAR