Cloud Security Engineer
Bank OZK
- Location
- Little Rock, Arkansas
- Employment
- Full Time
- Work model
- On-Site
- Level
- Mid
- Posted
- 1h ago
Skills
About this role
Why Bank OZK Founded on a legacy of more than 120 years in banking, Bank OZK is much more than just a company. We’re nationally recognized as an industry leader in financial services. That means we combine exceptional service with innovative technologies to deliver smart solutions to our clients across the country. We’re investing in small businesses, fueling economies in local communities and changing skylines in the largest cities across America. Here, we're not simply filling roles. We're fostering even greater careers. The foundation for a great career starts with an exceptional team and a comprehensive benefits package. We believe in providing our dedicated team members with the best resources to support their physical, mental and financial wellbeing, including generous PTO, 401(k) matching, health, dental, vision (and pet!) insurance as well as special perks and discounts. Learn more about Bank OZK benefits . Job Purpose & Scope Responsible for ensuring the secure design, implementation, and operation of Bank OZK’s cloud environments. The Cloud Security Engineer works closely with IT, Labs, Data teams, Third-Party Risk Management, and application owners to implement cloud security controls and enforce compliance with Bank policies and industry regulations. Essential Job Functions Supports the onboarding and risk assessment of new Cloud Service Providers (CSPs) through the Third-Party Risk Management (TPRM) process. Evaluates CSP security controls against Bank OZK’s Cloud Security Standard and regulatory requirements, ensuring that proposed cloud solutions meet all legal and compliance criteria before approval. Implements and maintains cloud security controls across SaaS, PaaS, and IaaS environments, applying Bank-approved secure configuration baselines (leveraging industry benchmarks like CIS) for cloud resources (VMs, containers, storage, etc.) and enforces “secure-by-default” settings during deployments. Collaborates with OZK Technology teams to design cloud architectures that incorporate network segmentation, encryption, and other security best practices from start to completion. Integrates cloud platforms and applications with the Bank’s centralized Single Sign-On (SSO) and identity management systems. Ensures that cloud activity logs are enabled, collected, and integrated with Bank OZK’s Security Information and Event Management (SIEM) and monitoring systems. Develop detections or alert rules to monitor cloud events for signs of compromise or policy violations. Investigates and responds to cloud security incidents in coordination with the Security Operations Center (SOC), helping to remediate issues and implement lessons learned. Manages cloud environments for security compliance and misconfigurations using automated Cloud Security Posture Management (CSPM) tools or scripts. Performs configuration audits and vulnerability scans of cloud assets and works with infrastructure and application teams to remediate identified weaknesses or document risk acceptances according to the Bank’s vulnerability management standards. Collaborates with software development teams and Application Security Engineers on secure deployment of cloud-native applications. Ensures cloud-hosted applications follow secure coding and deployment practices aligned with Bank standards (e.g. perform threat modeling, enforce secure SDLC requirements). Implements cloud-native application security controls such as web application firewalls (WAFs) for internet-facing apps and ensure proper network restrictions (security groups, private endpoints) for sensitive data stores Embeds security into the CI/CD pipeline and infrastructure-as-code processes. Works with DevOps engineers to implement automated security checks for cloud infrastructure templates and application code (e.g. IaC scanning, container image scanning, secret leakage detection) [1] [2] . Advises on secure configuration of CI/CD tools and use of secure secret