SIGN IN
Business Security Consultant jobs in United States
info-icon
This job has closed.
company-logo

EY · 1 month ago

Business Security Consultant

EY is a global leader in assurance, consulting, tax, and transaction services, dedicated to building a better working world. They are seeking a Business Security Consultant to enhance cloud security across a portfolio of applications hosted in Azure, focusing on the implementation of the Wiz CNAPP platform and ensuring compliance and risk reduction in cloud environments.
Non ProfitSoftwareAssociation
check
Growth Opportunities
check
H1B Sponsor Likelynote

Responsibilities

SME (subject matter expert) to mature/advance our cloud security posture using the Wiz CNAPP across the Azure cloud platform. Guide and help Integrating Wiz to drive risk-based remediation with product/DevOps teams and automate guardrails that keep our environment compliant and resilient
Drive the implementation of existing and new features of Wiz and build the capabilities of CNAPP within EY
Develop, tune, and enforce security policies, requirements, standards, and procedures for cloud environments and containerized workloads, including Kubernetes clusters setup, and orchestration solutions, emphasizing vulnerability reduction and compliance
Collaborate with cross-functional teams to shift left (IaC scanning in CI/CD, approve/deny policies), integrate security best practices into the software development lifecycle (SDLC) and continuous integration/continuous deployment (CI/CD) pipelines
Develop and implement security automation solutions to continuously monitor cloud environments for compliance, threats, and performance anomalies
Automate ingestion of security defects and vulnerability findings to Jira/ServiceNow
Conduct regular security assessments, vulnerability scans, and threat modeling for cloud environments. Identify, evaluate, and mitigate risks in cloud infrastructure using automated/customized methods
Work with cross-functional teams, including security architects, engineers, developers and product owners to explore new ideas and develop innovative ways to automate, monitor, and improve security at scale across cloud platforms
Work with Security Ops and Incident response teams to investigate and remediate security incidents, providing expertise on cloud-specific attack vectors and mitigation strategies
Generate dashboards and executive metrics (risk reduction, SLA adherence, coverage) for assigned portfolio of business products and services. Report related security risks, incidents, and findings to leadership and relevant stakeholders
Collaborate with stakeholders to define project scope, deliverables, and expectations, ensuring alignment with business objectives
Identify gaps in existing security tools and services, and, when necessary, collaborate with development teams to create custom security solutions to protect the organization

Qualification

Microsoft AzureCloud Native Application Protection Platform (CNAPP)Wiz CNAPP platformCloud Security ArchitectureCloud Security ConfigurationCloud Security GovernanceDevSecOpsCI/CD pipelinesInfrastructure as Code (Terraform)Infrastructure as Code (CloudFormation)Scripting (Rego)Scripting (Python)Scripting (TypeScript)APIsWebhooksSecurity AutomationVulnerability ScanningCompliance AssessmentsIdentity and Access Management (IAM)Network SecurityFirewallsAudit and LoggingISO 27001OWASPSOC 1SOC 2Vendor Risk ManagementCISSPGIAC CertificationsAzure Security Engineer Certification

Required

Bachelor's degree in Computer science, Information Security, or related field
8+years of experience working as a Cloud Security Engineer/Architect with Wiz (or similar CNAPP platforms and capabilities)
Hands-on experience with Wiz (or similar CNAPP) capabilities at Enterprise level including – CSPM, CWPP, Vulnerability scanning, Compliance assessments, DevSecOps integration
CI/CD familiarity (GitHub/GitLab/Azure DevOps), IaC (Terraform/CloudFormation)
Scripting/automation (Rego/Python/TypeScript), APIs/webhooks, event pipelines
Strong understanding of DevSecOps principles and practices
Must possess excellent communication, presentation, and collaboration skills
Frameworks: CIS Benchmarks, NIST 800‑53, 800‑190, ISO 27001/27002, SOC 2 and other industry standards

Preferred

Relevant security certifications such as CISSP or GIAC certs or Azure Security Engineer is a plus
Bonus: data classification (GDPR/CCPA), Container/Kubernetes security (EKS/AKS)

Benefits

Medical and dental coverage
Pension and 401(k) plans
A wide range of paid time off options
Team-led and leader-enabled hybrid model
Flexible vacation policy
Time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being

Company

EY is building a better working world by creating new value for clients, people, society, the planet, while building trust in the capital markets.

H1B Sponsorship

EY has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
9%
Represents job field similar to this job
Management and Executive
Accounting and Finance
Engineering and Development
Trends of Total Sponsorships
*2026 (3)
2025 (3)
2023 (16)

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Carmine Di Sibio
Global Chairman and CEO
linkedin
leader-logo
John Woodby
Chief Executive Officer, EY Capital Advisors, LLC
linkedin
Company data provided by crunchbase