SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
iCapital seeks an Assistant Vice President, Cloud Security Engineer to lead the establishment and management of cloud security programs across AWS, Azure, and GCP infrastructure. This is a deeply technical individual contributor role within the Information Security organization's Security Engineering team, responsible for designing and implementing secure cloud architectures, driving automation, and continuously identifying and addressing security gaps.
Key responsibilities include building and managing cloud security programs across major cloud platforms; designing, implementing, and validating secure cloud infrastructure architectures that meet established security standards; applying Zero Trust architecture principles across cloud infrastructure design and access models; driving continuous detection, remediation, and resolution of cloud vulnerabilities and misconfigurations using CSPM tooling such as AWS Security Hub, Wiz, or equivalents; and building automation capabilities for continuous monitoring and alerting.
The role requires partnering with engineering teams to drive adoption of security standards and best practices, embedding security early in the development lifecycle, and supporting a shift-left security culture. Collaboration with the SOC on cloud detection engineering, assistance with Risk and Governance teams on cloud-related policies and standards, and engagement with Platform, DevOps, and Software Engineering teams to deliver security initiatives and provide guidance are core responsibilities.
Required qualifications include 6–9 years of experience in cloud environments with AWS as the primary platform, including hands-on expertise in cloud security architecture and infrastructure design. Proficiency with AWS-native security services (IAM, Config, KMS, Secrets Manager, CloudWatch, CloudTrail, GuardDuty) is essential. Experience with cloud identity and access architecture, including federation (Okta), RBAC, ABAC, and service-to-service authentication models, is required. Hands-on experience with Infrastructure as Code tooling such as AWS CDK, CloudFormation, or Terraform is necessary. Relevant cloud or security certifications (AWS Certified Solutions Architect, AWS Certified Security – Specialty, CISSP, CCSP) are a plus.
The role operates on a hybrid schedule: four days in the Lisbon office with one day (Friday) remote flexibility. iCapital offers competitive salary, annual performance bonus, equity for full-time employees, 100% employer-paid health and dental insurance, and generous paid time off.