Cloud Security Analyst
Listed on 2026-01-01
-
IT/Tech
Cybersecurity, Systems Engineer
Job Description Are You Ready to Make It Happen at Mondelēz International? Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours.
The Cloud Security Analyst is responsible for ensuring the security, compliance, and operational integrity of enterprise workloads across cloud environments, including mostly AWS, Azure, and Google Cloud Platform. This role provides hands‑on security expertise, drives cloud governance maturity, and partners closely with engineering, operations, and compliance teams to reduce risk and strengthen the organization’s multi‑cloud security posture.
Key Responsibilities Cloud Security Posture Management (CSPM)- Monitor and manage security posture across AWS, Azure, and GCP using CSPM tools such as Wiz and Falcon Cloud Security.
- Identify misconfigurations, vulnerabilities, and high‑risk assets.
- Track and document remediation efforts.
- Develop dashboards, metrics, and reporting for cloud compliance and risk reduction.
- Review and enforce least‑privilege access across cloud and hybrid environments.
- Maintain identity guardrails (SSO, MFA, conditional access).
- Conduct periodic access reviews and support privileged access governance.
- Partner with engineering teams to design secure architectures following NIST, CIS, and company standards.
- Validate Infrastructure-as-Code for compliance.
- Support deployment and maintenance of cloud‑native security controls.
- Analyze cloud alerts and support cloud‑focused incident response.
- Coordinate with SOC teams to refine monitoring rules.
- Contribute to cloud security policies, standards, and baselines.
- Perform compliance reviews for CIS, NIST, ISO 27001.
- Support audits and evidence gathering.
- Work with Dev Ops teams to embed security into CI/CD pipelines.
- Implement automated security checks.
- Create scripts to automate security tasks.
- Serve as a trusted partner to cloud engineering, network, application, and GRC teams.
- Provide secure design guidance and threat modeling support.
- Communicate risks clearly to technical and executive stakeholders.
- 5 years of experience in cloud security or cloud engineering.
- Hands‑on experience securing AWS, Azure, and GCP.
- Strong understanding of IAM, network security, encryption, and cloud shared responsibility models.
- Experience with CSPM tools, such as Wiz and Falcon Cloud Security.
- Solid understanding of IaC concepts.
- Familiarity with SIEM/SOAR and compliance frameworks.
The base salary range for this position is $106,300 to $146,190; the exact salary depends on several factors such as experience, skills, education and location. In addition to base salary, this position is eligible for participation in a highly competitive bonus program with possibility for over achievement based on performance and company results.
In addition, Mondelez International offers the following benefits: health insurance, wellness and family support programs, life and disability insurance, retirement savings plans, paid leave programs, education related programs, paid holidays and vacation time. Some of these benefits have eligibility requirements. Many of these benefits are subsidized or fully paid for by the company.
No Relocation support available.
Business Unit SummaryThe United States is the largest market in the Mondelēz International family with a significant employee and manufacturing footprint. Here, we produce our well‑loved household favorites to provide our consumers with the right snack, at the right moment, made the right way. We have corporate offices, sales, manufacturing and distribution locations throughout the U.S. to ensure our iconic brands—including Oreo and Chips Ahoy!
cookies, Ritz, Wheat Thins and Triscuit crackers, and Swedish Fish and Sour Patch Kids confectionery products—are close at hand for our consumers across the country.
Mondelēz Global LLC is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).