About the Job
Lilly is hiring for an Engineer - Cybersecurity role in its Cybersecurity organization. The position is part of the Threat Mitigations team and focuses on cloud security, vulnerability management, threat mitigation and DevSecOps security practices.
The role involves working across cloud environments including AWS, Azure and GCP, identifying security risks, supporting remediation activities and helping engineering teams improve their security practices.
Job Overview
Eligibility Criteria
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent work experience.
- 1–3 years of cybersecurity experience, with a focus on cloud security and/or vulnerability management.
- Working knowledge of cloud security fundamentals across AWS, Azure and GCP, including IAM, network segmentation, encryption, and logging/monitoring.
- Hands-on experience with one or more CSPM platforms such as Wiz, Prisma Cloud, Orca Security, Microsoft Defender for Cloud, or similar.
- Experience with vulnerability scanners and management platforms such as Wiz, Qualys, Rapid7, or similar.
- Solid understanding of vulnerability management processes, including CVSS scoring and risk-based prioritization.
- Familiarity with cloud-native architectures including containers, Kubernetes and serverless.
- Understanding of cloud IAM policies, least-privilege access, OAuth 2.0 and SAML.
- General familiarity with firewalls, encryption, IAM, SIEM and DLP.
- Strong problem-solving and analytical skills focused on identifying, addressing and mitigating security risks.
- Ability to work effectively with developers, platform engineers and security peers.
Key Responsibilities
- Assist Cyber Threat Mitigation Leads in identifying, assessing and developing solutions to reduce security threats.
- Manage vulnerabilities through discovery, triage, ownership assignment, SLA tracking and remediation verification.
- Continuously monitor multi-cloud environments across AWS, Azure and GCP using CSPM platforms such as Wiz to identify misconfigurations, excessive permissions and compliance drift.
- Disposition findings from scanning tools, validate issues and provide clear remediation guidance to developers.
- Participate in implementing mitigation strategies across cloud workloads, containers, APIs and infrastructure-as-code.
- Contribute to threat modeling activities for new and existing cloud architectures and applications.
- Support risk burndown through deployment of security tools, including hands-on involvement in difficult-to-solve issues.
- Collaborate with diverse teams and stakeholders to promote security best practices.
- Support tracking and reporting of security mitigation metrics to provide visibility into risk remediation efforts.
- Integrate security tooling into CI/CD pipelines to enable shift-left practices and automated security checks during the build process.
- Support pull request gating, secrets scanning, dependency scanning and infrastructure-as-code scanning across engineering teams.
- Develop scripts to enable automation of scanning and triaging workflows.
Skills Required
- Cloud Security: AWS, Azure, GCP, IAM, network segmentation, encryption, logging and monitoring
- CSPM: Wiz, Prisma Cloud, Orca Security, Microsoft Defender for Cloud
- Vulnerability Management: Wiz, Qualys, Rapid7, CVSS scoring and risk-based prioritization
- Cloud-Native Security: Containers, Kubernetes, serverless architectures, APIs and IaC
- Identity & Authentication: Cloud IAM policies, least-privilege access, OAuth 2.0 and SAML
- Security Controls: Firewalls, encryption, IAM, SIEM and DLP
- Problem Solving: Strong analytical and security risk mitigation skills
- Collaboration: Ability to work with developers, platform engineers and security peers
Skills to Add in Your Resume
| Cloud Security | AWS, Azure, GCP, Cloud Security, IAM, CSPM |
| Security Platforms | Wiz, Prisma Cloud, Orca Security, Microsoft Defender for Cloud |
| Vulnerability Management | Vulnerability Scanning, CVSS, Risk Prioritization, Qualys, Rapid7 |
| Cloud Architecture | Containers, Kubernetes, Serverless, IAM, Least-Privilege Access |
| DevSecOps | CI/CD Security, Pull Request Gating, Secrets Scanning, Dependency Scanning |
| IaC Security | Terraform, CloudFormation, Infrastructure-as-Code Scanning |
| Automation | Python, Bash, PowerShell, Security Automation |
| Threat Modeling | STRIDE, PASTA, Attack Trees |
Benefits
- Exposure to cloud security across AWS, Azure and GCP.
- Hands-on involvement in cloud security posture management and vulnerability management activities.
- Experience with threat mitigation across cloud workloads, containers, APIs and infrastructure-as-code.
- Opportunity to work with DevSecOps practices including CI/CD security checks, scanning and pull request gating.
- Cross-functional collaboration with developers, platform engineers and security peers.
Who Can Apply?
- Candidates with a bachelor's degree in Computer Science, Information Security or a related field, or equivalent work experience.
- Professionals with 1–3 years of cybersecurity experience focused on cloud security and/or vulnerability management.
- Candidates with practical knowledge of AWS, Azure and GCP cloud security fundamentals.
- Candidates with experience using CSPM and vulnerability management platforms.
- Candidates familiar with cloud-native technologies, IAM, authentication standards and security controls.
- Candidates with strong analytical, problem-solving and collaboration skills.
How to Apply
⚠️ Disclaimer
The information provided on TechJobsAlert is collected from official company career pages and other publicly available sources for informational purposes only.
Salary, stipend, and other compensation mentioned on this page are estimated based on market research and publicly available information unless officially disclosed by the employer. Actual compensation may vary.
We do not charge any fee for job updates or applications and are not involved in the recruitment or selection process. We do not guarantee interviews, selection, or job offers.
Job openings, eligibility criteria, application deadlines, locations, and other details may change or the employer may stop accepting applications at any time without prior notice. Candidates are strongly advised to verify all information on the official careers website before applying.
