03/07/2020
Summary
The Cloud Security Engineer will work closely with the DevOps team for cloud security design with top-notch security best practices and is responsible for engineering secure AWS cloud environments and infrastructure. As a subject matter expert, you'll ensure the confidentiality, integrity, and availability of cloud-based and Internet accessible systems and services that support the core business functions.
Roles and Responsibilities
• Assist in the planning of Security roadmaps and lifecycle management
• (repeat)Design, integration, and testing of a suite of tools for security management of multi-tenant and single-tenant public cloud application services.
• Implementation of technological solutions dedicated to the data protection in cloud
• Configuration changes to improve the performance, usability, and value of cyber analysis tools.
• Perform security research, document and communicate the findings with respect to industry best practices/emerging technologies to secure the cloud infrastructure
• Assess overall cloud security posture. Redesign or evolve the posture as necessary to meet all the needs of a modernization of security within organization.
• Provide technical expertise relevant to the development, implementation, and updates to PKIs cloud security policies, procedures, guidelines to ensure company compliance.
• Implement Security and Disaster Recovery measures and drive automation in the cloud architecture.
• Implement security analytics, reporting and metrics program and to support security incidents and analysis with your technical expertise.
• Maintain and improve processes, tools, and documentation that will support production security requirements in the best manner possible
• Perform periodic technical reviews (including PEN testing, Vulnerability assessment) for Corporate and Cloud Infrastructure.
• Automate the configuration and installation of API Gateways
• Lead and Support configuration of Load balancers (Cloud and On-Prem)
YOU HAVE:
Work Experience
• 10+ years of IT industry experience in the domain of IT applications or IT infrastructure services
• 5+ Years of experience in IT security domain including IT security design and implementations
• 3+ years of experience with cloud environment and security systems
• 2+ years of progressive hands-on technical experience in solution design and architecture with primary focus on security products
Key Competencies
• Experience with security management of cloud based services (SaaS) in a fast-paced agile environment.
• Requires a specific understanding of Application and Operating system hardening, Pe*******on testing, Vulnerability assessments, Security audits, IPS, Firewalls, Threat management, SIEM, DR testing,
• Experience architecting, deploying and managing a suite of security management tools, including WAF, NGFW, IDS/IPS, SIEM, DDOS protection, Pen-testing, vulnerability management, and anti-malware.
• Hands-on experience with security management of virtual machines, containers, and applications.
• Excellent oral and written communication skills
• Direct experience implementing AWS and Azure cloud security services
• Knowledge in information security or IT risk management.
• Knowledge of SANS Top 20 Critical Security Controls and OWASP Top 10
• Knowledge of global and domestic regulations and standards (FISMA/NIST, SSAE 16, Data Privacy, ISO 27001/27002)
Technical Skillset/Experience
• Experience in configuring, deploying and managing services such AWS Control Tower, CloudWatch, CloudTrail, GuardDuty and KMS
• Experienced in configuring, deploying and managing application level security in the cloud using services such as AWS WAF & AWS Shield
• Deep understanding of concepts such as Service Control Policies, Config Rules and Access Control Lists
• Experience designing, deploying, and supporting production cloud environments, particularly multi-region/multi-AZ environments.
• Privileged Account management, etc.
• Must be experienced with design, deploy and configure network and enterprise security solutions.
• Experience working within AWS and/or Azure cloud environment.
• Continuous monitoring, alerting and logging of all applications layers and all infrastructure (e.g. CloudWatch, New Relic, Splunk, Prometheus)
• Self-healing clusters using robust health-check services and cloud load balancers (e.g. ELB/ALB/ELB, ECS)
• Automated build, test, and deployment through modern CI/CD
• Infrastructure-as-code via Terraform, CloudFormation and Ansible
• Programming and scripting knowledge (Shell scripting, Python, Ansible)
• Implementing Security and Access Control (OAuth. JWT, SAML, TLS/SSL)
Certifications
• Mandatory Certifications in public cloud (level of architect, security engineer/specialist)
• Preferred Certifications in CISSP, CISM, CCSP, CCSK