Security Engineer - Cloud
We are seeking a Cloud Security Engineer to join our cybersecurity team. This role will lead the design, implementation, and management of secure cloud environments while also contributing to broader security operations. In addition to cloud security responsibilities, this position will support functions like endpoint hardening, vulnerability management, Microsoft 365 security tickets, proactive investigations into potentially malicious domains, and other security tasks as assigned.
The Security Engineer is expected to have competency in a variety of security platforms, potentially including the implementation & operation of several of the following:
Cloud Security & Architecture:
- Design, implement, and maintain secure cloud configurations in line with best practices.
- Monitor and improve cloud security posture using available tools and platforms.
Endpoint & Vulnerability Management:
- Harden and secure enterprise endpoints across the organization.
- Identify, assess, and remediate vulnerabilities in a timely manner.
Threat Investigation & Response:
- Investigate potential phishing domain registrations and other external threats.
- Respond to and investigate security alerts across cloud and enterprise systems.
Microsoft 365 & Security Support:
- Address Microsoft 365 security-related tickets and requests.
- Support security controls and configurations for enterprise collaboration tools.
Also, the Security Engineer will participate in the following operational activities:
- Incident response
- Creating reports for management
- Analyze security solutions and seek improvements on a continuous basis
- Find cost-effective solutions to cybersecurity problems
- Other duties as assigned
Education Requirements:
- High School diploma required.
- Bachelor’s or master’s degree in security or technology field (or other related field), or equivalent work experience.
Recommended Experience:
- Cloud security hardening with platforms such as AWS, GCP and Microsoft Azure
- Cloud Security platforms
- Vulnerability management platforms
- Workstation full disk encryption solutions
- EDR consoles & deployments
- SIEM monitoring and deployment
- Firewall rule review/configuration
- IPS (host, network) configuration & operation
- Encryption tools & key management
- Virtualized, Hybrid, & Cloud environments
- NIST, ISO, or other security program frameworks
- Holds a current security- or audit-focused certification such as CISSP, GIAC, CEH, etc.
Required:
- Minimum 5 years of experience in cybersecurity principles, cyber threats and vulnerabilities.
- Requires knowledge of regulatory compliance, including SOX, PCI, and HIPAA requirements for information systems, security and privacy.
Equal Opportunity Employer This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.