Cloud Security Engineer

Cloud Security Engineer

17 Oct 2024
Texas, Houston, 77001 Houston USA

Cloud Security Engineer

Vacancy expired!

  • AWS Certified Security Specialty
  • Deploying Identity and Access Management systems to secure production and corporate access, such as: SSO, SAML
  • Understanding of Cloud Security across realms of Identity, Monitoring Auditing and Cryptography
  • Knowledge or experience with broad array of security technologies, such as NextGen FW, WAF, SIEM, Endpoint Security and more
  • Working knowledge or experience of information security within the enterprise
  • A strong grasp of Information Security and implemented processes to review IT infrastructure
  • Knowledge and experience with threat modeling and penetration testing, especially for web application and web APIs
  • Web security and compliance experience (e.g. Firewalls, IDS/IPS systems, DDOS prevention and PCI, HIPAA, FIPS, etc.)
  • Remediate Turbot and AWS Security Hub findings in coordination with application teams
  • Support 3rd party cloud security review in AWS and Azure
  • The security and compliance of the core infrastructure (Control tower and AWS-native tools)
  • Extending and maintaining automated enforcement of security guardrails using Turbot to ensure compliance with TMHCC security policies.
  • Monitoring, tracking and advising teams on remediation of non-compliant resources identified by Turbot and other AWS-native tools such as GuardDuty and AWS Security Hub.
  • Ensuring logging and monitoring feeds and tools are in-place and functional (feeds to Sumo Logic and Security SIEM (LogRhythm currently).
  • Implementing and maintaining AWS platform integrations with security tools such as Qualys and Crowdstrike.
  • Acting as a liaison between the CPO and the Security team (SOC) to assist with AWS-related security investigations, if needed.
  • Harden configurations using standards such as the Center for Internet Security (CIS) security benchmarks for Docker, Kubernetes, and others and keep software up to date.
  • Run containers as user (unprivileged) as opposed to root (privileged) and limit the ability for containers to escalate privileges (runAsNonRoot=true, AllowPrivilegeEscalation=false).
  • Use Software Composition Analysis (SCA) to scan all container images, as well as dynamically and statically linked dependencies and nested dependencies, for known vulnerabilities and embedded secrets.
  • Secure access to the API server and dashboard by enforcing access controls on the master node and by filtering traffic at the K8s ingress controller.
  • Enforce access control on worker nodes and ensure worker nodes are sufficiently hardened.
  • Automate repetitive tasks using tools such as AWS CLI, AWS Code, AWS Cloud Formation Template, Python, Terraform etc.

Related jobs

  • Are you an experienced, passionate pioneer in technology - a solutions builder, a roll-up-your-sleeves technologist who wants a daily collaborative environment, think-tank feel and share new ideas with your colleagues - without the extensive demands of travel? If so, consider an opportunity with our US Delivery Center - we are breaking the mold of a typical Delivery Center.

  • Are you an experienced, passionate pioneer in technology - a solutions builder, a roll-up-your-sleeves technologist who wants a daily collaborative environment, think-tank feel and share new ideas with your colleagues - without the extensive demands of travel? If so, consider an opportunity with our US Delivery Center - we are breaking the mold of a typical Delivery Center.

  • Cloud Security Operations Lead (AWS)

  • Cloud Security Architect

  • Are you an experienced, passionate pioneer in technology? A cloud solutions builder who wants to work in a collaborative environment. As an experienced Lead Cloud Native Engineer, you will have the ability to share new ideas and collaborate on projects as a consultant without the extensive demands of travel. Consider an opportunity with our US Delivery Center - we are breaking the mold of a typical Delivery Center.

  • Senior AWS Cloud Native Developer

  • The Senior Application Security Engineer position is a hands-on role that involves evaluating and enforcing application security in all phases of the Software Development Life Cycle (SDLC). This position will work closely with our engineering teams to define and implement application best practice security controls, perform software architecture and design reviews, threat modeling, conduct white box security testing, and support the identification, interpretation, and remediation of vulnerabilities across a variety of applications, programming languages, and platforms with a focus on supporting our GovCloud environment.

Job Details

  • ID
    JC21264429
  • State
  • City
  • Job type
    Contract
  • Salary
    Depends on Experience
  • Hiring Company
    Radus Tek Services
  • Date
    2021-10-06
  • Deadline
    2021-12-04
  • Category

Jocancy Online Job Portal by jobSearchi.