Security Engineer
Security Engineer
Reports to: Security Operations Manager
SUMMARY OF RESPONSIBILITIES
As a Cloud Security Engineer, you will be responsible for designing, developing, and implementing cloud-based solutions for our customers. You will work with a variety of cloud and security services, including virtual machines, storage, networking, and databases. You will also be responsible for troubleshooting and resolving customer issues. This position will also act as a point of escalation to other Security Analysts.
SPECIFIC DUTIES & RESPONSIBILITIES
Management:
- Cloud Architecture Design: Craft secure, scalable, and cost-effective cloud architectures aligned with business needs. This involves selecting appropriate Azure services, designing resource allocation, and optimizing infrastructure for performance.
- Deployment and Configuration: Implement and configure cloud solutions, including virtual machines, storage, networking, and databases, ensuring adherence to best practices and governance policies.
- Resource Optimization: Monitor and manage cloud resources, identify underutilized or overprovisioned resources, and implement cost-saving strategies like scaling and automation.
- Automation and Scripting: Develop automation scripts and leverage tools like Azure Resource Manager (ARM) templates to automate repetitive tasks, streamline deployments, and improve efficiency.
Security:
- Threat Protection: Implement and manage security controls like Azure Security Center, Defender for Cloud, and other Azure security services to protect against cyber threats, vulnerabilities, and data breaches.
- Microsoft Sentinel experience- implementing, managing, monitoring
- Identity and Access Management (IAM): Configure Azure Active Directory (AD) and other IAM tools to control access to cloud resources, ensuring only authorized users have access based on the principle of least privilege.
- Data Security: Implement data encryption, access controls, and other measures to protect sensitive data in the cloud, adhering to compliance regulations like GDPR and HIPAA.
- Incident Response: Develop and implement incident response plans to address security breaches promptly and effectively, minimizing damage and downtime.
Support:
- Troubleshooting and Problem Solving: Diagnose and resolve technical issues related to Azure services, applications, and infrastructure deployed in the cloud.
- Technical Support: Provide technical support to internal and external users, answering questions, guiding them through troubleshooting steps, and escalating complex issues as needed.
- Documentation and Knowledge Management: Develop and maintain clear, up-to-date documentation on cloud solutions, deployment processes, and troubleshooting procedures for internal knowledge sharing and user self-service.
- Work as part of a security team to analyze and respond to security threats and be a point of escalation to the team.
- Readouts- Leads high complexity client on-boarding and client readouts
- Participates in R&D activities and strategic initiatives
- Compliance evidence gathering and risk management discussions
- Creates or updates MSSP service and process documentation as required
- Participates as a sales resource as necessary to perform technical product demos
- Complex network and systems integration troubleshooting and issue resolution
- Training and Education: Provide training and education to internal teams and users on Azure services, best practices, and security awareness to ensure optimal cloud adoption and utilization.
PREFERRED EDUCATION
- Bachelor's Degree or equivalent work experience
- Related training in Network and Security Administration
PREFERRED CERTIFICATION & TESTING
- Microsoft Cloud Engineering Certifications (e.g. SC200)
- Information Security Management Certifications
- Incident Response / Handling Certifications
- Intrusion Detection Certifications
- Linux Certifications
- Cisco Networking Certifications
- Information Security Conferences and Training
RELATED WORK EXPERIENCE
- 5+ years Security Experience
- Proficiency with network technologies, Microsoft implementation/troubleshooting
- Familiarity with security frameworks such as PCI, NIST 800-53, ISO27002/1, or other State/Federal regulations