Principal Cloud Security Engineer

OpenKyber LLC
United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Component-Based Software Engineering Microsoft Azure Cloud Computing Cloud Computing Security Identity and Access Management Information Systems Security Architecture Professional Data Classification Static Application Security Testing Dynamic Application Security Testing

Job description

Sacramento, CA (Remote, Occasional Onsite) Must Have: Active Information Systems Security Professional (CISSP)

Mandatory Qualification: Leading data classification and categorization effort and documenting the results in accordance with Data Classification and Categorization Standards. Working with customers to identify and document business impacts and system security classification and data categorization ratings.

Performing SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) common tools and provide results and remediation execution approach to management, developers, business analyst, and tester.

Developing and presenting security remediation approach to senior management, developers, business analysist, and testers, including an execution plan.

Implementing ZeroTrust/Continuous authentication architectures.

Classifying issues identified via SAST and DAST tools based on risk and criticality.

Documenting security reports for As is applications, developing security user stories and task for the developers to address security vulnerabilities.

Performing and collaborating on analysis with other technical staff to identify and document security issues for application components and supporting infrastructure, such as: Non-standard or low-security authentication methods for users, systems, and infrastructure Reused or common credentials User credentials in code Unencrypted end-user passwords and Personal Identifiable Information (PII) Missing security controls based on the data classification and categorization.

Collaborating with Software Developers to identify and document approaches to remediate security issues, including plans to validate security fixes and improvements.

Collaborate with developers implementing an IAM (Identity and Access Management) solution.

Requirements

Do you have experience in Identity and access management (IAM) solutions?, Desired Qualification: Certified Information Systems Security Professional (CISSP) License.

Ten (10) years or more of Security Engineer experience using Mend and Invicti or similar tools.

Minimum of five (5) years of experience supporting security practices in a cloud environment (AWS, Azure, etc.).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:49 min

Container hosting options available on Amazon Web Services

Federico Fregosi · WWC 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · WWC 2024

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:51 min

Alibaba Cloud developer resources and cloud computing training

Cheng Zhang · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all