Cloud Security Consultant

Talent Groups
Springfield, MA, United States
8 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Identity and Access Management Log Analysis Azure Active Directory Software Vulnerability Management Software Security Multi-Cloud HybridCloud
+8 more
Cloudformation Kubernetes Infrastructure Automation Frameworks Information Technology AWS Fargate Terraform Splunk Devsecops

Job description

  • Provide services primarily in support of enterprise cloud security initiatives, including the following:
  • Secure AWS and Microsoft Azure environments by implementing cloud security best practices.
  • Monitor and investigate cloud security events using Splunk and cloud-native security tools.
  • Review, analyze, and remediate CSPM and CIEM findings, including IAM permissions, excessive privileges, and cloud misconfigurations.
  • Secure Kubernetes (EKS) clusters and Amazon ECS Fargate container workloads.
  • Implement security controls throughout CI/CD pipelines, including code, dependency, IaC, and secrets scanning.
  • Perform cloud security architecture reviews, IAM assessments, and Infrastructure-as-Code security reviews.
  • Utilize AWS Security Hub, GuardDuty, Microsoft Defender for Cloud, CNAPP platforms, and Tenable to identify and mitigate security risks.
  • Prepare documentation of security findings, remediation recommendations, and technical procedures, and collaborate with engineering teams to resolve complex cloud security issues.
  • Develop technical documentation and provide knowledge transfer to other security analysts, as needed.

Requirements

The client is seeking a highly skilled Cloud Security Engineer with the following qualifications:

  • Candidate must be available to perform services during standard Eastern Time business hours.Minimum of three (3) years of hands-on experience securing AWS and Microsoft Azure environments.
  • Experience implementing cloud security best practices across multi-cloud environments.
  • Experience securing Kubernetes (EKS) and Amazon ECS Fargate container workloads.
  • Hands-on experience with Splunk for security monitoring, log analysis, and cloud security investigations.
  • Experience implementing DevSecOps practices and securing CI/CD pipelines, including source code, dependency, Infrastructure-as-Code (IaC), and secrets scanning.
  • Experience identifying, analyzing, and remediating Cloud Security Posture Management (CSPM) and Cloud Infrastructure Entitlement Management (CIEM) findings in AWS and Azure environments.
  • Experience with AWS Security Hub, AWS GuardDuty, Microsoft Defender for Cloud, CNAPP platforms, and vulnerability management tools such as Tenable.
  • Experience performing cloud security architecture reviews and Infrastructure-as-Code (Terraform/CloudFormation) security reviews.
  • Experience securing Microsoft Entra ID and AWS IAM through conditional access, IAM roles and policies, leastprivilege access, and cross-account access controls.
  • Strong analytical, documentation, communication, and problem-solving skills with the ability to work independently., * Bachelor’s degree in Cyber Security, Information Technology, Computer Science, or an equivalent combination of education and work experience.
  • Minimum of three (3) years of experience in cloud security engineering or cloud security operations.
  • Hands-on experience securing AWS and Microsoft Azure environments.
  • Experience with enterprise cloud security tools and DevSecOps practices.
  • AWS, Azure, CISSP, CCSP, or other relevant cloud security certifications are preferred

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all