Cloud Security Specialist

Dine Development Corporation
Eagleswood, NJ, United States
1 day ago
Apply on www.builtincolorado.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$148,000.0 - $164,000.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Databases Continuous Integration Data Security Linux Multi-Factor Authentication
+41 more
Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) Key Management Network Security Network Segmentation OAuth OpenID PCI Data Security Standards Public Key Infrastructure Windows PowerShell Role-Based Access Control Openid Connect Azure Active Directory Azure DevOps Pipelines Zero Trust Network Access Security Assertion Markup Language (SAML) Security Information and Event Management Software Vulnerability Management Policy as Code Data Logging Scripting Load Balancing Data Classification Delivery Pipeline Software Security Git Cloudformation Microsoft Fabric Kubernetes Infrastructure Automation Frameworks Information Technology Bicep Opsworks CIS Benchmarks Api Gateway Terraform Devsecops Access Keys Docker Vulnerability Analysis

Job description

The Cloud Security Specialist supports day-to-day execution of the organization’s cloud security program across Microsoft Azure and Amazon Web Services. The role monitors cloud security controls, secures identity and access, reviews cloud and network architecture, integrates security into deployment pipelines, protects cloud-hosted data, and coordinates remediation with Information Security, Infrastructure, and Application Development. This is a growth-oriented role for a candidate with foundational to intermediate cybersecurity, cloud, or DevOps experience.

PRIMARY DUTIES

Cloud Security Operations and Posture Management

  • Monitor Azure and AWS environments for misconfigurations, vulnerabilities, policy violations, suspicious activity, and drift from CIS Benchmarks and approved baselines.

  • Administer and tune cloud security posture management and cloud-native security services, including Microsoft Defender for Cloud, AWS Security Hub, and AWS GuardDuty.

  • Investigate cloud security alerts, document findings, coordinate remediation with system and application owners, and escalate high-risk findings to senior staff.

  • Maintain cloud security dashboards, asset inventories, and landing zone usage and reporting.

Identity and Access Management

  • Support Azure and AWS identity controls, including Microsoft Entra ID, AWS IAM, role-based access control (RBAC), least privilege, multifactor authentication, conditional access, and privileged access management.

  • Review roles, service principals, managed identities, access keys, and excessive or inactive access; support identity federation and SSO using OAuth 2.0, OpenID Connect, and SAML.

Cloud Architecture and Network Security

  • Support secure landing zone design, hub-and-spoke topology, environment separation, and network zoning using NSGs, AWS security groups, network ACLs, and private endpoints.

  • Support secure configuration of load balancers and gateways (Azure Application Gateway, Azure Load Balancer, AWS ALB/NLB, API gateways), cloud WAF, CASB, and API security controls.

  • Review proposed cloud architectures for sound security design and escalate design concerns to senior staff.

Secure Cloud Engineering and DevSecOps

  • Integrate security requirements into deployments; review infrastructure-as-code (Bicep, ARM, Terraform, CloudFormation) and configurations for security risks.

  • Support security scanning, secrets detection, and policy checks in Azure DevOps (ADO) pipelines.

  • Implement and maintain security policy as code using Azure Policy, AWS Service Control Policies, and AWS Config rules.

Data Security in the Cloud

  • Support secure configuration of storage, databases, encryption, secrets, and key management (Azure Key Vault, AWS KMS).

  • Support data classification, labeling, and DLP with Microsoft Purview, and governance controls for Microsoft Fabric and Copilot, including oversharing risk.

Monitoring and Incident Response

  • Ensure cloud audit, security, and data access logs reach security monitoring platforms; support investigations, triage, and documentation for cloud-related incidents.

Cloud Risk, Compliance, and Reporting

  • Support risk assessments, audit evidence collection, and assessment of cloud controls against NIST, CIS Benchmarks, NYDFS, Virginia BOI, PCI-DSS, and other requirements.

  • Prepare cloud security metrics and reports for leadership; document standards, procedures, diagrams, and exceptions.

ADDITIONAL DUTIES

  • Participate in security awareness, tabletop exercises, and training; perform other duties as assigned., Drive cloud security sales by partnering with regional sellers, positioning products for security and cloud personas, engaging customers during evaluations and post-sales, developing pipeline, supporting major deals, training internal teams, and providing product feedback. The role requires advising senior technical and executive audiences, managing cloud sales processes, presenting to large groups, maintaining cloud certifications, and traveling up to 50%., Designs and delivers Qualys-based security and compliance solutions for enterprise customers across cloud and on-premises environments. Supports technical sales engagements, proofs of concept, architecture workshops, proposals, deployment health checks, and customer advisory activities. The role addresses asset and vulnerability management, patching, compliance, threat detection, application security, and remediation. It also contributes to product roadmap feedback, sales enablement, technical content, field training, and industry events, with at least 30% customer travel.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field. Equivalent work experience in lieu of degree is considered.

  • Two or more years of experience in cybersecurity, network security, DevSecOps, or related work.

  • Three to five years of hands-on experience administering Microsoft Azure and/or Amazon Web Services.

MINIMUM SKILL QUALIFICATIONS

  • Working knowledge of cloud security, identity and access management, RBAC, cloud networking, encryption, logging, and secure configuration.

  • Experience reviewing infrastructure as code, deployment pipelines, containers, or cloud-hosted applications.

  • Strong analytical, troubleshooting, documentation, communication, and teamwork skills.

PREFERRED QUALIFICATIONS

  • Experience with Microsoft Entra ID, Microsoft Defender for Cloud, AWS Security Hub, AWS GuardDuty, SIEM, or comparable cloud security tools.

  • Experience with Azure DevOps pipelines, Git, and policy as code (Azure Policy, AWS SCPs, AWS Config).

  • Experience with landing zones, hub-and-spoke design, cloud WAF, CASB, API security, and Azure CAF or AWS Well-Architected Framework.

  • Experience with Microsoft Purview, Fabric, and Copilot governance; identity protocols (OAuth 2.0, OIDC, SAML, PKI).

  • Container security (Docker, Kubernetes) and scripting in Python or PowerShell.

  • Security+, Microsoft Azure Security Engineer Associate (AZ-500), AWS Certified Security - Specialty, or equivalent certification.

  • Familiarity with NIST CSF, CIS Controls, ISO 27001/2, PCI-DSS, SOX, HIPAA, GDPR, GLBA, CNAPP/CWPP concepts, EDR/MDR, and Linux and Windows administration.

Benefits & conditions

At VA Farm Bureau, we provide an exceptional benefits package, including ongoing job development and support in all roles, paid training and continuing education reimbursement, medical and dental insurance available on your first day, generous employee 401K contribution, excellent Paid Time off (PTO) plan and more!, Remote USA Expert/Leader Expert/Leader Information Technology * Professional Services Lead AWS GovCloud security engineering and accreditation for pre-production modernization environments. Design secure cloud architectures, landing zones, IAM controls, network segmentation, infrastructure automation, containers, and CI/CD deployments. Own DoD RMF, IATT-C, and ATO packages, security controls, POA&Ms, vulnerability remediation, continuous monitoring, and cybersecurity assessments. Provide cloud and cybersecurity guidance for modernization, migration, data transition, Zero Trust, and ICAM initiatives while advising program leadership. Top Skills: APIsAWSAws GovcloudCi/CdContainer OrchestrationIamIcamInfrastructure As CodeJavaMicroservicesNist RmfRelational DatabasesZero Trust

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.builtincolorado.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · World Congress 2022

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

4:09 min

Selecting infrastructure tools and determining proper abstraction layers

Alayshia Knighten Alayshia Knighten · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all