Role : : Cloud Security Principal Engineer CISSP Certification required
Location : Philadelphia, PA Hybrid (80% remote, 20% onsite)
Type : Contract / Contract to hire
Required Skills & Experience
- Certifications : CISSP (mandatory); cloud security certifications strongly preferred
- Education : Bachelor's Degree (Computer Science, Information Systems, or related field preferred)
Experience :
12+ years industry experience across IT disciplines (architecture, network, application, database, operations)6+ years in information security, regulatory compliance, and risk management3+ years in Identity & Access Management (IAM), Role-Based Access Control (RBAC), user provisioning, or security awareness trainingExperience with cloud and / or virtualization technologiesTechnical Expertise :
Multi-cloud security (Azure preferred; AWS, Google Cloud also relevant)Identity & Access Management (IAM / Entra ID)Security tools : EDR (Microsoft Defender), SIEM (Sentinel / Splunk), CSPM (e.g., Wiz), VPNs / NGFWs, NAC, encryption protocolsSecure configuration management, automation pipelines (Terraform, PowerShell), vulnerability management platformsNetworking protocols (TCP / IP, WAN / LAN, firewalls, IPS, web filtering, disk encryption)Microsoft Active Directory, UNIX; ERP / clinical systems (Epic, Lawson) a plusFrameworks & Compliance :
NIST SP 800-53, HIPAA, PCI-DSS, CISA ZTMM, CIS Benchmarks, ISO 27000, Microsoft CAF, AWS CAF / Well-Architected, Google CAFOther Skills :
Risk management frameworksSDLC methodologies, PMO project management, MS productivity tools (Access, Word, PowerPoint, Visio, Project)Database query / data mining basicsStrong knowledge of InfoSec principles, IT controls, and regulatory standardsPreferred Skills & Experience
3+ years working with matrixed, high-performance teamsERP and clinical application security experienceStrong mentoring and leadership capabilitiesKey Responsibilities
Serve as subject matter expert and advisor on complex cloud security issuesDesign, implement, and optimize cloud security controls and service linesSupport cloud migration, tool optimization, automation, and risk-driven outcomesCollaborate with internal stakeholders, vendors, and MSPs to fine-tune detection / prevention capabilitiesLead incident response planning, runbooks, tabletop exercises, and system hardening guidesAlign security architectures with organizational policies and external frameworksParticipate in governance forums, DevSecOps, and cloud-native strategiesAssist with audits, compliance assessments, and risk remediation plansMentor junior InfoSec engineers through documentation, training, and peer reviewsShape and design service lines, manage risks, and ensure enterprise solutions are scalable and adaptableSupport business continuity, change management, and educate management on IAM and RBAC models