Talent.com
Cloud Security Engineer
Cloud Security EngineerBrown University Health • Providence, RI, United States
Cloud Security Engineer

Cloud Security Engineer

Brown University Health • Providence, RI, United States
1 day ago
Job type
  • Full-time
Job description

SUMMARY :

The Cloud Security Engineer serves as the liaison for protecting Brown University Health’s (BUH) multi-cloud footprint by designing and hardening secure landing zones, embedding security controls in Infrastructure-as-Code (IaC), operationalizing cloud-native security services and control-plane guardrails. Working in close partnership with Security Operations, Network Security, Network Engineering, and Server Engineering, this role translates security best practices and regulatory requirements into practical technical controls, drives Zero-Trust segmentation, automates preventative and detective controls, and continuously improves BUH’s cloud security posture.

Brown University Health employees are expected to successfully role model the organization's values of Compassion, Accountability, Respect, and Excellence as these values guide our everyday actions with patients, customers and one another.

In addition to our values, all employees are expected to demonstrate the core Success Factors which tell us how we work together and how we get things done. The core Success Factors include :

Instill Trust and Value Differences

Patient and Community Focus and Collaborate

ESSENTIAL FUNCTIONS :

Own and improve cloud security posture across a multi-cloud environment (Azure, AWS and / or GCP). Establish, document and enforce secure guardrails and baselines aligned to CIS Benchmarks and NIST CSF 2.0

Operate and tune our cloud security posture / CNAPP platform (agentless discovery, misconfiguration / vulnerability / identity risk analysis), drive prioritized remediation with responsible parties.

Review and advise on policy-as-code and infrastructure-as-code (IaC) security checks across pre-commit, CI / CD, and pre-deployment gates.  Conduct security design reviews of IaC to identify and recommend fixes for misconfigurations before provisioning.

Design and advise on least‑privilege access models (roles, conditional access policies, break‑glass, service principals), secrets management, key management, and encryption (at rest, in transit, and in use where applicable).

Design secure network architecture : VPC / VNet design, private connectivity / peering, egress controls, segmentation, and zero‑trust‑oriented access to cloud services.

Centralize logging / telemetry (activity, audit, identity, network, and data access) and integrate with SIEM / SOAR for alerting, correlation, and automated response.

Design and document data security controls across object storage, databases, and analytics services (classification, access boundaries, tokenization / format‑preserving encryption, key rotation, and auditing).

Perform periodic control assessments and gap analyses against CIS Benchmarks and NIST CSF 2.0.  Publish metrics / KPIs and risk treatment plans for leadership.

Automate routine security tasks and remediations using scripting and APIs (e.g., Python, PowerShell, serverless functions, workflow automation).

Partner with IT / Cloud Platform teams to maintain hardened images, patching, and vulnerability management for cloud workloads (VMs, managed services; containers, etc.).

Partner with Security Operations to translate cloud attack paths into detections (control-plane logs, API activity, network flow, workload telemetry) and tune SIEM / SOAR playbooks.

Secure SaaS integrations with cloud accounts (SSO, SCIM / JIT, conditional access, least‑privilege service integrations) and third‑party connectivity.

Identify, document and report any deviations from policy / standards, recommend corrective actions, and review security policies and control documentation to align with current practices.

Ensure least-privilege and MFA with Azure AD (Entra ID), AWS IAM, and workload federation are enforced.

Develop standards, policies, procedures and tabletop exercise scenarios.

Review and recommend updates to security policies, procedures, and control documentation to ensure they reflect current security best practices and regulatory requirements.

Monitor emerging threats, vulnerabilities, and industry best practices to ensure security controls remain effective and aligned with the evolving threat landscape.

Research and assists in the piloting and evaluation of new tools, technologies, technical controls, and processes to support and enforce defined security policies.

Support incident response (triage, containment, snapshot / metadata collection, forensics coordination, and post‑incident reviews) as required.

Attend and actively contribute to team, project, project management, problem management, cloud migration and major incident conference calls as required.

Performs other duties as assigned.

EXPERIENCE :

A minimum of ten years of IS experience, with five years of hands-on cloud security engineering with Azure, AWS and / or GCP.

A bachelor's degree in information systems or equivalent work experience; an M.B.A. or M.S. in information security is preferred.

Active Certifications Required (3 or more - CISSP, CCSP, GIAC (i.e., GCSA, GCLD, GCAD, GCPN, GPCS, GCTD), CKS, CCAK, Security+.)

Subject matter expert knowledge in encryption, KMS / Key Vault concepts, secrets management, identity federation (SAML / OIDC / OAuth2), and modern access controls.

Hands‑on experience securing both Azure and AWS in production, including IAM, networking, storage, and monitoring across multiple accounts / subscriptions.

Experience designing immutable logging and integrating cloud telemetry with SIEM / SOAR; skillful at alert tuning to reduce noise and surface true risk.

Subject matter expert knowledge in Infrastructure-as-Code and CI / CD security. Proficiency reviewing IaC for security issues and implementing policy‑as‑code guardrails; strong understanding of secure provisioning patterns and drift control.

Subject matter expert knowledge of Kubernetes and API security

Subject Matter Expert level knowledge of security tools, trends, methodologies and best practices for securing platforms and operating systems at the server, client and network level.

Ability to script and automate with Python and / or PowerShell, use cloud CLIs / SDKs, and work with APIs / webhooks for integrations and workflows.

Motivated self-starter who has a track record of taking ownership of information security challenges and driving them to resolution.

Must be able to thrive in a fast-paced, rapidly evolving security department / environment with varying priorities, while interacting with other departments.

Thorough and current understanding of a wide range of threat vectors and their potential exploits against current corporate controls and cloud specific attacks.

Strong knowledge of industry frameworks related to information security (e.g. ISO 27000, NIST CSF, HIPAA Security, CIS Benchmarks, etc.).  Ability to implement / enforce industry frameworks using cloud native services and automation.

Maintain an expert knowledge of InfoSec industry trends and developments and advise on changes to the threat landscape.

Knowledge of cloud networking, network infrastructure, including routers, switches, firewalls, and the associated network protocols and concepts.

Excellent interpersonal, verbal and written communication, and organizational skills.  Clear, concise communicator with the ability to produce standards, runbooks, diagrams, and executive‑level reporting.

Experience supporting 24×7 incident response, including participation in major incident / problem calls.

Maintains work effort status within SLA’s on Brown University Health’s Service Desk and Task Management Platforms.

INDEPENDENT ACTION :

Functions independently within departmental policies and practices.  Must be able to work independently in a manner to achieve goals, objectives and productivity requirements.  Refers unresolved complex issues to Manager of Information Security where clarification of department policies and procedures may be required.

SUPERVISORY RESPONSIBILITIES :

Employee functions independently within department policies and practices; refers specific decisions to security management where authority is outside of the defined departmental RACI Matrix or clarification of departmental policies and procedures may be required.

Pay Range :

$108,135.66-$178,417.51

EEO Statement :

Brown University Health is committed to providing equal employment opportunities and maintaining a work environment free from all forms of unlawful discrimination and harassment.

Location :

Corporate Headquarters - 15 LaSalle Square Providence, Rhode Island 02903

Work Type :

M-F 8 : 30am-5 : 00pm

Work Shift : Day

Daily Hours : 8 hours

Driving Required : No

Create a job alert for this search

Cloud Security Engineer • Providence, RI, United States

Related jobs
Cyber Security Engineer

Cyber Security Engineer

Keylent Inc • Johnston, RI, United States
Full-time
Location - Johnston, RI (Onsite from Day 1).Experience administering Firewalls (Juniper / Palo Alto).Strong knowledge of at least one of the following areas : operating systems, databases, systems, ne...Show more
Last updated: 2 days ago • Promoted
U.S. Border Patrol Agent

U.S. Border Patrol Agent

U.S. Customs and Border Protection • Greene, Rhode Island, United States
Full-time
Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show more
Last updated: 30+ days ago • Promoted
Security Guard - 3rd shift

Security Guard - 3rd shift

Adams and Associates, Inc. • Exeter, RI, US
Full-time
Are you tired of working for a company that promises upward mobility but never delivers? Are you looking for an employer that regularly promotes from within? Do you want to help guide and develop y...Show more
Last updated: 30+ days ago • Promoted
Security Engineer

Security Engineer

Zoom Corporation • Providence, RI, United States
Full-time
The Security Engineer is responsible for security design and reviews across our products and services, with a specific focus on Platform services and core infrastructure components.The ideal candid...Show more
Last updated: 3 days ago • Promoted
Public Safety Monitor-Front Desk

Public Safety Monitor-Front Desk

Southcoast Health • Fall River, MA, United States
Full-time
Join Southcoast Health, where your future is as promising as the care we provide.Our commitment to each other, our patients, and our community is more than a mission - it's our way of life, and you...Show more
Last updated: 30+ days ago • Promoted
Senior Systems Engineer - Autonomous Maritime Platforms

Senior Systems Engineer - Autonomous Maritime Platforms

General Dynamics Mission Systems • Taunton, MA, US
Full-time
Requires a Bachelor's degree in Systems Engineering, or a related Science, Engineering or Mathematics field.Also requires 2+ years of job-related experience or a Master's degree.Department ...Show more
Last updated: 9 hours ago • Promoted • New!
Cloud Sales Engineer - Video Security & Access Control (Northeast)

Cloud Sales Engineer - Video Security & Access Control (Northeast)

Motorola Solutions • Providence, RI, United States
Full-time
At Motorola Solutions, we believe that everything starts with our people.We're a global close-knit community, united by the relentless pursuit to help keep people safer everywhere.Our critical comm...Show more
Last updated: 1 day ago • Promoted
Security Engineer

Security Engineer

Nutanix • Providence, RI, United States
Full-time
Hungry, Humble, Honest, with Heart.Are you a forward-thinking security professional with a passion for implementing cutting-edge technology and a strong understanding of Zero Trust principles? If s...Show more
Last updated: 17 hours ago • Promoted • New!
Lead Adversarial Security Engineer

Lead Adversarial Security Engineer

Trellix • Providence, RI, United States
Full-time
Lead Adversarial Security Engineer.Trellix, the trusted CISO ally, is redefining the future of cybersecurity and soulful work. Our comprehensive, GenAI-powered platform helps organizations confronte...Show more
Last updated: 5 days ago • Promoted
Security Engineer

Security Engineer

Thrive • Foxborough, MA, US
Full-time
Quick Apply
About Us Thrive is a rapidly growing technology solutions provider focusing upon Cloud, Cyber Security, Networking, Disaster Recovery and Managed Services. Our corporate culture, engineering talent,...Show more
Last updated: 30+ days ago
Cyber Security / Infrastructure Engineer Intern

Cyber Security / Infrastructure Engineer Intern

Innovative Defense Technologies (IDT) • Fall River, MA, US
Internship
Intern : Cybersecurity / Infrastructure Engineer – JR | Summer 2026 Start.Innovative Defense Technologies.IDT), provider of automated software testing, data analysis, and cybersecurity solutions for...Show more
Last updated: 30+ days ago
Postdoctoral Fellow (Interdisciplinary / Cyber Security)

Postdoctoral Fellow (Interdisciplinary / Cyber Security)

InsideHigherEd • Kingston, Rhode Island, United States
Full-time
Postdoctoral Fellow (Interdisciplinary / Cyber Security).Non-Union Non-Classified Staff.The search will remain open until the position has been filled. Work on interdisciplinary research opportuniti...Show more
Last updated: 2 days ago • Promoted
Software Engineer

Software Engineer

TEKsystems • Smithfield, RI, United States
Full-time
As a Senior Software Engineer, you will play a key role on a Scrum team and within Digital Platforms Technology.You will be encouraged to gain understanding of all the components of our web applica...Show more
Last updated: 10 hours ago • Promoted • New!
Field Technician (CCTV Security Systems)

Field Technician (CCTV Security Systems)

Jobot • Canton, MA, US
Full-time +1
Field Technician (CCTV Security Systems) needed for a company that is a global technology powerhouse base in Canton, MA.This Jobot Job is hosted by : David Hyon. Are you a fit? Easy Apply now by clic...Show more
Last updated: 30+ days ago • Promoted
Business Intelligence Developer II

Business Intelligence Developer II

FM • Johnston, Rhode Island, United States
Full-time
Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk manageme...Show more
Last updated: 14 hours ago • Promoted • New!
Cloud Architect

Cloud Architect

Oracle • Providence, RI, United States
Full-time
Architect, design, and implement resilient cloud solutions on OCI, emphasizing networking, storage, and system administration to meet complex customer requirements. IaaS / PaaS Solution Deployment : .De...Show more
Last updated: 3 days ago • Promoted
Senior Programmer Analyst - (2 Positions)

Senior Programmer Analyst - (2 Positions)

InsideHigherEd • Kingston, Rhode Island, United States
Full-time
Senior Programmer Analyst - (2 Positions).PTAA - Professional / Tech / Admin Assoc.Anticipated Hiring Salary Range : $75,000 - $85,000. The search will remain open until the position has been filled.Firs...Show more
Last updated: 30+ days ago • Promoted
Sr. Configuration Analyst

Sr. Configuration Analyst

Leidos Inc • Newport, RI, United States
Full-time
The Leidos National Security Sector has an opening for a Senior Configuration Analyst to support the Naval Array Technical Support Center (NATSC) located at Navy Undersea Warfare Center (NUWC), New...Show more
Last updated: 29 days ago • Promoted