A financial firm is looking for a Cloud Security Specialist to join their team in New York, NY.
Compensation : $150-180k
Must be local to the NYC area
Responsibilities : SME Consultancy :
- As part of the IT Security team, develop and implement firm IT Strategy in consultation with the IT teams, ensuring that all initiatives are mirrored in respective strategies including the overall firm Strategy
- Provide security advice and support for information technology projects as Cloud Security subject matter expert (SME)
- Research new security related products and services to ensure that firm is equipped with appropriate industry best tools and solutions
Cloud Security :
Subject Matter Expert (SME) for cloud security within the Security Operations DepartmentExperience working with and managing IDPS deployments such as Suricata / Snort including a strong PCAP analysis skillsetImplement and optimize detection and response workflows in cloud-native / hybrid environmentsMonitor, investigate, and triage cloud security alerts from SIEM and cloud native toolsCollaborate with cloud operations and infrastructure teams to ensure secure architecture and configurationCreate and maintain cloud-focused detection rules and playbooks in collaboration with incident response teamsContribute to investigations and assist in threat hunting within environmentsReview cloud logsSupport compliance efforts through evidence gathering, control validation, and reportingParticipate in security reviews for existing integrations and new services etc.Investigate and respond to security incidents escalated from the SOCAssist in implementing cloud workflows utilizing Lambda and Step functions which enable cloud incident responseRegulatory Compliance & Reporting :
Ensure incident response efforts and documentation comply with industry standards and best practices (GDPR, SOC, NIST, ISO etc.)Maintain detailed documentation and reporting for audits and compliance reviewsProcess Improvement & Risk Mitigation :
Develop and refine incident response standard operating procedures and playbooksConduct root cause analysis and post incident reports to identify areas for improvementRecommend and implement process improvements to enhance detection, response and recovery capabilitiesOperational :
Operate and maintain controls related to SIEM, DLP, Vulnerability Management, Cyber Threat Intelligence, Endpoint Protection, etc with an emphasis on cloud deployments and implementationsConduct IT Security risk assessments for all high impact projects, defining security mitigating controls that impact the technology architectures of firm, service providers, and business partnersReview and update IT Security procedures to reflect best practice and mitigate current and emerging threatsMaintain relationships with third-party IT security vendors and strategic partnersQualifications :
'Hands-on' IT Security analysis and engineering experience including securing systems, networks and infrastructure; operational support, including on-call experienceProven experience including combination of intrusion detection, malware analysis, forensics and incident response, particularly in cloud / hybrid environmentsExtensive knowledge of cloud environments such as AWS & AzureMonitor, tune and develop technical IT Security controls and frameworks to ensure appropriate preparation, monitoring and response to threatsEnsure a risk-based approach to IT Security is adopted in every part of the business and solutionsWork with members of the IT Security team to help design, implement and maintain securityPrepare for, identify (hunt) and remediate cyber threatsOperate and maintain IT Security controls related to SIEM, DLP, Vulnerability Management, Cyber Threat Intelligence, Endpoint Protection, etc.Deliver IT Security projects from concept, approval, design, and implementation to operationAbility to collaborate effectively with others to drive forward key security objectivesStrong documentation and report writing skills (to both technical and business audiences)Excellent time management and organizational skills combined with technical IT Security acumenExpert knowledge of Firewalls, TCP / IP, IPS, DLP, proxies, SIEM, & Endpoint Protection softwareFinancial and / or Banking industry experience preferredVirtualized and Cloud platforms experience such as Amazon Web Services, Microsoft Azure or Office 365B.S. in a technology discipline (Computer Science, Computer Engineering, Cybersecurity or equivalent)Security certifications such as CISSP and at least one GIAC GSEC, GCED, GCIA, GCIH, GREM, GCFR or equivalent is preferredCloud certifications such as AWS Solution Architect, AWS Security Specialty etc.Knowledge of incident handling life cycle based on an established framework : ISO 27035, SANS, NIST SP 800-61, CERT, ENISAExperience with security and automation in cloud native environments