Redstone Federal Credit Unionposted 3 days ago
Huntsville, AL
Credit Intermediation and Related Activities

About the position

Develops, secures, and maintains the security stack of the cloud infrastructure to support Credit Union business needs. Supports operational innovation and provides security direction to elevate the Credit Union's security posture within a cloud computing infrastructure. Helps ensures applications are secure while supporting business initiatives. Utilizes advanced knowledge and trouble shooting skills to assist with the planning, designing, and implementing of procedures and ongoing maintenance. Collaborates with security leadership to consistently assess the threat landscape and to adapt quickly to protect the business from risk.

Responsibilities

  • Develops, secures, and maintains a resilient enterprise-grade cloud security stack in tandem with cloud network engineers.
  • Maintains a consistent, secure environment using configuration management solutions.
  • Conduct rigorous oversight of security systems and security configuration administration to reduce risk to enterprise systems and accounts.
  • Manages and maintains cloud Security Incident and Event Management (SIEM) and work closely with our cloud SIEM provider and Managed Security Service Provider (MSSP) to capture logs and security events from cloud infrastructure and applications.
  • Administers the Application Programming Interface (API) management tool to ensure APIs are securely implemented and managed.
  • Assists with development, maintenance and utilization of scripts (e.g., Python, Ruby, etc.) to support custom extracts, and transform load (ETL) tools, with a security focus for the data flow.
  • Leads and conducts analysis of cloud infrastructure to detect security gaps or deficiencies in the cloud environment; recommends and implements solutions for improvements.
  • Secures business applications and computing environments across public, private or hybrid cloud infrastructures.
  • Documents, formulates and enforces areas of security improvement that balance risk with business operations without impacting efficiencies or innovation.
  • Actively monitors, assesses and recommends tactical and strategic initiatives based on new and emerging threats posing risk to cloud computing environments.
  • Manages remediation efforts after security assessment findings outline weaknesses requiring attention.
  • Adheres to the Information Security Program to ensure the confidentiality, integrity and availability of information assets.
  • Administers security systems to detect and prevent security breaches; monitors network and server intrusion detection systems.
  • Conducts vulnerability assessments and identifies areas for improved security management.
  • Maintains accurate records on cyber security threat information, breaches and discovered security deficiencies.
  • Disseminate complex security information clearly and concisely in a format that both technical and non-technical audiences can easily comprehend.
  • Develops, recommends, implements and manages a variety of cloud security management policies, protocols, systems and tools.
  • Collaborates regularly with others in the department to correct identified system vulnerabilities to reduce threats to the organization.
  • Serves as expert consultant for all cloud security related matters.
  • Evaluates problems, identifies root causes; coordinates resources determine temporary measures and/or permanent solutions.
  • Installs, configures, tests and implements system monitoring and management software tools.
  • Monitors system alerts, events, changes and activities that may impact performance or security.
  • Researches, troubleshoots and resolves complex system errors, failures and other problems.
  • Works closely with others in the department to ensure security patches and firmware are up-to-date.
  • Acts as a key figure in incident response to track occurrence and resolution, with strict documentation and reporting.
  • Stays apprised of current and proposed security changes impacting regulatory, privacy and security industry best practice guidance.
  • Assists in maintaining strong oversight with cloud computing vendors and solution providers to safeguard against undue risk presented by external entities.

Requirements

  • 4 Year / Bachelors Degree - Information Security, Information Assurance, Information Systems, Computer Science or a closely related field - Required
  • 5 Years - Responsible experience in a Cloud Security Engineer role or related position with at least exposure with Amazon Web Services (AWS) and Microsoft Azure.
  • Experience in cloud computing technologies, including software-, infrastructure and platform-as-a-service, as well as public, private and hybrid environments - Required
  • Experience in cloud networking architecture and cloud operations, with cloud access security broker (CASB) experience.
  • Experience in (IDS/IPS), public key infrastructure (PKI), identity and access management (IDAM) systems, antivirus and firewalls.
  • Extensive knowledge of cloud security controls and technologies, such as Security Information and Event Management (SIEM) systems.

Nice-to-haves

  • Holds or working towards one or more certifications including, CCSP (Certified Cloud Security Professional), AWS Certified Security Specialist, Azure Security Engineer Associate, or similar - Preferred

Benefits

  • Equal opportunity employer
  • Drug-Free and Tobacco Free Workplace
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service