Cloud Security Engineer

$156,000 - $190,000/Yr

Stanford University - California, MO

posted 4 months ago

Full-time - Mid Level
Remote - California, MO
501-1,000 employees
Educational Services

About the position

Come work at Stanford, where we're on a mission to give meaning, solve problems and enrich human lives on a global scale. Stanford's Information Security Office is looking for a cloud security engineer to work with our small, tightly-knit team on a wide range of security-related projects, helping to protect our digital resources. The Information Security Office is a high-profile team, and is one of the few departments with university-wide purview, so you'll have plenty of opportunity to share and shine. We operate with a high degree of autonomy, expecting each of our contributors to bring their own special talents to bear on the tough challenges facing the university. The Cloud Security & Vulnerability Management team in the Information Security Office (ISO) at Stanford University is responsible for safeguarding the university's cloud infrastructure, which includes IaaS and SaaS services across various cloud platforms. This is primarily a hands-on, under-the-hood position but definitely has a public-facing perspective. The team engages with thousands of cloud accounts used for research, teaching and learning, alumni, and administrative computing. The data handled includes regulated information such as health, student, payment, controlled unclassified, and export control data. The team utilizes modern security services like Wiz, Splunk, CrowdStrike, Qualys, ProofPoint (DLP and CASB) to protect users, data, and digital assets. We regularly work with our two other teams: Governance, Risk & Compliance (GRC) for policy and regulation work, as well as with Security Operations for threat detection, investigation, and response efforts. We're a part of the roughly 650-person University IT organization, and we're a key part of the bigger cybersecurity and technology community at Stanford, which spans seven schools, two hospitals and one national laboratory. We all work for the greater good. In this role, you will engage with faculty, staff, and students to advocate for secure cloud computing, apply guardrails, policies, and service controls across all cloud platforms, and integrate third-party identity provider services. You will also review vulnerability reports, lead remediation efforts, conduct security-oriented architecture reviews, and contribute to key initiatives like zero trust and NIST compliance efforts. Additionally, you will participate in a 24x7 on-call rotation for incident response, share knowledge with team members, and document workflows and processes.

Responsibilities

  • Engage with faculty, staff, and students to advocate for secure cloud computing.
  • Apply guardrails, policies, and service controls across all cloud platforms.
  • Integrate third-party identity provider services, such as Entra for SCIM and SAML for web authentication.
  • Review vulnerability reports and engage with stakeholders to lead remediation efforts.
  • Design and lead cloud infrastructure incident response exercises.
  • Handle service-related tickets from community members.
  • Conduct security-oriented architecture reviews for clients across campus.
  • Contribute to key initiatives like zero trust and NIST compliance efforts.
  • Help design and implement a flexible, extensible, and cost-effective secure enclave.
  • Share knowledge with team members and colleagues to advance their careers.
  • Document workflows, processes, lessons learned, and knowledge.
  • Participate in a 24x7 on-call rotation for incident response.

Requirements

  • Bachelor's degree or equivalent experience.
  • A minimum of five years of experience as a contributing member of an enterprise-oriented technology team that had a primary responsibility of securing data in the cloud.

Nice-to-haves

  • Knowledge of industry standards and regulations, particularly NIST.
  • Knowledge of ISO 27001, HIPAA, and PCI DSS.
  • Past work as a devops engineer, CI/CD fluency.
  • CISSP or other professional cybersecurity certifications.
  • Prior work in a highly-regulated industry or higher education.

Benefits

  • Comprehensive rewards package including health insurance, dental insurance, and retirement plans.
  • Flexible work arrangements including remote work options.
  • Travel reimbursement for campus visits if outside the greater Bay Area.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service