Eclaro - Boca Raton, FL
posted 3 months ago
As a Cloud Security Engineer, you will play a crucial role in ensuring the security of cloud-based infrastructures and applications within the organization. Your primary focus will be on implementing Shift Left security practices and integrating security into Infrastructure as Code (IaC) methodologies. This position requires a solid understanding of cloud technologies, security best practices, and the ability to embed security into the development lifecycle and IaC workflows. You will be responsible for assessing, implementing, and managing security controls to protect cloud environments from the earliest stages of development, leveraging automation and orchestration techniques inherent to IaC practices. Your responsibilities will include collaborating with development teams to embed security controls, such as code scanning, vulnerability assessment, and secure coding practices, into CI/CD pipelines and IaC workflows. You will conduct security assessments of IaC templates and configurations to identify vulnerabilities, misconfigurations, and security risks. Additionally, you will implement security controls and measures within IaC scripts and configurations to protect cloud resources, ensuring that best practices such as IAM policies, encryption, network security rules, and access controls are embedded directly into IaC templates and deployment pipelines. Monitoring IaC deployments for security incidents and responding promptly to security alerts and breaches will also be part of your role. You will develop incident response procedures specific to IaC environments and coordinate response efforts with development and operations teams. Furthermore, you will be tasked with developing and implementing automation solutions for security tasks and processes within IaC pipelines, utilizing tools and frameworks such as Terraform, AWS CloudFormation, or Azure Resource Manager to automate security controls deployment, configuration management, and compliance checks within IaC workflows. You will ensure that IaC templates and deployments comply with relevant regulatory requirements, industry standards, and organizational policies. Collaborating with compliance teams to conduct audits, assessments, and reviews specific to IaC security will be essential. Providing security awareness training and guidance to development and DevOps teams on integrating security into the development process and IaC workflows will also be a key responsibility. You will maintain accurate documentation of security configurations, policies, procedures, and incident response activities related to development environments and IaC deployments, and generate reports on Shift Left security and IaC security metrics, compliance status, and incident trends for management and stakeholders.