State of North Carolinaposted 10 months ago
$81,500 - $122,250/Yr
Full-time • Mid Level
10,001+ employees
Executive, Legislative, and Other General Government Support

About the position

The Department of Health and Human Services (DHHS) Privacy and Security Office (PSO) is a critical unit within the Office of the Secretary, Information Technology Division. This office is responsible for providing leadership and direction for the department's privacy, security, Business Continuity Planning (BCP), Continuity of Operations Planning (COOP), and compliance activities. The PSO ensures that all Federal, State, and Department-wide privacy and security requirements are met, which is essential for protecting sensitive information and technology. The office also develops policies, standards, and other materials that support compliance efforts across the department. As a Cloud Security Specialist, you will manage and support the implementation of various cloud infrastructures related to security, including Amazon Web Services (AWS), Azure, and Google Cloud Platform (GCP). Your role will involve assisting in the security design, deployment, maintenance, and troubleshooting of the department's cloud infrastructure. You will be responsible for creating detailed technical documentation to support the security management of multiple cloud environments and aiding in the development of privacy and security policies and procedures for new projects or enhancements to existing systems. Additionally, you will provide guidance on best practices related to information security and participate in regular status meetings with IT leadership and other stakeholders regarding current projects and future initiatives. Training internal staff on cloud platforms and services will also be part of your responsibilities. You will create a cloud-based security platform that monitors and analyzes data from multiple sources to identify potential threats and develop an automated system for detecting anomalous behavior within cloud environments using machine learning algorithms. Collaboration and motivation of team members will be essential to accomplish objectives and strategies that comply with professional standards while maintaining a schedule. Understanding Operating Systems (OS), vulnerability management tools, HIPAA, and industry standards such as CVE, CPE, and CVSS will also be beneficial in this role.

Responsibilities

  • Manage and support the implementation of multiple Cloud infrastructures related to security, such as AWS, Azure, and GCP.
  • Assist in the security design, deployment, maintenance, and troubleshooting of the department's cloud infrastructure.
  • Create detailed technical documentation to support the security management of multiple cloud environments.
  • Aid in developing privacy and security policies and procedures for new projects or enhancements to existing systems.
  • Provide guidance on best practices related to information security.
  • Participate in regular status meetings with IT leadership and other stakeholders regarding current projects and future initiatives.
  • Provide training to internal staff on cloud platforms and services.
  • Create a cloud-based security platform that monitors and analyzes data from multiple sources to identify potential threats.
  • Develop an automated system for detecting anomalous behavior within cloud environments using machine learning algorithms.
  • Collaborate with and motivate others to accomplish objectives and strategies that comply with professional standards and maintain a schedule.

Requirements

  • Two years of related experience implementing cloud security with a focus on security engineering, system security design, and security incident response.
  • Experience applying security engineering concepts to cloud platform solutions to meet operational requirements, such as scalability, security, reliability, extensibility, and manageability.
  • Documented experience implementing various cloud technologies including networking, security and compliance, compute, storage, and databases alongside cloud security solutions.
  • Demonstrated experience applying knowledge of cloud security and implementation features; OS, multi-tenancy, virtualization, orchestration, elastic scalability, etc.
  • Prior experience applying compliance frameworks PCI, SOX, SOC 2, ISO 27001, NIST 800-53 to a complex environment.
  • Demonstrated experience with cost benefit analyses, accurately assess risk, forecast both long and short-term outcomes, evaluation on the implications in a complex business environment while working to deliver on expedited schedules.

Nice-to-haves

  • AWS, GCP, Azure or other cloud-related certifications
  • SANS Global Information Assurance Certifications (Or Similar - ex. Carnegie-Mellon CERT); Security Essentials Certification (GSEC); or Information System Security Certification Consortium (ISC2) Systems Security Certified Practitioner (SSCP).
  • Experience with the North Carolina IT functions.

Benefits

  • Health insurance options
  • Standard and supplemental retirement plans
  • NCFlex program (numerous high-quality, low-cost benefits on a pre-tax basis)
  • Paid vacation
  • Sick leave
  • Community service leave
  • Paid parental leave for eligible employees
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service