Curi - Raleigh, NC

posted 4 months ago

Full-time
Raleigh, NC
Performing Arts, Spectator Sports, and Related Industries

About the position

Curi is a full-service advisory firm dedicated to serving physicians and medical practices. We pride ourselves on being fierce advocates for physicians, smart business leaders, and thoughtful partners. Our offerings include advisory services, capital solutions, and insurance products that are tailored to meet the unique needs of our clients. We focus on delivering performance that is both time-tested and trusted across the fields of medicine, business, and life. In this role, we are looking for a highly skilled and experienced Cyber Security Engineer with a primary focus on AWS security. The successful candidate will be responsible for designing, implementing, and managing security solutions to protect our cloud infrastructure on AWS. This position requires close collaboration with our security and engineering teams to ensure the security and compliance of our cloud environments, which also include Azure and GCP. The key result areas for this position include AWS Security Implementation, Infrastructure as Code (IaC) Integration, SIEM Monitoring and Incident Response, and educating and collaborating with various stakeholders. The Cyber Security Engineer will design, deploy, and maintain security solutions for AWS environments, conduct regular security assessments, and stay current on cloud security features and best practices. Additionally, the role involves implementing security best practices using IaC tools like Terraform, monitoring events in the SIEM tool, and collaborating with different teams to integrate security into the software development lifecycle (SDLC).

Responsibilities

  • Design, deploy, and maintain security solutions for AWS environments, including IAM policies, network security configurations, and monitoring systems.
  • Conduct regular security assessments and audits of AWS resources, monitor environments using security tools, and respond to security incidents promptly to mitigate risks.
  • Stay current on AWS and other cloud security features and best practices and provide recommendations for enhancing the security posture of our infrastructure.
  • Document security configurations, policies, and procedures related to AWS environments and contribute to developing security standards and guidelines.
  • Implement security best practices using IaC tools like Terraform to ensure consistent and automated security configurations across all AWS environments.
  • Monitor events in the SIEM tool and respond to phishing incidents to protect the organization's assets and data.
  • Set up, configure, and conduct vulnerability management with our SIEM (Rapid 7) and coordinate remediation efforts to address vulnerabilities.
  • Participate in security assessments and penetration testing activities.
  • Collaborate with different teams to integrate security into the software development lifecycle (SDLC) and automate security controls in the CI/CD pipeline.
  • Conduct security onboarding for new team members, ensuring they are aware of security policies and best practices.

Requirements

  • 3-5 years working in Cyber Security.
  • Bachelor's Degree in a related business or technical discipline or the equivalent combination of education, technical training, or work/military experience in lieu of a degree.
  • Strong understanding of AWS services and features such as IAM, VPC, CloudTrail, and AWS Config.
  • Experience with Infrastructure as Code (IaC) tools such as Terraform and version control systems like GitHub.
  • Excellent analytical and problem-solving skills, with the ability to assess complex security issues and propose effective solutions.
  • Strong communication and collaboration skills, with the ability to work effectively with cross-functional teams.
  • AWS certifications (e.g., AWS Certified Security - Specialty) are required.

Nice-to-haves

  • CCSP (Certified Cloud Security Professional) certification is preferred.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service