Cloud Security Engineer (AWS & GCP)
New
Q
Quantum SkyCloud security
Remote (US)Full-TimeSenior
Salary115,000 - 140,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- Six (6) or more years of IT engineering and/or cybersecurity experience, with at least three (3) years working in a dedicated cloud security engineering or similar position.
- Required Skills
- AWSLinuxTerraform
Requirements
- Six or more years of IT engineering and/or cybersecurity experience, including at least three years in cloud security engineering or a similar position.
- Hands-on experience with both AWS and Google Cloud Platform (GCP).
- Ability to diagnose and resolve issues across Linux and Windows systems, network infrastructure, and cloud services.
- Experience with systems administration and vulnerability management, including patching, hardening, and identity and access management (IAM).
- Experience working in a DevSecOps environment and integrating security practices into cloud and infrastructure workflows.
- Hands-on experience with one or more listed tools, including Splunk Enterprise, Tenable Security Center/Nessus, GitLab, Okta, Trivy, Anchore, Terraform, CloudFormation, or Ansible.
- Familiarity with ITSM ticketing systems such as GitLab, Jira, or ServiceNow.
- Ability to work independently during business hours and on-call periods.
- Must be a US citizen with the ability to obtain a security clearance.
- Desired: a relevant bachelor's degree, federal or government-facing customer experience, or experience with FedRAMP, FISMA, or NIST 800-53.
- Desired: prior on-call, SRE, SOC, or incident response experience; relevant AWS or GCP certifications; Security+ or another relevant security certification.
- Experience with Kubernetes is highly desirable.
Responsibilities
- Administer and maintain cloud workloads, including patching, vulnerability and compliance scanning, remediation, backups, and recovery.
- Support AWS and GCP environments, including Windows and Linux virtual machines, container workloads, cloud services, and identity services.
- Configure, update, and maintain endpoint protection, log collection, vulnerability scanning, and compliance monitoring tools.
- Troubleshoot network, compute, application, and identity issues by reviewing logs and analyzing system behavior.
- Implement hardening and compliance controls using CIS Benchmarks, DISA STIGs, and FedRAMP requirements.
- Remediate vulnerabilities identified by tools such as Tenable, Trivy, OpenSCAP, Anchore, and Twistlock.
- Provide quality assurance feedback during system deployments and collaborate with Security Analysts to deliver security services.
- Create and maintain network diagrams, dataflow diagrams, SOPs, and security tool configuration guides.
- Respond to after-hours alerts and incidents during the assigned on-call rotation; triage, contain, stabilize, escalate, and document incidents.
- Contribute to automation improvements and runbook enhancements, and support and mentor junior engineers as required.
View Full Description & ApplyYou'll be redirected to the employer's site