USNLX Diversity Jobs

USNLX Diversity Careers

Job Information

TEKsystems Cloud Security Engineer in Bolingbrook, Illinois

Description:

POSITION SUMMARY: The Lead Cloud Security Engineer has significant responsibilities related to securing solutions deployed to the Google Cloud Platform (GCP) landscape with integrations to legacy on-premise deployments and other SaaS or web service solutions. The Engineer collaborates with other members of the team (including onshore and offshore consultants), to ensure successful delivery of enterprise products and improve our information security posture. They work closely with key stakeholders and maintain high quality standards while operating in a highly dynamic and fast paced environment. CORE JOB RESPONSIBILITIES: • Application Support: Develops procedures and documentation for applications support. Manages application enhancements to improve business performance. Advises on application security, licensing, upgrades, backups, and disaster recovery needs. Ensures that all requests for support are dealt with according to set standards and procedures. • Business Process Improvement: Analyzes business processes; evaluates alternative solutions, assesses feasibility, and recommends new approaches, typically seeking to exploit technology components. Evaluates the financial, cultural, technological, organizational and environmental factors which must be addressed in the change program. Develops business requirements for the implementation of significant changes in organizational mission, business functions and process, organizational roles and responsibilities, and scope or nature of service delivery. • Information Management: Ensures that the business processes and information required to support the organization are defined and devises appropriate standards, processes and data architectures. Evaluates the impact of any relevant statutory, internal or external regulations on the organization's use of information and develops strategies for compliance. • Problem Management: Ensures that appropriate action is taken to anticipate, investigate and resolve problems in systems and services. Ensures that such problems are fully documented within the relevant reporting system(s). Leads the development of problem solutions. Coordinates the implementation of agreed remedies and preventative measures. Evaluates patterns and trends. • Relationship Management: Facilitates open communication and discussion between stakeholders, acting as a single point of contact by developing, maintaining and working to stakeholder engagement strategies and plans. Negotiates with stakeholders at senior levels and ensures that organizational policy and strategies are adhered to. Uses feedback from customers and stakeholders to help measure effectiveness of stakeholder management. Contributes to the development and enhancement of customer and stakeholder relationships. REQUIREMENTS FOR CONSIDERATION: • Bachelor’s degree in Computer Science, a related field, or applicable work experience • Infosec certifications such as ISC2 (CISSP or CCSP) or ISACA (i.e.: CRISC, CISA, CISM, etc.) • Technical infosec certifications such as Google Certified Security Engineer, Google Certified Professional Cloud Architect, Microsoft Certified: Azure Security Engineer Associate • 5+ years of progressive career experience focusing on GCP Cloud Security and Application Security Architecture • Expert knowledge of Cloud Security risk themes • Deep mastery of Google Cloud Platform services, ensuring security and compliance data and workloads, with a heavy focus on implementing IAM permissions in a least-privileged, yet scalable manner. • Experience with using cloud CSPM tools (Palo Alto Prisma Cloud) to detect, notify, and remediate security misconfigurations. • Cloud security automation experience through Terraform, Jenkins, Ansible, or other related tooling. • Experience with integrating code scanning for vulnerabilities into CI/CD pipelines for Cloud Native deployments. • Experience with AD group structuring, Google Cloud Directory Sync (GCDS), and SAML 2 federated authentication. • Experience in designing data protection and privacy-centric security controls in enterprise data-warehouses including ingestion, ETL, storage, analytical consumption, and reporting. • Deeply articulate in security risks associated with SaaS services, their integration with legacy on-premise systems, and commonly associated security solutions. • Excellent technical and non-technical documentation skills including security standards, policies, guidelines, and procedures, change documentation, enterprise end-user communications, technical knowledge articles, infrastructure diagrams, and process charts. • Deep experience performing enterprise security risk assessments, selecting appropriate technical controls, liaising with business partners through the project lifecycle, and complete risk-acceptance handling of residual risks. • Strong Experience in applying industry standard cyber security frameworks and vendor blueprints to business problems • Proven ability to design, document, and implement reusable security patterns. • Proven hands-on experience implementing architectural big data security patterns in a scalable and consistent manner. • Strong leadership skills in accountability and customer focus • Proactive and able to catch issues before failures • Experience interacting with business users and vendors including vendor management • Strong analysis/troubleshooting skills • Excellent communication skills; feels comfortable working with non-technical business partners • Work with production support and project consultants in an onshore / offshore model • Flexibility of providing support during odd hours, weekends, and peak seasons • Minimal travel required (training/conferences)

Skills:

gcp, Cloud Security, Security Engineer

Top Skills Details:

gcp,Cloud Security,Security Engineer

Additional Skills & Qualifications:

ADDITIONAL RESPONSIBILITIES: • Partner with technical and non-technical team members to assess security risk in business solutions, across varied systems and landscapes. Recommend, develop, deploy, and monitor appropriate mitigating controls. Document and socialize residual risk. • Lead the risk analysis and security enablement efforts for strategic enterprise products. • Lead cloud experts and cloud novices through an infosec modernization of our cloud-native compute and data analytics platforms that rises to meet current threats • Identify analytical points of interest in raw data exports from security tooling and infrastructure systems, merging with other data sources, and build repeatable reports for management consumption • Develop and deploy automated solutions to monitor, alert, and remediate security and compliance findings in public cloud infrastructure and deployed code • Identity and solution for gaps in current security tooling and processes-- enabling improved delivery quality, efficiency, and accuracy.

Experience Level:

Intermediate Level

About TEKsystems:

We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.

The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

DirectEmployers