Cloud Security Specialist
Atlanta, GA, United States
Emory Healthcare
Emory is your one-stop shop for all of your health care needs, both in sickness and in health.Overview
Be inspired. Be rewarded. Belong. At Emory Healthcare.
At Emory Healthcare we fuel your professional journey with better benefits, valuable resources, ongoing mentorship and leadership programs for all types of jobs, and a supportive environment that enables you to reach new heights in your career and be what you want to be. We provide:
- Comprehensive health benefits that start day 1
- Student Loan Repayment Assistance & Reimbursement Programs
- Family-focused benefits
- Wellness incentives
- Ongoing mentorship, development, and leadership programs
- And more
Description
Emory Healthcare (EHC), part of Emory University, is the most comprehensive academic health system in Georgia committed to providing the best care for our patients, educating health professionals and leaders for the future, pursuing discovery research in all of its forms, including basic, clinical, and population-based research, and serving our community. As the clinical enterprise of the Robert W. Woodruff Health Sciences Center of Emory University, Emory Healthcare is dedicated to the unifying core purpose, core values, and strategic direction of the Robert W. Woodruff Health Sciences Center. The Cloud Security Specialist directs and provides hardening guidance for cloud services from Cloud Service Providers such as Amazon, Azure and Google.
RESPONSIBILITIES:
- Develops, implements, monitors and enhances data security policies, procedures, and standards related to AWS Azure, and GCP.
- Works with a team of Cloud Security Professionals where work is assigned via scaled agile methodology and distributed based on priority and skillset of team members.
- Perform in-depth risk assessments to ensure that the security safeguards and controls are aligned with our security policy and standards.
- Review infrastructure design on-premises and on the Cloud (inclusive of container security architecture, data security architecture, network security architecture, and operational security architecture).
- Assess the infrastructure and microservices design against different security regulatory, industry and internal standards which are based on NIST, HIPAA security guidelines and identify the necessary security architecture requirements.
- Execute on Cloud security engagements during different phases of the lifecycle, assess, design and implementation.
- Implementing industry-leading practices around cyber risks and cloud security.
- Research, create, develop and enforce security policies, standards and procedures to ensure the protection of the organizations security and systems as specified by the HIPAA/NIST control framework.
- Provide IT and business resources guidance in interpreting security compliance requirements and performing application and system security assessments.
MINIMUM QUALIFICATIONS:
- 5+ years of relevant information security and information risk management experience.
- 3+ years of relevant experience in Public Cloud Security, including IaaS, PaaS and SaaS.
- Skills/Abilities/Competencies
- Familiarity of Infrastructure as a Service,
- Infrastructure as Code and related concepts on Azure or Amazon Web Services (AWS).
- Knowledge of cybersecurity concepts, including threats, vulnerabilities, security operations, encryption, boundary defense, auditing, authentication and risk management.
- Skilled experience in Cloud Security Architecture and Microservices Security (e.g. Tenant Security, AKS Security, Containers Security, Pod Security, Application Gateway & WAF, Security Groups and VNET Segmentations, Security Analytics, etc.).
- Knowledgeable in the dependencies related to end-point security and interaction with other components such as privilege management system, SIEM, SOAR, vulnerability management solution and operating model, PKI/Encryption technology, Firewall/IPS, WAF etc.
- Understanding the dependencies related to application security best practices such as secure coding, security testing techniques. Working knowledge of common and industry standard cloud-native/cloud-friendly authentication mechanisms (OAuth, OpenID, etc.).
- Experience and exposure to threat modelling and design reviews to assess security implications and requirements for the introduction of new technologies.
- Skilled in representing technical viewpoints to diverse audiences and in making timely and prudent technical risk decisions.
- In-depth understanding in applying native cloud security and monitoring services in the cloud, including network firewalls, access control lists, encryption, auditing and monitoring, alerting, secrets management and compliance scanning.
- Knowledge of configuration management technologies (i.e., SaltStack and Ansible), Infrastructure Automation Technologies (i.e., Terraform), Containerization and Cloud Orchestration Technologies (i.e., Kubernetes, Dockers), Windows/Linux and related services (i.e., Active Directory, DNS, MSSQL). Experience with DevOps Concepts and DevOps tooling such as Terraform, GitHub, Jenkins, SaltStack, XL Release, Bit Bucket.
- Skilled in full software or systems development life cycle, including requirements analysis, design, integration, testing and implementation.
- Knowledge of federal IT and cloud security policies, including FISMA, FedRAMP, NIST 80053, and DoD Cloud SRG and applying them to the design and implementation of cloud solutions to achieve an authorization to operate (ATO).
- Technology Risk Management & Compliance experience. Cloud Migration Experience Azure & Google.
Additional Details
Emory is an equal opportunity employer, and qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by state or federal law.
Emory Healthcare is committed to providing reasonable accommodations to qualified individuals with disabilities upon request. Please contact Emory Healthcare’s Human Resources at careers@emoryhealthcare.org. Please note that one week's advance notice is preferred.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Active Directory Agile Analytics Ansible Application security Audits Automation AWS Azure Cloud Compliance DevOps DNS DoD Encryption FedRAMP Firewalls FISMA GCP GitHub HIPAA IaaS IPS Jenkins Kubernetes Linux Microservices Monitoring MSSQL Network security NIST OpenID PaaS PKI Risk assessment Risk management SaaS SDLC Security assessment SIEM SOAR Terraform Vulnerabilities Vulnerability management Windows
Perks/benefits: Career development Health care Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.