Senior Cloud Security Analyst/Engineer

CMA

United States

On-site

USD 90,000 - 130,000

Full time

28 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CMA seeks a Cloud Security Operations professional to monitor and manage cloud security events, IDS/IPS rules, and incident response. The role involves SIEM correlation, threat intelligence, and cross-team coordination to protect CMA’s cloud infrastructure.

Responsibilities include maintaining firewall and endpoint security, overseeing patching for Windows and UNIX, and producing management-ready security reports and recommendations.

Qualifications

  • Cloud SIEM familiarity and incident response planning are required.
  • Knowledge of security frameworks (NIST, CIS, OWASP) is required.

Responsibilities

  • Maintain and monitor IDS/IPS rules.
  • Administer cloud security for firewalls, endpoint protection tools, and patching for Windows and UNIX systems.
  • Configure and manage SIEM events, correlate malware and security events, and provide findings to management.
  • Monitor and review cloud-based LDAP/Active Directory accounts.
  • Maintain security incident tickets in ITSM and coordinate with staff to close tickets.
  • Assist investigations into cloud security intrusions and incidents, providing reports to management.
  • Monitor threat portals for cyber threat information and share updates with CMA staff.
  • Provide security analysis and recommendations for CMA security posture.

Skills

Cloud SIEM familiarity
BCP/IR
Security frameworks knowledge

Tools

EDR tools (Falcon, Symantec)
Cloud infrastructure security tools (GCP SCC, GCP Cloud Armor, AWS)

Job description

  • Maintain and monitor Network Intrusion Detection/Protection (IDS/IPS) rules.
  • Perform cloud security administration for Firewalls, Endpoint Protection tools, Windows & *nix patching tools.
  • SIEM: ability to create and manage cloud alerting events. Experience with AI-enabled enterprise products such as Splunk or LogRhythm desired. Configure or perform security event scanning, detection, and analysis using available tools and platforms. Review, collect, analyze, and correlate malware and security events from network security tools and provide results and recommendations to management. Correlate SIEM events for early warning, alerting, trends and prevention. Analyze event data received to eliminate false positives and identify security events. Conduct trend analysis of security events to identify anomalous malicious activity and related events.
  • Monitor and review cloud-based LDAP/Active Directory accounts.
  • Maintain and update security incident tickets within corporate ITSM. Review and update assigned ITSM security tasks. Open tickets for identified security events and incidents. Manage assigned tickets by working with appropriate staff.
  • Assist with investigations into cloud security intrusions, events, incidents, or suspicious activities. Monitor the cloud network and supporting systems to detect security compromise events. Provide reports and updates to management as needed.
  • Incorporate input from N/SOC staff and external vendor personnel to validate potential cloud events and incidents.
  • Monitor various cyber security threat portals and other credible sources for cyber threat information.
  • Monitor security group mailbox for email alerts and user requests.
  • Provide reports and attend scheduled and ad-hoc meetings as necessary.
  • Provide network and security operations technical analysis, assessment, and recommendations to CMA staff and management as needed. Provide cloud security threat prevention recommendations.
  • Provide enterprise-wide network systems and applications systems security log auditing or audit artifacts as needed.
  • Additional job duties as required.
Mandatory Qualifications
  • Cloud SIEM familiarity (GCP SCC, Splunk)
  • BCP/IR
  • Endpoint detection & response (EDR) tools (Falcon, Symantec)
  • Cloud Infrastructure security tools (GCP SCC, GCP Cloud Armor, AWS tools, IDS/IPS, FW, DNS)
  • Security control frameworks (NIST, CIS, OWASP, AI RMF)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Analyst & SIEM Engineer
Senior Cloud Security Analyst & SIEM Engineer

CMA • United States

On-site
USD 90,000 - 130,000
Security Analyst Senior
Security Analyst Senior

Donnelly- • New York (NY)

On-site
USD 130,000 - 170,000
Senior Security Engineer
Senior Security Engineer

Dexian • Dublin (CA)

On-site
USD 180,000 - 240,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Cybersecurity Analyst (AWS Cloud Security)
Cybersecurity Analyst (AWS Cloud Security)

Barton Malow Builders • Southfield (MI)

On-site
USD 80,000 - 110,000
Senior Cloud Security Engineer – SIEM (Remote)
Senior Cloud Security Engineer – SIEM (Remote)

CMA • City of Albany (NY)

On-site
USD 90,000 - 140,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States

On-site
USD 120,000 - 150,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Cloud Security Engineer
Cloud Security Engineer

Fabergent • Miami (FL)

On-site
USD 100,000 - 130,000
Senior Cloud Security Architect
Senior Cloud Security Architect

Compunnel, Inc. • New York (NY)

On-site
USD 130,000 - 160,000