Job Title: Sr. Cloud Security Engineer
Summary of Position:
The Sr. Cloud Security Engineer is responsible for designing, implementing, and maintaining cybersecurity solutions that protect the organization's information technology infrastructure. The Sr. Cloud Security Engineer is a key contributor in complex initiatives focused on delivering advanced. comprhensive cloud security solutions for the enterprise. The postion will collaborate closely with other senior security engineers, architects, and various engineering diciplines to ensure that adequate cloud security solutions are designed, implemented, and configured appropriately.
Principal Duties and Responsibilities:
Cloud Security:
- Demonstrate leadership and technical expertise in planning, ownership, & management of the Organization's cloud security strategy.
- Lead the design, implementation, and management of cloud security solutions such as: Core security capabilities for protecting IaaS, PaaS, & SaaS services
- Cloud Security Posture Management (CSPM)
- Cloud Access Security Broker (CASB)
- Cloud-Native Application Protection Platforms (CNAPP)
- Security Service Edge (SSE)
- Provide expertise and guidance with securing cloud-native application development and delivery platforms (DevOps, CI/CD) with demonstrated strength in DevSecOps tooling (SAST, DAST).
- Ensure that adequate security tools and controls are deployed for effective protection throughout the Organization's cloud environments
- Satisfy any legal, compliance, and regulatory requirements related to cloud security controls.
- Ensure the development of and adherence to security policies, standards, procedures, and best practices in all areas of cloud security engineering and operations.
- Contribute to the development of the Cybersecurity Program and Security Engineering and Architecture roadmaps.
- As it relates to Cloud Security, collaborate and provide input to Lennar's Cybersecurity teams in the areas of Risk Management, Compliance, and Incident Response.
- Promotes and facilitates effective communication between Security Engineering & Architecture, Enterprise Architecture, Infrastructure, and other departments and/or business units.
- Assist in the acquisition and risk assessment, procurement, and evaluation of new vendor and product selections.
- Evaluate and recommend new and emerging services and technologies.
- Assist with remediation efforts and recommendations as it relates to external and internal security audits.
- Participate as an active member of the Security Incident Response Team, including post-mortem investigation activities.
- May provide mentorship and support to various junior security engineers and security operations team members.
Education and Experience Requirements:
- Education: Bachelor's degree required in Computer Science, Cybersecurity, Engineering, or related field. Master's degree preferred.
- Experience: 3 - 5+ years of relevant work experience in cloud security engineering, cloud network solutions, and cloud-native application security testing tools
- 3 - 5+ years of experience with implementing and managing security technologies in a mid to large-scale enterprise environment.
- 3 - 5+ years of experience with securing IaaS/PaaS/SaaS resources hosted in public cloud environments (AWS, Microsoft Azure, Oracle OCI).
- 3+ years of experience with DevSecOps components, including a strong understanding of DevOps and a Software Development Lifecyle, implementation of static/dynamic application testing solutions, and application vulnerability discovery/assessment/remediation support.
- Experience securing SaaS cloud-delivery platforms (i.e. Microsoft 365, Salesforce, Box.com) with CASB, CSPM, and similar technologies.
Certifications: Certified Information Systems Security Professional (CISSP), Azure Security Engineer Associate, AWS Certified Security-Specialty, Certified Cloud Security Professional (CSSP), GIAC Cloud Security Automation (GCSA), AWS Solutions Architect Professional, Certificate of Cloud Security Knowledge (CCSK), or similar advanced security certifications preferred.
Additional Skills, Knowledge, and Experience:
- Expert knowledge of cloud identity and access controls, including federation between on-premises identities and cloud platforms.
- Expert knowledge of cloud network security fundamentals, including securing VNET/VPC's, Web Application Firewalls, and cloud-native Firewall-as-a-Service solutions.
- Experience with Security Information and Event Management Systems (SIEM) and log management systems (Splunk, Exabeam, Microsoft Sentinel).
- Experience with Threat & Vulnerability Management solutions (Rapid7, Nessus, Qualys).
- Ability to analyze and communicate strengths, weaknesses, and derive recommendations for enhancing the organization's cloud security posture.
- Experience identifying and analyzing emerging and advanced threats, with a focus on cloud and application layer attack vectors (OWASP Top -10, secure coding practices).
- Experience with OWASP Software Assurance Maturity Mode