Cloud Security Engineer

Tyto Athene

$140K — $150K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Minimum eight years of cyber security experience, six of which should be in a Cloud Security Engineer role within an enterprise SOC environment.
  • Proven expertise in cyber threat hunting in cloud environments including SaaS, PaaS, and IaaS.
  • Experience leading incident response for cloud infrastructures and associated security tools.
  • Hands-on experience with AWS is essential, along with knowledge of Azure and Google Cloud.
  • Bachelor's degree or equivalent relevant experience required.
  • Ability to communicate complex technical concepts in simple terms is necessary.
  • Active Top Secret Clearance with SCI eligibility is a must.

Responsibilities

  • Perform cloud threat hunting to identify embedded threats.
  • Analyze cloud logs for relevance and context.
  • Lead incident response for cloud security incidents.
  • Develop comprehensive incident response playbooks for cloud environments.
  • Collaborate with stakeholders for visibility into cloud workloads.
  • Onboard cloud logs to the SIEM tool and ensure proper event logging.
  • Create and implement monitoring use cases for immediate detection of cloud threats.
  • Tune security tools continuously for optimal performance.

Benefits

  • Health/Dental/Vision insurance
  • 401(k) matching
  • Paid Time Off policies
  • Short-Term/Long-Term Disability and Life Insurance coverage
  • Referral bonuses
  • Reimbursement for professional development
  • Parental leave
Full Job Description
Description

Tyto Athene is seeking an enthusiastic Cloud Security Engineer to help our largest Federal client monitor and secure their rapidly expanding cloud footprint against would-be attackers. The successful candidate will have a passion for and experience with being the foremost Cloud Security expert in a large, enterprise SOC environment and augment the team’s knowledge and skills regarding AWS to develop alerting and response procedures for cloud events and perform cloud hunting, monitoring, and incident response.

 

Responsibilities:

  • Perform cloud hunting and identify embedded threats effectively and efficiently
  • Review and analyze cloud logs to bring relevance and context to the data
  • Lead cloud incident response activities as they occur
  • Develop a full set of cloud incident response playbooks
  • Work with stakeholders to ensure full visibility into workloads running in the cloud
  • Ensure all cloud logs are onboarded to the SIEM tool and the correct events are logged
  • Develop and implement a full set of monitoring use cases to enable DOJ security tools to immediately and automatically detect cloud threats
  • Continuously tune security tools for optimization, i.e., maximum blocking with minimal false positives
  • Devise and implement additional KPIs and metrics that help DOJ monitor the overall health of this function
  • Ensure and enable DOJ’s participation in threat information-sharing initiatives across the USG
  • Assist the engineering team with the deployment, configuration, and maintenance of cloud-based SOC tools, technologies, applications, and solutions
  • Perform research and lead proof of concept efforts to determine where additional technologies may be necessary
Qualifications Required:
  • Able to work normal business hours (core) and occasional/limited on-call hours as requested by the client and/or as required by operational demands (e.g., during major incidents)
  • Willingness to work at the client site in Washington DC at least part of the time is required (hybrid/telework)
  • Eight (8) years of cyber security experience, with at least six (6) of those years working as a Cloud Security Engineer in an enterprise SOC environment
  • Demonstrated expertise in performing cyber threat hunting activities in cloud environments (e.g., SaaS, PaaS, IaaS, including O365, SIEM, EDR, and other cloud-based applications) is critically important
  • Demonstrated experience leading incident response activities when cloud-based tools and systems are involved
  • Experience across all major cloud providers (AWS, Azure, Google), with a focus on AWS
  • Bachelor’s degree required OR additional relevant experience
  • Ability to work as an integral part of a high-performing SOC team is required
  • Effective verbal and written communication skills that include the ability to describe highly technical concepts in non-technical terms
  • Understanding of recent cybersecurity policies and mandates such as EO 14028, M-21-31, NSM-8, and their impact on SOC activities

Desired:

  • Advance level Cloud Security certifications are strongly preferred (e.g.., AWS Security Specialty certification)
  • CISSP, GCIH, and similar certifications are a plus

Clearance:

  • Active Top Secret Clearance with SCI Eligibility is required
About Tyto Athene

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $140,000-$150,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

 

Similar Jobs

More Jobs at Tyto Athene

More Information Technology Jobs

Find similar Cloud Security Engineer jobs: