5-7 years of hands-on experience with REST API security and integrations.
Proficient in automation scripting and orchestration tools.
Strong grasp of integration patterns, including error handling and monitoring.
Experience with DevSecOps practices and CI/CD methodologies.
Deep knowledge of IAM and federal cybersecurity requirements.
Proven troubleshooting skills to solve complex security issues.
Ability to provide proactive security consultation and advisory services.
Responsibilities
Develop API integration architecture documents for cloud systems.
Create comprehensive testing and documentation for cloud API integrations.
Build and secure resilient API integrations for data access management.
Automate orchestration using serverless functions and scheduled jobs.
Support cloud access security broker initiatives and data loss prevention.
Collaborate with teams providing SME support on cloud security implementations.
Offer technical security consultation to engineering teams.
Benefits
Comprehensive health insurance options.
Flexible work hours with remote work opportunities.
Professional development and training programs.
Retirement plan with employer matching contributions.
Full Job Description
Job Title: Cloud Security Specialist (API) Job Location: Washington, DC
Project Description:
The IT Security Engineering Team is supporting a data access management project that requires a Senior Cloud Security Specialist with proficiency in REST API integrations. The Senior Cloud Security Specialist will need to provide hands-on API integration support between cloud applications using modern and secure techniques.
Background:
We are seeking a Senior Cloud Security Specialist to support the Security Engineering team within the IT division at the Board of Governors of Client. This team is responsible for the strategy, design, deployment, and maintenance of effective security solutions in cloud, local, and hybrid environments.
Requirements:
Required Experience:
Extensive REST API experience specifically in implementing, securing, automating, testing, and documenting API integrations.
Strong understanding of resilient integration patterns including error handling, retry mechanisms, and monitoring strategies.
Proficient in scripting and automation languages for security orchestration.
AWS Certified Solutions Architect - Professional or Associate.
Prefer experience with integrations between ServiceNow, Collibra, and Saviynt.
Experience implementing cloud-native serverless architectures and services.
Experience architecting and implementing security controls across public cloud platforms.
Experience implementing DevSecOps practices including continuous integration/deployment pipelines and infrastructure as code methodologies.
Experience implementing cloud access security broker (CASB) solutions for SaaS application security and visibility.
Strong understanding of security concepts and technologies related to Identity and Access Management (IAM), security engineering, network security design, security operations, security architecture, general engineering processes, cloud security, data loss protection, zero trust, DevSecOps, and vulnerability management.
Demonstrated federal experience and comprehensive knowledge in adopting and implementing federal cybersecurity requirements, including but not limited to the NIST Cybersecurity Framework, OMB Memorandum M-22-09, NIST SP 800-53.
Possess deep analytical, problem-solving, and troubleshooting experience, to independently resolve complex security challenges.
Proven ability to provide technical security consultation and advisory services with a proactive approach to identifying potential issues, raising questions, and engaging in open dialogue with team members and stakeholders to ensure security objectives are met.
The Consultant shall deliver, but not limited to, the following:
API integration architecture document detailing out the integrations between cloud systems.
Data model and attribute mapping across cloud systems.
Automation scripts and orchestration (serverless functions, scheduled jobs, event handlers).
Build resilient, secure API integrations between cloud applications in support of an end-to-end data access management solution.
Comprehensive testing and documentation of cloud integrations.
Support data loss prevention and cloud access security broker cloud initiatives.
Work across multiple teams as a Cloud Security Engineer SME to support security design, build, implementation, and monitoring of cloud platforms, applications, and tools.
Offer technical consultation to cloud engineering teams on secure implementations.
Create or update security configuration guides and playbooks.