CybersecurityJobs.io
← Back to all jobs

Job Description

The Cloud Security Engineer defines, documents, and implements infrastructure and application security best practices and standards in the cloud.

Responsibilities

  • Lead the introduction and adoption of Enterprise Information Security (EIS) team processes and disciplines in cloud environments (including Risk Management, Vulnerability Management, Secure Application Development, Secure Environment Configuration, and Identity Management)
  • Provide cloud configuration and deployment expertise for Gordon Food Service
  • Analyze cloud platform vulnerabilities and guide resolution through management and recommendations
  • Study, define, and implement secure provisioning, configuration, and operational practices for on-premise and off-premise cloud environments
  • Build and maintain configuration and deployment solutions via code to support security requirements in CI/CD
  • Research and track the evolving cloud threat landscape; adapt Gordon Food Service protection strategies to proactively address emerging threats
  • Conduct security risk assessments (including risk analysis for new cloud-related technologies or tools)
  • Perform internal penetration testing against new or modified software solutions
  • Coordinate external security assessments, including “grey-box” web application penetration tests
  • Provide security-focused cloud architecture guidance to Gordon Food Service software engineers
  • Write and maintain secure coding and configuration standards, and support best practices for custom software development
  • Interface with multiple teams across the organization in day-to-day activities

Requirements

  • Bachelor's Degree in Computer Science or a related field (preferred)
  • 5+ years of information technology experience, including software engineering, DevOps and/or system engineering, or an equivalent combination of education, training, and experience
  • Knowledge of security concepts such as SAST, DAST, RBAC, least privilege, and secrets management, plus scanning tools and network security concepts
  • Familiarity with CIA triad security concepts
  • Strong written and verbal communication skills; strong organizational and problem-solving capabilities
  • Ability to multitask and prioritize; ability to work independently and within a team
  • Experience with public cloud providers: Google Cloud Platform (GCP), AWS, and Azure
  • Experience with application containerization and container orchestration technologies
  • Experience with cloud-specific networking for mesh and least privilege network access
  • Experience with software-defined networking including routing, bridging, VLANs, and switches
  • Experience with build tools, configuration management tools, and provisioning tools
  • Experience with programming languages used in cloud development and configuration
  • Experience automating build and release processes
  • Knowledge of Unix/Linux
  • Knowledge of common productivity tools, particularly Google Apps (spreadsheet, word processing, presentation, email, and internet applications)

Technologies

  • Google Cloud Platform (GCP)
  • AWS
  • Azure
  • SAST
  • DAST
  • RBAC
  • Secrets management
  • Scanning tools
  • Application containerization
  • Container orchestration technologies
  • Cloud-specific networking technology
  • Mesh
  • Least privilege network access
  • Software-defined networking
  • Routing
  • Bridging
  • VLANs
  • Switches
  • Build tools
  • Configuration management tools
  • Provisioning tools
  • Unix/Linux
  • Google Apps

Work Location and Schedule

  • Location: Atlanta, GA (hybrid)
  • Hours: Monday to Friday, 8am to 5pm
  • Hybrid cadence: 4 days in office in Wyoming, MI or Atlanta, GA with 1 day remote

Similar Jobs