Senior Cloud Security Engineer – FedRamp

🕒 Maio 4

🤠 Texas – Remoto

info

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🦅 Patrocina Visto H1B

info

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of Zimperium

Zimperium

201 - 500 funcionários

Fundada em 2010

🔒 Cibersegurança

🏢 Corporativo

☁️ SaaS

💰 $12.000.000 Venture Round em 2018-11

Cybersecurity • Enterprise • SaaS

Zimperium é uma empresa líder no setor de segurança móvel, especializada em segurança de endpoints e aplicações móveis. Eles fornecem soluções avançadas para proteger dispositivos móveis e aplicações, permitindo que as empresas protejam seus endpoints móveis e possibilitem acesso seguro a dados e sistemas sensíveis. As plataformas da Zimperium se integram com diversos ambientes, incluindo a nuvem, instalações locais e configurações isoladas, garantindo segurança contínua e persistente durante o desenvolvimento e a execução. A empresa é reconhecida por seu foco único em segurança móvel, oferecendo ferramentas que ajudam a prevenir perda de dados, fraudes e violações regulatórias em aplicativos móveis.

Descrição

• Design, implement, and manage security best practices and controls for services hosted across AWS, Azure, GCP, and OCI environments. • Act as the subject matter expert for security automation, leveraging CloudFormation and/or Terraform to deploy secure infrastructure consistently and at scale. • Implement and enforce rigorous security configuration benchmarks, specifically CIS Level 2 and DISA STIGs, across all compute environments, including various flavors of Linux and Kubernetes clusters. • Configure, manage, and optimize cloud-native and third-party security tools such as Palo Alto Prisma Cloud, Orca, Google SecOps, and Palo Alto Next Generation Firewalls. • Deploy and manage Web Application Firewalls (WAFs), including F5 and other cloud-native WAF solutions, to protect critical applications. • Integrate security testing tools (SAST, DAST, SCA) into CI/CD pipelines to enable "shift-left" security practices. • Design and maintain solutions for the secure storage and rotation of credentials, API keys, and secrets using tools like HashiCorp Vault or equivalent cloud-native services. • Conduct threat modeling and perform security reviews for new applications and services to proactively identify and mitigate risks in the design phase. • Participate in a rotating on-call schedule to address security incidents and operational issues promptly. • Support internal and external audits by generating evidence, writing detailed reports, and delivering clear, concise technical presentations to leadership. • Operate with minimal oversight, taking the initiative to identify and suggest security improvements and drive projects to completion.

🎯 Requisitos

• 8+ years of progressive experience in IT, with at least 5 years dedicated to Cloud Security Engineering in a multi-cloud environment. • Expert-level proficiency in Infrastructure as Code (IaC) for security automation using Terraform and/or CloudFormation. • Deep practical experience securing at least three of the following major cloud providers: AWS, Azure, GCP, and OCI. • Proven expertise in system hardening using industry standards like CIS Level 2 and DISA STIGs. • Extensive experience with Linux administration and securing containerization technologies, specifically Kubernetes. • Hands-on experience with advanced security platforms, including at least two of the following: Palo Alto Prisma Cloud, Orca, Google SecOps, and Palo Alto Next Generation Firewalls. • Demonstrated experience with WAF solutions, such as F5 or equivalent cloud-native services. • Strong working knowledge of DevSecOps principles, including integrating security tools into CI/CD pipelines. • Proven experience with Secret Management solutions (e.g., HashiCorp Vault, AWS Secrets Manager). • Excellent written and verbal communication skills, including the ability to write executive-level reports and deliver technical presentations. • Proven ability to operate independently and take ownership of critical responsibilities.

🏖️ Benefícios

• Health insurance • Remote work options

Candidatar-se

Vagas Similares

🕒 Maio 4

DuckDuckGo

51 - 200

🔒 Cibersegurança

Senior Web Security Engineer ensuring security capabilities during rapid product development at DuckDuckGo. Conduct browser audits and manage application security scanning infrastructure.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $178.500 / ano

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Maio 4

Tenable

1001 - 5000

🔒 Cibersegurança

☁️ SaaS

🏢 Corporativo

Security Consultant implementing Tenable’s Exposure Management solutions to manage cyber risks. Onboarding Tenable technologies to deliver customized solutions and ensuring vulnerability mitigation.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Maio 4

Upstart

1001 - 5000

Security Engineer II at Upstart focusing on security controls for cloud and infrastructure systems. Partnering with engineering teams to reduce risks and improve systems' security.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Maio 4

GuidePoint Security

201 - 500

🔒 Cibersegurança

CNAPP Cloud Security Engineer providing delivery services for cloud security tools and technologies. Advising and implementing solutions for customers across multiple sectors.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Maio 4

Urrly

1 - 10

🎯 Recrutamento

⚕️ Seguro de Saúde

🤖 Inteligência Artificial

Cybersecurity Compliance Consultant leading CMMC policy development for DoD contractors. Managing compliance sprints and client documentation for audit readiness in a fully remote setup.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $100.000 - $125.000 / ano

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório