This position is needed to provide direct support to the Office of Cybersecurity team to meet Agency, State and Federal security & privacy goals and compliance requirements.
Responsibilities:
- The Cloud Cybersecurity Analyst will be performing monitor, detect and response capabilities in the agency cloud infrastructure.
- This role will work with the stakeholders to help architect, build and maintain a Secure Cloud Infrastructure by adhering to Agency policy and industry best practices.
- This position will report directly to the CISO to drive innovation and maturation of the Agency's Cloud Cyber threat detection and response capabilities.
Essential Responsibilities
- Perform threat identification and analysis of risks to the Agency Cloud environments
- Conduct penetration testing and vulnerability assessments on Azure cloud infrastructure and applications.
- Provide input and feedback on cloud/hybrid architectures related to Security
- Assist in the implementation and advancement of Continuous Monitoring and Incident Response processes and procedures
- Assist in investigation and remediation of Compliance policy violations, security incidents and related issues
- Investigate and remediate compliance policy violations, security incidents, and related issues.
- Serve as a Security Point of Contact for matters related to Securing Cloud Infrastructure
- Consult on, and provide requirements for critical projects and initiatives
- Create and maintain documentation for security processes and penetration testing results.
- Revise documents and artifacts as tactics and techniques evolve to address new and emergent threats and trends
- Work with stakeholders to advance security efforts of the Agency Cloud Environments
- Raise the awareness level of cloud security in the agency
- Conduct Security Assessments to identify areas of risk and ensure gaps are remediated
- Effectively communicate to management and business stakeholders the status of projects and issues as they relate to Cloud Security
- Perform security posture assessments using Azure-native tools (Microsoft Defender for Cloud, Azure Security Center, etc.)
Required/Preferred Skills:
Required:
- Cloud Security or Architecture Certification
- 5+ years of experience with Cyber Threat Monitoring, Detection, Response and Incident Handling
- Knowledge of OWASP Top 10 and cloud-specific attack vectors
- Experience with vulnerability management and remediation in cloud environments
- 5+ years of experience of I.T. working with Windows, Linux, Cloud technologies or Web-based applications
- Hands-on experience with penetration testing tools (Burp Suite, Metasploit, Nmap, Kali Linux)
Preferred Skills
- BS degree in computer science, information technology, engineering or similar discipline
- Microsoft Certified: Azure Security Engineer Associate), Network Security Certifications
- COMPTIA CLOUD +
- Experience with Prisma Cloud, Dome9 or similar Cloud Security capabilities
- Prior experience working with cloud security and governance tools, cloud access security brokers (CASBs), and Infrastructure as Code (IaC)
- Experience with designing and deploying an Inspection architecture in a Cloud Environment.
- Experience with full-stack deployment
- CISSP
- 3+ years of experience with Cloud platforms (in order of preference) such as Microsoft Azure, Amazon Web Services (AWS) and/or GCP
V Group Inc. is a NJ-based IT Services and Products Company with its business strategically categorized in various Business Units including Public Sector, Enterprise Solutions, Professional Services, Ecommerce, Projects, and Products. Within Public Sector business unit, we cater IT Professional Services to Federal, State and Local. We have multiple awards/ contracts with 30+ states, including but not limited to NY, CA, FL, GA, MD, MI, NC, OH, OR, CO, CT, TN, PA, TX, VA, NM, VT, and WA.
If you are considering applying for a position with V Group, or in partnering with us on a position, please feel free to contact me for any questions you may have regarding our services and the advantages we can offer you as a consultant.
Please share my contact information with others working in Information Technology.