FreshRemote.Work

Senior Cloud Security Engineer - Remote

ABOUT THE ROLE:

As Rightway's pioneering Cloud Security Engineer, you'll lead the charge in securing cloud environments compliant with HIPAA and HITRUST standards. You will be instrumental in fortifying our current cloud infrastructure and shaping new cloud initiatives (“greenfields”) to support our B2B and B2C applications, directly impacting the healthcare outcomes of our members. We deeply believe in mentorship and learning from each other, so you can expect to both guide and be guided on your journey with us!

WHAT YOU’LL DO:

  • Evaluate and deploy vulnerability scanners for web application, image, and container runtime security (e.g., Snyk, Trivy, StackRox, Checkov, Falco, Grype)
  • Spearhead the scoring and triage of vulnerabilities, applying context to CVSS scores and utilizing threat intelligence, and other measures of exploitability (e.g., EPSS)  to prioritize real risks over false positives.
  • Enhance CI/CD pipelines (e.g., BitBucket, CircleCI, Jenkins, GitLab) for gating security vulnerabilities detected at various levels (e.g. IaC, Container, OSS Library).
  • Tune Web Application Firewalls (WAFs) such as CloudFlare or optimize AWS Web Application Firewall for robust OWASP based functionality/rulesets. 
  • Configure Application Performance Monitoring (APM) tools (e.g. Datadog) to meet security and compliance requirements by writing regular expressions and queries.
  • Craft scripts for threat detection and incident response, ensuring our proprietary applications remain secure against emerging threats.
  • Design and enforce robust security controls to enhance key management.
  • Deploy tooling such as Prowler, CloudCustodian, etc. to perform best practice assessment and embrace Governance as Code, to meet HIPAA/HITRUST requirements. 
  • Coordinate external/internal infrastructure penetration testing then validate, prioritize, and mitigate/remediate findings. 
  • Manage zero-trust network architectures, ensuring secure and compliant connectivity between endpoints and cloud services. (e.g., ZScaler, Twingate).
  • Partners with DevOps/SRE function to provide security input and architecture review of …

Hey, this job isn't fresh anymore!

Search Fresh Jobs

Job Profile

Skills

Application Performance Monitoring AWS AWS services CI/CD CI/CD pipelines Datadog Incident Response Infrastructure as Code Key Management Kubernetes Penetration Testing Terraform Threat Detection Vulnerability Scanners Web Application Firewalls Zero-Trust Network Architectures

Tasks
  • Configure APM tools
  • Coordinate penetration testing
  • Craft scripts for threat detection
  • Design and enforce security controls
  • Enhance CI/CD pipelines
  • Evaluate and deploy vulnerability scanners
  • Manage zero-trust network architectures
  • Provide security input and architecture review
  • Tune Web Application Firewalls
Experience

10 years

Certifications

AWS Security Specialty AWS Solutions Architect CCSP CEH