Unknown Company
Associate Security Consultant, Security Transformation Services
Minimum qualifications:
- Bachelor's degree in Computer Science, Information Systems, Cyber-security or a related technical field, or equivalent practical experience.
- Experience in information security and cloud security.
- Experience managing Wiz, or Cloud Security Posture Management (CSPM), across Google Cloud Platform (GCP).
- Experience using Python.
Preferred qualifications:
- Experience with end-to-end attack life-cycle and tactics, techniques, and procedures (TTPs).
- Experience supporting incident response efforts within cloud environments, specifically using CSPM data to provide context during an investigation.
- Understanding of zero trust, identity and access management (IAM), and container security.
- Ability to implement Center for Internet Security (CIS), National Institute of Standards and Technology (NIST), and Payment Card Industry Data Security Standard (PCI-DSS) frameworks.
- Ability to communicate technical risks to executives, manage projects, produce reports, draft approach papers, while creating custom dashboards to demonstrate security posture improvements.
About the job
Mandiant Security Transformation Services (STS) helps organizations build an effective security operations program that minimizes organizational risk and reduces the impact of security breaches. With targeted focus in on-premises and cloud architecture, our consultants work from initial assessment, on-site workshops to explore clients on-premises and cloud environment, configuration review of security controls, to detailed practical technical recommendations to harden the on-premises and cloud environment, enhance visibility and detection, and improve processes to reduce the risk of compromise.
In this role, you will lead the operationalization of the Wiz platform, integrating multi-cloud environments to achieve total asset visibility. You will bridge the gap between Cloud Engineering and Security Operations (SOC) by tuning misconfiguration detection rules, integrating alerts into Security Information and Event Management/Security Orchestration, Automation, and Response (SIEM/SOAR) pipelines, and defining automated remediation responses using cloud-native tools and Python/API scripting. You will deliver actionable executive reports, collaborate daily with client stakeholders to drive risk reduction, and support incident response efforts. You will require proficiency in Wiz, supported by relevant cloud certifications.
Responsibilities
- Serve as the embedded subject matter expert, integrating multi-cloud environments into the Wiz platform to ensure comprehensive asset visibility and effective policy configuration.
- Collaborate with SOC and Cloud Engineering teams to define automated remediation responses, tune misconfiguration detection rules, and integrate cloud security posture management (CSPM) alerts into existing SIEM, SOAR, and ticketing workflows.
- Configure and manage automated compliance checks against industry-standard frameworks (CIS Benchmarks, NIST, PCI-DSS, GDPR) and translate governance principles into technical rule sets.
- Conduct in-depth security posture reviews, delivering technical reports and executive dashboards that translate complex findings into actionable remediation steps.
- Travel up to 50% of the time as required by client engagement.