Unknown Company

Cloud-Software Eng III

durham, nc • Posted 3 days ago
Onsite Full Time General

Cloud-Software Eng III (US)The Global Certification Team for XaaS certifications is building a Center of Excellence for Cisco's global cloud certifications. This team is growing to centralize and standardize the cloud certification process for Cisco, including FedRAMP, SOC2, ISO27001, etc. The SOC2 Cloud Authorization Engineer (CAE) role is to support securing initial global regulatory cloud certifications as well as annual renewals for Cisco cloud offer certifications by:providing technical guidance on the implementation and documentation of the cloud certification requirements,ensuring each certification is compliant with relevant regulatory and certification security requirements (e.g.

FISMA, FedRAMP, SOC2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, HITRUST, CJIS, C5, SOC, etc.),partnering with the business unit to remove impediments beyond/outside of the business unit that jeopardize securing or retaining a cloud certification.The CAE will have broad technical background and experience necessary to support multiple cloud product certifications which may span offices, time zones and hemispheres. The CAE will have experience with architecture, design and operations of cloud solutions and the how to meet security compliance requirements. Must have the ability to propose technical solutions to complex security compliance issues.

The CAE should have a clear understanding and experience implementing SOC 2 Type II certifications, knowledge and/or experience with at least one other major cloud certification (FedRAMP, SOC2, ISO 27001, or HITRUST), and understanding of the cloud authorization processes. NIST and/or FISMA experience is also preferred along with basic competencies in the areas:Day to Day Duties:Working with multiple stakeholders (internal and external) across product lines to assess and identify security compliance gaps and propose technical remediation solutions and options necessary to secure a certificationAssisting with technical questions regarding control implementation as well as post authorization activities such as significant change, annual authorization renewals, etc.Reviewing current system security measures and recommending and implementing enhancementsTranslating complex concepts and solutions into documents required for the certification (i.e. System Security Plan)Working knowledge or experience conducting system security and vulnerability analyses and risk assessmentsUpdating security knowledge by tracking and understanding emerging security practices and standards; participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizationsCollaborating effectively across multiple organizations with diverse personalities and expertise to drive to agreement on complex issuesMinimum Qualifications:**Must be a US Citizen**2+ years specialized experience in reviewing security documentation for requirements, compliance, compliance documentation, testing results, standard operating procedures, system security plans, etc.2+ years of SOC2 Type II certification experienceUnderstanding of cloud security and overall cloud computing architectureExperience with communication between leadership, operational teams, development teams and certification teamsUnderstanding of development of presentation materials and overall presentation skills around technology and complianceExperience applying process improvement techniquesExcellent written and verbal communication skillsSolid understanding of security protocols, cryptography, authentication, authorization and securityDesired Skills:2+ years of certification experience with (ISO27001, FedRAMP, PCI DSS, SOC2, HITRUST, or CJIS)Applicable industry security certifications (e.g.

CAP, CISA, Associate of CISSP, GIAC, etc.) a plusSecure Software Development Lifecycle experience a plusExperience writing scripts and tools

Back to Job Search