Job Overview
A Cyber Security Engineer responsible for maintaining security measures that protect the organization’s systems, cloud workloads, and data. Focuses on identifying vulnerabilities, operating security tools across on-premises and cloud environments, providing guidance to engineering teams, and supporting incident response efforts.
Key Responsibilities
- Cloud posture across AWS (and/or Azure/GCP), identify misconfigurations and risks, drive remediation by partnering with cloud and application owners.
- Provide security guidance and advisory support to cloud, infrastructure, and development teams on secure configuration, IAM, encryption, network segmentation, and logging.
- Support secure cloud architecture reviews and ensure alignment with the Framework (Security Pillar), CIS Benchmarks, and organizational cloud security standards.
- Understand network protocols and network security tools like NAC, IPS.
- Administer IAM platforms and integrations (e.g., SSO, MFA, directory services, conditional access) across on-premises and cloud environments.
- Conduct vulnerability assessments across on-premises, cloud, and container workloads to identify potential risks.
- Assist in remediation of vulnerabilities by working closely with IT, cloud, and development teams.
- Deploy, configure, and maintain security tools such as IDS/IPS, endpoint protection, SIEM, and WAF.
- Develop, implement, and enforce security policies and procedures, including cloud security standards and guardrails.
- Perform routine audits to ensure security compliance with organizational policies and regulatory requirements (e.g., NIST CSF, PCI DSS, SOX) across hybrid and cloud environments.
- Research and stay informed about current cybersecurity threats, vulnerabilities, cloud attack techniques, and best practices.
- Provide technical support and guidance to IT, cloud engineering, and development staff on security-related issues.
Qualifications
- Hands-on experience operating a CSPM/CNAPP platform (Orca preferred; Wiz, Prisma Cloud, or Defender for Cloud also relevant).
- Working knowledge of at least one major cloud provider (AWS preferred), including native security services (GuardDuty, Security Hub, IAM Identity Center, KMS, CloudTrail, WAF/Shield).
- Strong understanding of cloud security concepts including IAM, key management, network security (VPC, transit gateway, private endpoints), logging/monitoring, and shared responsibility models.
- Ability to interpret cloud misconfiguration findings, assess risk, and clearly communicate remediation guidance to cloud and application teams.
- Exposure to container and serverless security concepts (EKS, ECS, Lambda) is a plus.
- Cloud security certifications such as AWS Certified Security – Specialty, AWS Certified Solutions Architect, Microsoft SC-200/AZ-500, or CCSP are highly desired.
- Bachelor’s degree in Cyber Security, Computer Science, or related field, or equivalent relevant work experience.
- 2–5 years of experience in cyber security or related roles, including exposure to cloud environments.
- Additional certifications such as Security+, CEH, or CySA+ are desired.
- Knowledge of security tools, technologies, and best practices across enterprise and cloud environments.
- Strong understanding of networking and operating systems.
- Analytical and problem-solving skills with attention to detail.
- Ability to work collaboratively in a team environment and communicate technical concepts effectively.
Policy and EEO Statement
NRG Energy is committed to a drug and alcohol-free workplace. Employees may be subject to periodic random drug testing and post-accident testing as permitted by law. We are an Equal Opportunity Employer. Compensation may vary based on experience or skills.
#J-18808-Ljbffr