Senior Cloud Security Specialist (AWS)The Senior Cloud Security Specialist (AWS) within Emory’s Enterprise Information Security team, will be primarily responsible for working with the Enterprise Security and other Emory IT teams to identify, evaluate, and implement security controls for cloud services. This will mainly include Amazon Web Services, but will encompass all future cloud related activities.Familiarity with IT aspects of a healthcare environment would be preferred, but not required, such as: healthcare IT data transfer protocols, healthcare industry terminology, HIPAA regulations, medical device network and telemetry concepts, data encryption, security industry recommended best practices, and healthcare information security policies and laws.JOB DESCRIPTION:Responsible for developing incident detection and response capabilities within cloud services, creating appropriate guardrails for users in the cloud environment to work within their space, and performing security reviews on systems being migrated to the cloud.Support Emory University’s migration of on-premise solutions to the cloud, and support Emory Healthcare’s adoption of cloud services.Assist with information security activities with university or healthcare units across the enterprise.Utilize technical and thought-leadership responsibilities for multiple information security disciplines such as incident response, vulnerability management, intrusion detection and prevention, threat hunting, security operations, security policy, and awareness/education.Oversees information security incident response activities, risk assessment and risk management activities, and vulnerability assessment and vulnerability management activities spanning University and Healthcare business units.Manages detailed network, operating system, database, and application vulnerability assessments and security configuration audits. Manages initiatives.Oversees operational tasks supporting information security functions such as intrusion detection and prevention, security event log analysis, management reporting, malware prevention and remediation, encryption, network segmentation, remote access, cloud security, and authentication.Drafts and reviews information security policies, processes, and procedures.Prepares information security awareness and education materials and other documentation.Determines and documents information security requirements and controls necessary for the protection of information resources.Provides guidance and assistance regarding information security matters such as the interpretation of information security policies and requirements or their applicability to particular situations.May independently develops automated tools and methodologies.Analyzes data from Information Security functions and provides reports and recommended response actions to Information Security management.Represents Information Security to other organizations on information security related matters, as assigned.Publishes regular status reports and submits to management.As a member of the Enterprise Security team, the position will also be tasked with other information security related tasks and projects as necessary.Performs related responsibilities as required.Certifications that would be most appropriate for this position, but not required, are as follows:AWS Certified Solutions Architect / ProfessionalAWS Certified Security - SpecialtyAWS Certified SysOps AdministratorCISSP – Certified Information Systems Security ProfessionalGCSA – GIAC Cloud Security AutomationGCPN – GIAC Cloud Penetration TesterGPCS – GIAC Public Cloud SecurityGCIA – GIAC Certified Intrusion AnalystGCIH – GIAC Certified Incident HandlerGCED – GIAC Certified Enterprise DefenderGCFE – GIAC Certified Forensic ExaminerGCFA – GIAC Certified Forensic AnalystGREM – GIAC Reverse Engineering MalwareCHSE - Certified HIPAA Security ExpertCHPSE - Certified HIPAA Privacy and Security ExpertMINIMUM QUALIFICATIONS:A bachelor's degree and five years of related IT experience including demonstrated technical expertise in multiple information security domains, or an equivalent combination of education, training and experience.Excellent team participation skills, as well as good written and verbal communication skills.Strongly preferred qualifications include knowledge of information security technologies, methodologies, and best practices in the domains of: security incident response, vulnerability assessment and management, intrusion detection and prevention, system administration (Windows, OS X, Linux, etc.), security administration of networks, operating systems, databases and applications, access control, encryption, firewalls and proxies, networking, security event log analysis, malware prevention and remediation, cloud technologies, programming/scripting, and risk assessment and management.Security certifications are a plus (e.g.
SANS/GIAC, CISSP, CISA, CISM).PREFERRED QUALIFICATIONS:Significant experience with various SaaS, IaaS, and PaaS services, but especially Amazon Web Services (AWS).Significant experience designing, maintaining, and implementing security controls and technologies in cloud environments.Experience with AWS technologies such as, but not limited to: VPCs, Organizations, IAM, KMS, Security Groups, GuardDuty, CloudTrail, CloudWatch, Macie, Secrets Manager, Security Hub, Systems Manager, Inspector, Detective, Lambda, and Config (Rules and Compliance Packs).Experience and/or familiarity with concepts such as logging, SIEM, firewalls/WAFs, VPNs, subnets, ACLs/NACLs, penetration testing, encryption, automation, pipelines, code repos, and DevOps / DevSecOps.Experience with Windows and Linux systems.Familiarity with programming languages such as: Python, Bash, PowerShell, Java, Go, Node.jsExperience with IaC such as Terraform, CloudFormation.Experience conducting detailed application, system, and network vulnerability assessments and/or security configuration audits.Experience conducting incident response and/or forensic analysis activities.Experience with Microsoft Azure and/or Google Cloud Platform (GCP) is a plus.Ability to create comprehensive documentation.Ability to work with other teams to implement security goals.Customer service skills for both internal and external customers.