JOBSEARCHER

Senior Cloud Engineer/ CON EDISON

Senior Cloud EngineerContract: 1 yearLocation: New York, New YorkExperience: 8+ yearsClient: ClientVisa: No H1B & CPTJob Description:Under the general guidance of the IT Architect or Systems Manager, the candidate will be responsible for evaluating and implementing new technologies, analyzing infrastructure and software designs and implementations, and identify and resolve potential issues to help enhance and secure a large enterprise network.Responsible for designing complex and innovative solutions addressing vulnerability detection, threat and risk analysis, network intrusion, securing technology assets across the application, infrastructure, cloud and data tiers and development/implementation of vulnerability mitigation strategies.This is a hands-on team member who actively works with various teams including security, infrastructure and development teams to improve our overall security standards.Expected to be the last level of technical escalation within the company for the assigned responsibilitiesGuides engineering teams and makes informed security decisions on the design of infrastructure, systems and applicationsWorks with tech leads and teams to ensure security is built into app development, network infrastructure and cloud systems.Work with necessary Information Technology groups to satisfy specific technology related issues.Act as an Information Security liaison between the customers and all groups in Information TechnologyImplements industry leading practices around cyber risks and Cloud security and perform security assessments of cloud platforms/environments using industry standard frameworks such as ISO, CSA-CSM and NISTDesigns and develops security policies, standards and procedures e.g. firewall management, SSL/IPSec, security incident and event management (SIEM), data protection (DLP, encryption), user account management (SSO, SAML), and password/key management.Identifies software weaknesses that could lead to exploitable vulnerabilities such as SQL injection, cross-site scripting, cross-site request forgery, buffer overflows, use of hard-coded passwords, weak encryption, sensitive data.Seasoned professional with detailed technical knowledge of techniques, standards and state-of the art capabilities for authentication and authorization, applied cryptography, security vulnerabilities and remediation.Can advise on architecture decisions at technical and product level.Adequate knowledge of web related technologies (Web applications, Web Services and Service Oriented Architectures) and of network/web related protocols.Experience designing the secure deployment and monitoring of applications and infrastructure into public cloud services (e.g., AWS or Microsoft Azure).Constantly looking for better ways of solving security problems and designing the solution, not afraid of challenging the status quo.Support various systems and become SME for themRespond swiftly to all alerts; performing initial risk/impact assessments or escalating issues as appropriateFollow change management controls and guidelinesSupport operating organizations during corporate emergencies.Participate in the Company's emergency management processes, cyber security and storm plansPerform other related tasks and assignments as required.Required Qualifications:3-5 years thorough understanding of communication protocols and security standards.Must be comfortable and skilled at driving information security processes and techniques.Must be able to communicate designs and give persuasive presentations. Must be able to interact with all levels of management and communicate technical concepts to a non-technical audience.Ability to handle multiple assignments with changing priorities while meeting deadlines.Must be flexible and able to work as required to support deployments, resolve production problems or respond to corporate emergencies.3-5 years of strong understanding of cyber security principles.3-5 years of experience designing, developing, implementing secure architectures and/or processes.Experience with implementing or integrating commercially available infrastructure components.Experience in evaluating technology and establishing standard designs.Must be experienced with Splunk and PhantomSplunk related experience: Requires a broad foundation of IT architectural experience with an understanding of current PaaS and SaaS technologies.Experience with scripting languages such as PythonExperience with Bulk deployments.Experience with AV and EDR.Experience in Threat Hunting and Threat and Vulnerability managementRequired Skills:Ability to establish medium and long-term plans and priorities and estimate investment requirements.Familiarity with Internet facing technologies, server/storage technologies, cloud services and hybrid cloud integration is a must.Must be conversant in emerging technologies and practices such as cloud computingAbility to work with various different methods of getting data in such as syslog, API, log filesAbility to create custom extractions, regex, log parsingAbility to setup Splunk Environments such as heavy forwarders, splunk connect 4 syslog, indexers, deployment servers, and search headsAbility to modify Splunk Configuration FilesPreferred Qualifications:Technical certifications (e.g. AWS Certified Solutions Architect, Cloud Certified Professional, Microsoft Cloud Certifications, CISSP, CISM, CIPP, Splunk Certifications, etc.)Experience in Agile Development, with specific Security Architect (or similar) experience.Knowledge of security tools, Python, scripting2 years Threat ManagementNote:Hybrid from Day 1NY/NJ or nearby statesGas/Energy/Electric/Utilities industry experience