Cloud Security Engineer
Overview
In this Cloud Security Engineer role, you will hunt for adversaries and secure cloud environments through proactive threat hunting, tooling automation, and data-driven investigations. You’ll contribute to threat intelligence and collaborate across teams to mature defensive TTPs while solving complex security challenges at scale. The position emphasizes building analytics and automation capabilities to protect customers and support incident response. You will work with cross-functional teams to advance security detection and prevention in a cloud-centric setting.
ResponsibilitiesPlan and execute proactive adversary hunts using log sources, network- and host-based tools, and threat intelligenceContribute to threat intelligence sharing forums and curate intelligence to understand adversaries and campaignsInvestigate suspected compromised assets and cloud services; analyze logs to determine what occurred and report findingsIdentify fraud and abuse; develop data analysis and response tooling at scale to protect customersTransform and curate data to support advanced analytics and automation of investigationsDesign, develop, and deliver tooling to assist the investigative and hunting process, with documentationCollaborate with internal and external teams to mature threat hunting techniques, TTPs, and partnershipsApply SDLC, large-scale computing, anomaly detection, SOC detection, SIEM, IT operations, and incident response concepts
Key requirementsExperience in cyber security, threat analytics, and incident responseProficiency with large data sets and data analysis or data science toolingHands-on with SQL, KQL, Azure Data Explorer, Azure Data Lake, AML, Jupyter Notebooks, Spark, Azure Synapse, R, U-SQL, Python, ELK Stack, or SplunkEffective communication with management and technical stakeholdersAbility to work in ambiguous situations and adapt to changeCollaborative mindset and cross-functional teamworkProficiency in threat hunting, digital forensics, and threat intelligenceAutomation skills using PowerShell, Python, and Azure-based toolsExperience with cloud security, SDLC, SOC SIEM, and incident response