Key Responsibilities: Cloud Security Implementation: Actively implement and maintain cloud security measures, including access controls, encryption protocols, identity and access management (IAM), and network security across cloud services (Private Cloud, AWS, Azure etc.). Vulnerability Management: Perform continuous security assessments, vulnerability scans, and penetration testing to identify weaknesses in cloud-based systems and applications. Proactively address security flaws and apply patches or remediation measures. Security Monitoring & Incident Response: Monitor cloud environments for suspicious activity, unauthorized access, and potential security breaches. Respond to alerts, investigate incidents, and lead containment efforts to mitigate risks in real-time. Security Automation: Develop and deploy automated security processes (such as security configuration monitoring, auto-scaling security policies, and vulnerability patching) to reduce manual workload and increase efficiency. Compliance Assurance: Ensure that cloud environments are compliant with healthcare-specific regulatory frameworks (e.g., HIPAA, HITRUST, SOC 2). Support security audits, track compliance statuses, and document security controls and activities. DevSecOps Integration: Work closely with the DevOps and software development teams to integrate security practices into the software development lifecycle (SDLC), including securing CI/CD pipelines, code reviews, and automated testing for vulnerabilities. Data Protection: Implement strong data protection strategies in the cloud, including data encryption, secure data storage, data masking, and secure data sharing practices, in line with the organization's privacy policies. Security Infrastructure Optimization: Collaborate with cloud architects and infrastructure teams to continuously improve the security of the organizations cloud infrastructure, ensuring that security features are both functional and efficient. Risk Management & Threat Intelligence: Leverage threat intelligence feeds and security tools to stay ahead of emerging threats. Conduct risk assessments of cloud-based systems and applications to identify and mitigate potential security risks. Security Documentation: Create and maintain comprehensive documentation of security configurations, incident reports, security protocols, and disaster recovery plans. Preferred Qualifications: Certifications: CISSP, AWS Certified Security Specialty, CompTIA Security+, CEH, or similar. Experience with vulnerability management tools (e.g., Qualys, Nessus, OpenVAS). Familiarity with container security (Docker, Kubernetes). Experience working with secure coding practices and threat modeling. Previous experience with incident response and security operations center (SOC) duties. Interested candidates can share resumes at hidden_email,
Employement Category:
Employement Type: Full time Industry: IT Services & Consulting Role Category: Not Specified Functional Area: Not Specified Role/Responsibilies: Cyber Security Engineer Job in Practicesuite