Job Closed

This listing is no longer active.

Elyon International logo
Elyon International

ELYON International, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Location Portland, Oregon (Remote) Employment Type Contractor Minimum Experience Experienced

Cloud Security Threat Modeler

Security EngineerSecurity EngineerOtherRemoteMid LevelTeam 201-500

Location

United States

Posted

81 days ago

Salary

0

Seniority

Mid Level

No structured requirement data.

Job Description

Cloud Security Threat Modeler

Elyon International

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Engineer and standardize reusable security patterns for Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). This role provides approved patterns for services, allowing application teams to utilize pre-approved service and API patterns without requiring them to threat model cloud services when developing application threat models. Primary Responsibilities - Backlog Execution: Conduct deep-dive threat model reviews for an immediate backlog of 22 cloud services. - Pattern Engineering: Develop modular, "Lego-brick" threat models for cloud services and API patterns, defining mandatory security controls and standardized use cases. - Stakeholder Defense: Schedule threat model reviews (TMRs) for cloud services. Present and defend service threat models in formal threat model reviews (TMRs) with the Boeing Enterprise Security (BES) to defend and secure approval for standardized patterns. - Additional Reviews: For services that require changes to environment perimeters, coordinate with landing zone architects to update landing zone architecture standards, schedule reviews, and review changes with the Secure Perimeter Review Board (SPRB) reviews. - Technical Research: Perform manual analysis using TrustOnCloud research libraries to identify Cloud Service Provider (CSP) specific threats and configuration requirements. Work with CSP subject matter experts to develop service threat models when necessary. Secondary Responsibilities - Library Stewardship: Manage repository of approximately 200 service and API threat models. - Governance & Maintenance: Execute a manual biennial (2-year) refresh cycle for all models in the library to ensure continued alignment with CSP updates and feature releases. Key Performance Indicators (KPIs) - Throughput: Following a 1-month ramp-up and shadowing/training period, complete a minimum of 3 service threat model reviews per month. - Backlog Resolution: Clear the initial 22-service backlog within approximately 8 months of the completion of the training period. - Maintenance Compliance: Maintain 100% adherence to the biennial manual refresh schedule for the 200-pattern library. Qualifications - Experience: 5+ years in cloud security architecture or threat modeling. - Technical Depth: Expert knowledge of AWS, Azure, and GCP managed services and the Shared Responsibility Model. - Analytical Skill: Proven ability to synthesize complex technical data (e.g., TrustOnCloud reports) into concise, executable security standards. - Communication: Ability to negotiate and defend technical security positions to central risk and compliance stakeholders. Preferred Experience - Direct experience using TrustOnCloud for threat research. - Background in creating reusable security patterns in large-scale enterprise environments. Benefits - Paid sick leave - Medical/Dental (optional) - 401 (k) Retirement Plan (optional) - Employer Paid Life Insurance - Employer Paid Short Term Disability - Optional Life Insurance Company Description ELYON International, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Location Seattle, Washington (Remote) Employment Type Contractor Minimum Experience Experienced

Job Requirements

  • Experience: 5+ years in cloud security architecture or threat modeling.
  • Technical Depth: Expert knowledge of AWS, Azure, and GCP managed services and the Shared Responsibility Model.
  • Analytical Skill: Proven ability to synthesize complex technical data (e.g., TrustOnCloud reports) into concise, executable security standards.
  • Communication: Ability to negotiate and defend technical security positions to central risk and compliance stakeholders.
  • Preferred Experience
  • Direct experience using TrustOnCloud for threat research.
  • Background in creating reusable security patterns in large-scale enterprise environments.

Benefits

  • Paid sick leave
  • Medical/Dental (optional)
  • 401 (k) Retirement Plan (optional)
  • Employer Paid Life Insurance
  • Employer Paid Short Term Disability
  • Optional Life Insurance

Related Categories

Related Job Pages

More Security Engineer Jobs

OtherRemoteTeam 51-200Since 2022H1B No Sponsor

• Assist with updating existing documentation based on input from product stakeholders. This will include using the Jira ticketing system to track progress and capture changes. • Assist with updating product release notes based on input from product management and other stakeholders. • Assist with reviewing and editing work from other writers and contributors. • Translate complex information into clear, user-friendly documentation.

United States
Job Closed
OtherRemoteTeam 501-1,000Since 2015H1B No Sponsor

• Serve as the product security lead and ISSM for operational autonomous aircraft platforms. • Own and guide RMF activities, including ATO packages, ongoing authorization, and customer security engagements • Translate security and compliance requirements into product-appropriate, technically sound controls • Partner closely with systems, software, hardware, and platform engineering teams throughout the product lifecycle • Evaluate the security impact and operational tradeoffs of design decisions • Support government and customer audits, assessments, and security reviews • Contribute to the maturation of product security and compliance practices across Shield AI

Texas
$138K - $207K / year
Job Closed

Senior Cybersecurity Engineer, Secret Clearance

Rise8

Rise8 is a digital transformation company focused on helping government agencies move quicker and more efficiently by designing and delivering resilient, secure

• Secure cloud-based environments by designing and implementing native security solutions using services. • Drive Continuous RMF practices, automating control implementation and reporting through modern methodologies like Continuous Authorization to Operate. • Automate provisioning and configuration of IT environments • Implement and manage security measures like firewalls, IDS/IPS, vulnerability scanning, encryption, and ICAM solutions. • Secure containerized and large-scale cloud production systems while responding effectively to security incidents. • Apply advanced security concepts to protect systems, including threats, vulnerabilities, encryption, boundary defense, and risk management. • Establish and manage identity and access management policies, ensuring least-privilege access and cross-account role adherence. • Create and maintain engineering artifacts, such as network diagrams, data flow diagrams, installation procedures, and operational manuals. • Enforce cloud-native security best practices, leveraging frameworks like AWS’s Well-Architected Security Pillar • Collaborate with cross-functional teams to integrate Zero Trust principles into the broader security posture, aligning with DoD policies such as the Risk Management Framework (RMF) • Apply and operationalize RMF, FedRAMP, and DISA CC SRG controls, ensuring compliance with DoD Impact Levels. • Collaborate with cross-functional teams to integrate lean and agile practices into secure development lifecycles. • Contribute to the continuous improvement of DevSecOps practices, ensuring systems are secure, scalable, and compliant. • Work in a dynamic, collaborative environment that supports your professional development.

United States
$163.1K - $203.9K / year
Texas Health Resources logo

Consumer Identity & Access Management (CIAM) Engineer II

Texas Health Resources

Located in Arlington Texas, Texas Health Resources is a nonprofit, faith-based healthcare provider that has been providing a wide range of healthcare services to the communities th

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description CIAM Engineer II – Consumer Salesforce Bring your passion to Texas Health so we are Better + Together Work location: Texas Health Resources, Remote – Must reside in Texas or be willing to relocate. Required to attend in-person meetings at corporate office in Arlington. Work hours: Full Time Days Monday through Friday 8:00am – 5:00pm for 40 hours per week. Consumer Salesforce highlights: - Innovative, collaborative, and fast-paced environment - Opportunities to learn and advance in roles - Supportive and transparent leadership - Work from home life balance - Inclusive and supportive team attitude Qualifications - Bachelor's Degree in Computer Science, Information Technology, Business Administration; 4 Years relevant work experience in lieu of a degree (Required) - 3 Years Identity and Access Management technologies; to include 1 year in CIAM administration (Required) Requirements - Accountable to ensure implementations are properly promoted to production environment. - Accountable for the upgrades and processes to ensure high reliability implementation of such upgrades. - Accountable to comply with all THR Security tasks for the platform. - Accountable to prioritize all work appropriately to maintain operational effectiveness and efficiency. - Be available as needed, to support after-hours incidents, problems, outages, etc. that affect the CIAM platform. - Responsible for other applications as assigned. - Integration testing for development and releases. Benefits - Benefits include 401k, PTO, medical, dental, Paid Parental Leave, flex spending, tuition reimbursement, student loan forgiveness as well as several other benefits. - Delivery of high quality of patient care through nursing education, nursing research and innovations in nursing practice. - Strong Unit Based Council (UBC). - A supportive, team environment with outstanding opportunities for growth. Company Description Learn more about our culture, benefits, and recent awards. Do you still have questions or concerns? Feel free to email your questions to recruitment@texashealth.org.

United States
Job Closed