Job Closed
This listing is no longer active.
Best-in-class fulfillment solution for ecommerce brands.
Security Engineer II – Cloud Security
Location
India
Posted
136 days ago
Salary
0
Seniority
Senior
Job Description
Security Engineer II – Cloud Security
ShipBob, Inc.
• Monitor security alerts, investigate incidents, and escalate as needed across security tools. • Support SIEM and detection (Sentinel, Defender XDR), tuning alerts and improve detections. • Assist vulnerability management program by working with IT/Engineering and other app developers by providing security expertise, tracking remediation and ensuring SLA compliance. • Help manage identity security including conditional access, PIM, MFA, RBAC, risky sign-ins, and access reviews. • Maintain security documentation and collect evidence. • Develop and automate security workflows, playbooks, and tools to improve the efficiency and effectiveness of security operations. • Develop, enforce, and update security policies, procedures, and guidelines for access control, threat detection, and compliance with standards such as ISO 27001, SOC 2, PCI, NIST CSF, and Sarbanes-Oxley. • Communicate risks and vulnerabilities to stakeholders, document remediation plans, and proactively share information with management. • Build and execute regular threat hunting campaigns focused on current, emerging, and obscure tactics, techniques, and procedures. • Proactively search for, identify, and analyze new and existing techniques to detect advanced and targeted threats. • Utilize advanced threat hunting techniques to detect anomalies and suspicious activities. • Collaborate with security team members, developers, operations, and stakeholders to share knowledge and best practices. • Identify process improvements and provide actionable guidance. • Perform other duties as assigned.
Job Requirements
- 4+ years of hands-on work experience with security architecture and engineering in a cybersecurity operations program.
- 2+ years of experience in incident response, detection, threat intelligence, or access control security engineering roles.
- Excellent knowledge and experience with access control frameworks and tools (IAM, RBAC, ABAC, OAuth, SAML), cloud security, network security, endpoint security, and threat intelligence.
- In-depth knowledge of Azure services (especially Azure Active Directory, Azure AD Identity Protection, Azure RBAC), and experience securing cloud-based infrastructures (Azure, M365, Google Workspace, Salesforce).
- Proficiency in scripting languages such as Python, PowerShell, Go, or Bash.
- Strong knowledge of industry-standard frameworks (MITRE ATT&CK, ISO 27001, SOC 2, NIST CSF, PCI, SOX, GDPR).
- Proven ability to manage multiple risk and compliance projects.
- Strong written and verbal communication; effective collaborator with outstanding interpersonal skills.
- Excellent analytical and problem-solving skills supporting business objectives.
- Detail-oriented, organized, and able to balance precision with big-picture thinking.
- Quick learner who proactively drives personal and professional growth.
- Demonstrated initiative and ownership in problem-solving.
- Strong design and solution implementation skills for Zero Trust Architecture.
- Desire to solve response challenges with automation.
- Security+, CISSP, CISA, CISM, CRISC, GCIA, GCIH, GREM, or similar certifications preferred; equivalent experience accepted.
Benefits
- Medical, Term & Accidental Insurance
- All Purpose Leave (casual & sick time): 12 days
- Earned Leave: 15 days
- Public Holiday: 12 days
- Generous Maternity & Paternity Leave
- Quarterly Wellness Day
- Work From Home Allowance
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Lead North America sales team (6+ team members) to drive territory growth; execute, refine & improve go-to-market strategy. • Define clear priorities and actions for achieving sales targets. • Own Security vertical: generate demand, manage projects, and grow product sales. • Build toward long term, sustainable growth. • Promote brand through customer visits, integrator engagement, and industry events. • Plan travel for maximum ROI and maintain strong reseller network through evaluation, training, and accountability. • Deliver accurate forecasts, manage pipeline, and ensure consistent follow-up. • Mentor team on value-based solution selling and support professional growth. • Collaborate with business development and marketing teams.
• Develops and manages security for more than one IT functional area (e.g., data, systems, network and/or Web) across the enterprise. • Lead ensuring Cloud Security Firewall requests, Gitlab merge requests, GCP group access requests, and DaVita Temporary Privilege Escalation Tool requests are tracked, worked, and addressed. • Develop and publish Information Security policies, procedures, standards and guidelines based on knowledge of best practices and compliance requirements. • Prepares status reports on security matters to develop security risk analysis scenarios and response procedures. • Provide weekly, bi-weekly and monthly status updates on various cloud security projects including Wiz vulnerability and misconfiguration management, the Cloud Governance effort of implementing security checks in the CI/CD pipeline, as well as log ingestion and custom alerting in Cysiv. • Responsible for the tracking and monitoring of IT security incidents through remediation. • Jira ticket tracking and communicating with other teams regarding security issues through remediation. • Develop technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks. • Enforces security policies and procedures by administering and monitoring security profiles, reviews security violation reports and investigates possible security exceptions, updates, and maintains and documents security controls. • Review policies and create custom controls in our CSPM to cover a variety of security frameworks. • Document Cloud Security practices & procedures in Confluence and Administer the Cloud Security DevOps Jira project. • Provide direct support to the business and IT staff for security related issues. • Serves as a cloud security point of contact for other teams. Represents the security needs of the organization by providing expertise and assistance in all IT projects with regard to security issues.
• Leads and coordinates complex security initiatives, overseeing strategy, implementation, and operations to protect digital assets from threats. • Ensures compliance, conducts training, and develops incident response plans for various platforms. • Works with the IT department to ensure that systems and networks are designed, developed, deployed, and managed with strong security and risk management controls. • Manages the vulnerability management program, annual cybersecurity assessments, and penetration tests. • Researches and reports on emerging threats and helps the organization with risk mitigation. • Analyzes security events to proactively detect threats and mitigate attacks before they occur.
Cyber Cloud Security Lead – Integrated Cloud Consulting
RSM US LLPExperience the power of being understood.
• leading a global team of cloud security specialists, developing go-to-market solutions, working with industry leading cloud providers and technology vendors • identifying, pursuing and closing new opportunities with both existing and new clients • providing subject matter knowledge to support the efforts of the broader consulting practice • leading multiple team engagements simultaneously, including several threads of complex implementation and migration engagements • acting as a subject matter specialist for cloud security including, but not limited to identity and access management, network security, data encryption (in motion/at rest), API gateway security, infrastructure hardening and security, change management and change control, insider threat, monitoring/alerting • providing leading practices in cloud security operations, incident response, business resiliency




