Lumen Technologies logo
Lumen Technologies

Lumen Technologies is self-described as a global company of 40,000+ professionals empowering businesses, government, and communities to “produce amazing things.” Driven by the

Cloud Security and Vulnerability Management Consultant

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 10,001

Location

United States

Posted

1 day ago

Salary

$67.7K - $99.3K / year

Seniority

Mid Level

Job Description

Cloud Security and Vulnerability Management Consultant

Lumen Technologies

Role Description Lumen Security Advisory Services is hiring a Cloud Security & Vulnerability Management consultant to join a team that delivers customer-facing security assessments and vulnerability management engagements across cloud environments and customer premises. The primary focus is cloud security posture assessment, where the team evaluates customer environments against industry compliance frameworks, identifies vulnerabilities and misconfigurations, and helps customers understand their security posture and build practical remediation strategies. A secondary focus is vulnerability management, where the team deploys and manages scanning platforms in customer environments, configures and tunes the platform alongside customers, develops patching strategies aligned to customer needs, and guides remediation prioritization and planning. This is a hands-on consulting role on a small, fast-moving team. You'll work directly with customers, run assessments using commercial and custom-built tooling, and contribute improvements to shared platforms and codebases. Main Responsibilities - Cloud Security (Primary Focus) - Deliver cloud security posture assessments across AWS, Azure, and Microsoft 365 environments - Evaluate customer environments against CIS Benchmarks, cloud provider security frameworks and best practices, and customer-specific compliance standards - Use custom-developed assessment frameworks and cloud-native security tooling to identify misconfigurations and security gaps - Perform cloud resource inventory and exposure analysis - Prioritize findings by risk and develop clear remediation guidance - Vulnerability Management - Deploy and manage vulnerability scanning platforms in customer environments - Configure and tune scanning platforms alongside customers, including patching strategy development - Analyze scan results, prioritize findings by severity and business impact, and guide remediation planning - Understand vulnerability types, severity frameworks (e.g., CVSS, vendor-specific), and how to communicate risk to customers - Consulting & Delivery - Participate in customer-facing activities: kickoff calls, technical interviews, working sessions, and findings presentations - Contribute to assessment reports and remediation roadmaps for technical and executive audiences - Communicate technical risk clearly to non-technical stakeholders - Tooling & Platform Development - Contribute to a custom-built cloud security assessment platform (AWS native services) - Develop and maintain custom security checks and automated compliance scanning tools - Work with AWS and Azure cloud infrastructure components - Write and maintain scripts for assessment automation and reporting Qualifications - Hands-on experience with at least one major cloud platform (AWS preferred; Azure, M365 also valued) - Understanding of cloud security posture management (CSPM) concepts and the differences between platform-level tools (e.g., Wiz) and assessment-focused tooling - Familiarity with compliance frameworks such as CIS Benchmarks, SOC2, PCI-DSS, or NIST - Understanding of vulnerability management concepts: vulnerability types, severity scoring, remediation prioritization - Strong communicator able to explain technical findings to both engineers and executives - Comfortable writing Python and working in Git - Experience with AI-assisted development and automation tools such as GitHub Copilot, Microsoft Copilot Studio and agent building, Power Automate, and Claude - Willingness to learn new tools and platforms quickly Requirements - 3–5 years’ experience in cloud security, vulnerability management, security consulting, or a related technical security role Certifications - Relevant certifications (AWS, Azure, CISSP, or similar), however, demonstrated experience matters more Compensation This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors. - $67,703 - $90,270 in these states: AL, AR, AZ, FL, GA, IA, ID, IN, KS, KY, LA, ME, MO, MS, MT, ND, NE, NM, OH, OK, PA, SC, SD, TN, UT, VT, WI, WV, WY - $71,088 - $94,784 in these states: CO, HI, MI, MN, NC, NH, NV, OR, RI - $74,474 - $99,297 in these states: AK, CA, CT, DC, DE, IL, MA, MD, NJ, NY, TX, VA, WA Benefits - Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing.

Related Categories

Related Job Pages

More Security Engineer Jobs

Varicent logo

Security Engineer – Contract

Varicent

Industry-Leading Sales Performance Management Software for Growth Market and Enterprise Organizations.

ContractRemoteTeam 501-1,000H1B No Sponsor

• Coordinate the deployment, configuration, testing, monitoring, and ongoing maintenance of security technologies, including SIEM, EDR, DLP, WAF, CASB, Secure Web Gateway, URL filtering, email security, and application/vulnerability scanning platforms. • Lead small-to-medium-sized security initiatives from requirements gathering through design, testing, pilot execution, and implementation. • Support proof-of-concept evaluations and product assessments to ensure proposed solutions align with security strategy, standards, and industry best practices. • Act as a service or tool owner by identifying enhancements, maintaining operational runbooks, and recommending improvements for tools under your responsibility. • Develop and maintain procedures, workflows, architecture diagrams, and operational playbooks that support security monitoring and engineering activities. • Investigate and triage security events using technologies such as SIEM, EDR, DLP, WAF, CASB, Secure Web Gateway, and email security solutions. • Detect, respond to, and support investigations of security incidents while documenting root-cause analysis and lessons learned. • Follow established incident response procedures and playbooks, escalating critical findings appropriately and efficiently. • Apply analytical and adversarial thinking to identify, protect, detect, respond to, and recover from common cyber threats and attack vectors. • Perform and support secure baseline reviews, infrastructure scanning, endpoint scanning, application vulnerability assessments, penetration testing validation, and AI red-teaming exercises. • Review vulnerability findings for accuracy and completeness while partnering with stakeholders to prioritize remediation efforts based on risk. • Escalate critical vulnerabilities, zero-day threats, and high-priority risks while supporting rapid mitigation efforts. • Contribute to continuous improvements in vulnerability management workflows through automation and the integration of security testing into CI/CD pipelines. • Conduct security risk assessments for internal initiatives, product enhancements, vendors, and productivity tools. • Perform STRIDE-based threat modeling for internal projects and AI-enabled solutions, producing actionable recommendations and clear risk reports. • Apply a risk-based approach to evaluating Agentic AI technologies and AI-related security risks. • Conduct vendor risk assessments within OneTrust and support broader third-party risk management activities. • Identify opportunities to strengthen controls, improve processes, and enhance security outcomes across teams. • Stay informed on emerging threats, technologies, and industry best practices, sharing relevant insights with colleagues and stakeholders.

Canada
$76.8K - $96K / year
Full TimeRemoteTeam 501-1,000H1B No Sponsor

Role Description Monitor our security dashboards, triage findings, and plan and implement remediation steps end to end. - Proactively shape our infrastructure architecture and configuration with security and compliance front of mind. - Implement infrastructure changes hands-on, applying DevOps practices across infrastructure-as-code, CI/CD, and cloud configuration. - Keep track of emerging threats, CVEs, and advisories, and drive timely mitigation across our systems. - Partner with engineering teams to embed security into the development lifecycle rather than bolting it on. - Help us meet and maintain compliance requirements relevant to healthcare data. Qualifications - Solid experience in a DevOps, SRE, or cloud security role, with hands-on infrastructure work. - Strong knowledge of AWS, containerized workloads (Docker, Kubernetes), and infrastructure-as-code (Terraform). - Hands-on experience with cloud security posture management tooling. - A working understanding of vulnerability management and how to prioritize and remediate threats in practice. - Familiarity with security and compliance frameworks (e.g., SOC 2, ISO 27001, GDPR; healthcare-specific frameworks a plus). - Comfortable building and maintaining CI/CD pipelines. - A proactive, ownership-driven mindset and the ability to communicate risk clearly to engineers and stakeholders. - Proven experience in collaboration with AI tools like Codex or Claude Code. - English working proficiency. Benefits - Exciting start-up atmosphere. Gone are the days in which you wait for approvals for months. - Make our disruptive product even better. Change how healthcare functions. - Work with state-of-the-art technology. No legacy code. No technological debt. All green fields. - Your workplace—your choice. Office? Great! Home? Sure! Mars? Not sure about the Internet there, but why not. - Flexible working hours. No downtime. High degree of autonomy. - The team. Collaborative. Fun. True professionals. A real team. - Remote work opportunity. Company Description We are growing and excited to meet you to join us on our mission. Let's revolutionize health care together!

Worldwide
TTEC logo

Cloud Security Manager

TTEC

Customer experience obsessed. Powered by people + technology.

Full TimeRemoteTeam 10,001+Since 1984H1B Sponsor

Role Description You will lead and oversee the organization’s Cloud Security team, enforcing the security architecture, policies, and controls that safeguard our organization’s cloud platforms. This role blends technical depth, leadership, and strategic planning to protect cloud workloads from evolving threats and contributes to strategic security decisions. During a Typical Day, You’ll: - Direct and manage the Cloud Security team, ensuring effective staffing, training, and operational efficiency. - Oversee Cloud Posture and Vulnerability Management for enterprise and client cloud environments. - Ensure continuous monitoring and finding resolution of cloud infrastructure (AWS, Azure, GCP) findings out of CSPM/CNAAP tooling. - Define, track, and report on KPIs for cloud posture and vulnerability management. - Identify, assess, and govern mitigation of cloud-related risks through continuous monitoring and threat modeling. - Ensure adherence to frameworks such as SOC2, FedRamp, ISO 27001, NIST, PCI DSS, and HIPAA. - Verify security controls are implemented and functioning as designed. - Manage cloud security tools (CSPM, CWPP, CNAAP) and integrate them into operational workflows. - Act as the alternate escalation point for critical security issues, making decisions to ensure business continuity. - Mentor cloud security engineers and analysts to drive a culture of security awareness. - Collaborate with cloud providers, internal teams, and external auditors. Qualifications - 10+ years of progressive technology experience, including 5+ years in a security leadership role. - Bachelor’s degree in computer science, IT, or related field. - Cloud certifications such as CCSP, AWS Security Specialty, Azure Security Engineer, or Google Professional Cloud Security Engineer. - 7+ years of experience in cybersecurity, with at least 3 years focused on cloud security. - Strong understanding of network security, encryption, IAM, and DevSecOps practices. - Hands-on experience with AWS, Azure, or GCP security services. - Proven ability to translate complex technical risks into clear, business-focused language for senior leadership. Benefits - Supportive of your career and professional development. - An inclusive culture and community-minded organization where giving back is encouraged. - A global team of curious lifelong learners guided by our company values. - Ask us about our paid time off (PTO) and wellness and healthcare benefits. - A great compensation package and performance bonus opportunities. - Benefits you'd expect and maybe a few that would pleasantly surprise you (like tuition reimbursement).

Philippines
Full TimeRemoteTeam 5,001-10,000Since 1991H1B Sponsor

• Create, manage, and respond to security incidents and conduct analysis in accordance with existing processes and company security policies • Installation, configuration, and administration of information security tools • Troubleshoot and resolve technical issues related to security tools and security processes • Coordinate with third-party vendors • Assist with internal and external audits associated with regulatory and compliance requirements • Provide formal notification to Information Security leadership when changes are planned that may impact the approved security posture of NICE CX or the associated certification and accreditation • Review and recommend improvements to information security processes • Ensure regular housekeeping activities are performed to maintain system integrity and monitoring

United Kingdom