#req11088
esigning secure cloud solutions, integrating security technologies such as identity and access management, encryption, monitoring, and zero-trust models for multi-cloud and hybrid scenarios.
Implement security controls for data centers, network perimeters, cloud platforms, and virtualized environments, following industry best practices.
Conduct vulnerability management activities, including assessments, penetration testing, and remediation for both on-premises and cloud-based assets.
Monitor and respond to threats across infrastructure, network, and cloud environments, ensuring timely detection, response, and recovery.
Support compliance efforts with regional and global policies governing infrastructure, network, and cloud security, including data protection and secure access.
Provide technical guidance to infrastructure, network, and cloud teams to promote robust design, deployment, and operational security.
Engage with external partners, auditors, and regulatory authorities to help maintain security standards for Cornerstone's technology stack.
Contribute to training programs to increase awareness of infrastructure, network, and cloud security best practices across the organization.
Build and improve proactive security solutions integrating our tools and processes for active monitoring and remediation.
Assist in implementing and maintaining technical solutions for compliance frameworks such as SSAE18, FedRAMP, and ISO 27001.
Provide hands-on support for security technologies including, but not limited to: SIEM, IDS, Vulnerability Scanners, CNAPP, and ASPM.
Requirements:
Bachelor's degree in an Information Technology related field or equivalent work experience
5+ years of experience in system, network, and/or cloud security
Experience with network security systems (firewalls, cloud native controls like security groups) and reviewing/validating their configurations.
Experience supporting security for SaaS or PaaS solutions, preferably in AWS (GCP and Azure experience a plus)
Ability to create solutions using Python, Node.JS, or Go, and Infrastructure as Code (CloudFormation)
Experience with CI/CD practices and tools (Git, Jenkins), and integrating security into CI/CD pipelines
Familiarity with major security frameworks (FedRAMP, NIST 800-53, ISO 27001, SOC2 Type 2)
Self-motivated and able to work independently
Strong multitasking and learning skills
Demonstrated problem solving and analytical abilities; strong oral and written communication skills to engage with the global Cornerstone team
Preferredqualifications:
IT security certifications (CISSP, AWS Security, CISM, GPEN/GWAPT, etc.)
Experience designing and implementing security controls in cloud-first environments
Familiarity and experience with CI/CD processes and security controls
Experience implementing security controls in microservices cloud environments