Source description
About the role
5+ years of experience in information security, cybersecurity engineering, or a related technical discipline
3+ years of hands-on experience securing cloud environments (AWS preferred), including IAM, VPC security, security groups, and cloud-native security services (e.g., AWS GuardDuty, Security Hub, CloudTrail)
Experience with SIEM platforms and security event monitoring, alerting, and incident response workflows
Proficiency in vulnerability management tools and processes, including experience conducting or coordinating penetration testing
Solid understanding of network security concepts including firewalls, WAFs, IDS/IPS, DNS security, and zero-trust principles
Experience with identity and access management including SSO, MFA, OAuth, and privileged access management (PAM) solutions
Hands-on experience integrating security into CI/CD pipelines (DevSecOps), including static/dynamic analysis tools and secrets management
Familiarity with compliance frameworks such as SOC 2, ISO 27001, NIST CSF v2.0, PCI-DSS, and their technical implementation requirements; working knowledge of AI-specific frameworks (e.g., NIST AI RMF, ISO 42001) is a plus
Working knowledge of data privacy regulations and their operational security implications, including GDPR and CCPA
Hands-on experience implementing and managing conditional access policies, network and host-based DLP, information protection classifications, and endpoint security controls within an enterprise security platform
Scripting or automation experience (Python, Bash, or similar) for security tooling and workflow automation; comfort leveraging AI-assisted tools to enhance and accelerate security operations, analysis, and process development
Strong Linux administration skills, preferably with RHEL-based systems
Excellent analytical and problem-solving skills with the ability to assess complex risk scenarios and communicate findings clearly
Strong written and verbal communication skills, with ability to present technical security concepts to non-technical stakeholders
Experience mentoring or developing junior security team members, or demonstrated ability to contribute to team capability growth through training, knowledge transfer, or documentation
Relevant security certifications such as CISSP, CISM, OSCP, AWS Security Specialty, or equivalent are a plus
More at Kobie Marketing
