Cloud Security Operations Engineer
2 weeks ago
Job Description:
The Cloud Security Operations Center (CSOC) is responsible for maintaining the security posture of cloud-based environments and responding to security incidents. Below are the key roles and responsibilities of a CSOC:
Threat Monitoring and DetectionMonitor Cloud Environments:
Continuously monitor cloud platforms (e.g., AWS, Azure, GCP) for potential security threats.
Identify Anomalies:
Detect unusual activity using tools like SIEM (Security Information and Event Management) systems, cloud-native monitoring tools, and AI/ML-based analytics.
Track Security Metrics:
Maintain metrics like incident frequency, time-to-detection, and compliance adherence.
Respond to Security Incidents:
Investigate, analyze, and respond to incidents like unauthorized access, data breaches, and DDoS attacks.
Root Cause Analysis:
Perform post-incident reviews to identify vulnerabilities and implement preventative measures.
Automated Responses:
Leverage automation (e.g., playbooks, SOAR tools) to speed up incident containment and remediation.
Cloud-Specific Vulnerabilities:
Regularly assess vulnerabilities in cloud assets, including virtual machines, containers, APIs, and serverless functions.
Patching and Updates:
Ensure timely application of patches and updates to mitigate risks.
Configuration Management:
Use tools to detect misconfigurations in cloud services like S3 bucket permissions, IAM policies, or firewall rules.
Ensure Regulatory Compliance:
Maintain adherence to standards like GDPR, HIPAA, PCI DSS, and cloud-specific frameworks like CSA STAR.
Audit Readiness:
Prepare for regular security audits and provide necessary documentation and evidence.
Policy Enforcement:
Implement and enforce security policies across all cloud environments.
Identify Emerging Threats:
Perform threat intelligence gathering to stay ahead of new attack vectors targeting cloud environments.
Advanced Analysis:
Use proactive techniques to discover advanced persistent threats (APTs) and insider threats.
Monitor Privileged Access:
Oversee and restrict access to sensitive resources in cloud environments.
IAM Best Practices:
Enforce strong IAM practices like least privilege, multi-factor authentication (MFA), and role-based access control (RBAC).
Key and Secret Management:
Securely manage encryption keys, API keys, and other credentials.
Encrypt Data:
Ensure encryption of data at rest and in transit in compliance with policies.
Data Loss Prevention (DLP):
Use tools to monitor and prevent unauthorized data exfiltration.
Backups:
Regularly verify that backup procedures are secure and effective.
Coordinate with Teams:
Work with IT, DevOps, and business units to align security strategies with organizational goals.
User Training:
Provide training to employees on best practices for cloud security.
Incident Reporting:
Maintain clear communication channels for reporting and resolving incidents.
Cloud-Native Security Tools:
Manage and configure tools like AWS GuardDuty, Azure Security Center, and Google Cloud Security Command Center.
Third-Party Tools:
Integrate and optimize third-party security tools for enhanced visibility and threat detection.
Automation:
Leverage automation to streamline processes like log analysis and threat mitigation.
Security Posture Reviews:
Regularly assess the security architecture and identify areas for improvement.
Stay Updated:
Keep up with the latest cloud security trends, technologies, and threats.
Simulated Attacks:
Conduct penetration testing and red team/blue team exercises to evaluate and strengthen defenses.
Job Qualifications:
ducational Qualifications:Degree:
Cybersecurity
- Information Technology
- Computer Science
Other related technical fields.
Bachelor's Degree in:
Equivalent experience may suffice in lieu of formal education.
Certifications:
Certified Cloud Security Professional (CCSP)
- AWS Certified Security – Specialty
- Microsoft Certified: Security, Compliance, and Identity Fundamentals
- Google Professional Cloud Security Engineer
- CompTIA Security+
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Ethical Hacker (CEH)
- GIAC Certified Incident Handler (GCIH)
GIAC Certified Intrusion Analyst (GCIA)
Cloud Security:
- General Security:
- SOC-Specific:
Cloud Security Knowledge:
- Expertise in cloud security tools and practices (AWS IAM, Azure Security Center, Google Cloud Security Command Center).
- Understanding of cloud compliance frameworks (e.g., SOC 2, ISO 27001, GDPR, NIST, HIPAA).
Monitoring and Threat Detection:
Splunk, QRadar, Elastic SIEM, or Azure Sentinel.
Proficiency with SIEM (Security Information and Event Management) tools:
- Experience with threat detection systems, IDS/IPS (e.g., Snort, Suricata).
Incident Response:
- Knowledge of incident response processes and workflows.
- Familiarity with playbook development and SOAR (Security Orchestration, Automation, and Response) tools.
Cloud Platforms:
- AWS: Security Hub, GuardDuty, CloudTrail
- Azure: Defender, Sentinel, Key Vault
Google Cloud: Security Command Center, Chronicle
Strong familiarity with at least one major cloud provider:
- Hands-on experience in managing and securing multi-cloud or hybrid environments.
Vulnerability Management:
- Ability to assess vulnerabilities and implement fixes.
- Knowledge of tools like Nessus, Qualys, or Rapid7.
Automation and Scripting:
Python, PowerShell, or Bash.
Proficiency in scripting languages for automating tasks:
- Experience with Infrastructure-as-Code (IaC) tools (e.g., Terraform, CloudFormation).
Networking and Firewalls:
- Strong understanding of TCP/IP, DNS, and VPN technologies.
- Experience with cloud-native firewalls and network security tools.
Endpoint Security:
- Managing endpoint security tools (e.g., CrowdStrike, Carbon Black).
- Knowledge of EDR (Endpoint Detection and Response) solutions
- Analytical Thinking: Ability to analyze logs and patterns to detect potential security breaches.
- Communication: Skills to articulate findings to stakeholders and collaborate with cross-functional teams.
- Problem-Solving: Quick response to security incidents with effective solutions.
- Attention to Detail: Essential for identifying subtle security threats.
- Teamwork: Ability to work with other security professionals and operational teams
- Entry-level: Some positions may accept candidates with 1-2 years of experience if they hold relevant certifications and demonstrate strong technical aptitude.
Job-Specific Expectations:
- Monitoring cloud environments for security events and anomalies.
- Investigating and responding to cloud security incidents.
- Implementing cloud-native security tools and practices.
- Collaborating with DevOps and IT teams to improve security posture.
- Ensuring compliance with security and privacy regulations.
- Familiarity with zero-trust architecture principles.
- Hands-on experience with DevSecOps pipelines.
- Knowledge of advanced persistent threats (APTs) and threat hunting.
- Familiarity with encryption and cryptography in cloud environments.
- Know how to drive manual cars
- Works 24/7 including holidays and weekend
- On call as needed
- Willing to extend working hours
-
Cloud Network Operations Engineer
2 weeks ago
Pasig, National Capital Region, Philippines Converge ICT Solutions Inc. Full timeJob Description:Cloud Network Operations Monitoring is critical for maintaining the health, performance, and security of cloud-based network infrastructure. Here are the key roles and responsibilities associated with this function:Network Performance MonitoringReal-Time Monitoring: Continuously track network performance metrics, including latency,...
-
IT Cloud Engineer Associate
3 days ago
Pasig, National Capital Region, Philippines Inchcape Full timeAre you looking to accelerate your career path in a stimulating, fast-growing business? At Inchcape, we're pursuing an exciting strategy to evolve our global business and lead our industry's transformation.Join Inchcape Digital, part of Inchcape global network. You'll explore and develop cutting-edge technology and data solutions that are driving our...
-
Security Engineer
2 weeks ago
Pasig, National Capital Region, Philippines Azeus Systems Limited Full timeResponsibilities Involve in Red Team activities:Perform penetration testing of Web and Mobile (iOS, Android, Windows and Mac) applicationsOwn the vulnerability management lifecycle from identification, remediation to reportingActive monitoring and detection of operational security risks in the organizationConduct technical investigations on security...
-
Security Engineer
2 weeks ago
Pasig, National Capital Region, Philippines Azeus Systems Limited Full timeResponsibilitiesInvolve in Red Team activities:Perform penetration testing of Web and Mobile (iOS, Android, Windows and Mac) applicationsOwn the vulnerability management lifecycle from identification, remediation to reportingActive monitoring and detection of operational security risks in the organizationConduct technical investigations on security incidents...
-
Cloud Data Center Operations Team Leader
2 weeks ago
Pasig, National Capital Region, Philippines Converge ICT Solutions Inc. Full timeJob Description: Cloud Data Center Operations encompass the management and maintenance of data center infrastructure in cloud environments. Here are the key roles and responsibilities typically associated with this area:Infrastructure ManagementDeployment and Configuration: Setting up and configuring physical and virtual servers, storage, and network...
-
System Engineer, Cloud
1 week ago
Pasig, National Capital Region, Philippines GRUNDFOS Full timeWould you like to be a part of Grundfos digital transformation?Help shape our cloud adoption capabilities to bring our intelligent pump solutions and customer services to new levels - improving customer experiences around the world, saving energy and millions of liters of water.Your main responsibilities:You will join our Continuous Delivery Excellence team...
-
Senior Officer, Security Engineering
5 days ago
Pasig, National Capital Region, Philippines PDAX Full timeAbout PDAXAt PDAX, we believe that the future of money is digital, and our mission is to empower all Filipinos to grow their wealth through blockchain technology.As one of the first crypto firms in the Philippine market, we feel a sense of duty to our users and to the ecosystem to set the standard for safety, ease of access, and reliability. We expect our...
-
Associate, Security Engineering
5 days ago
Pasig, National Capital Region, Philippines PDAX Full timeAbout PDAXAt PDAX, we believe that the future of money is digital, and our mission is to empower all Filipinos to grow their wealth through blockchain technology.As one of the first crypto firms in the Philippine market, we feel a sense of duty to our users and to the ecosystem to set the standard for safety, ease of access, and reliability. We expect our...
-
it cloud enginner professional
5 days ago
Pasig, National Capital Region, Philippines Inchcape Full timeAre you looking to accelerate your career path in a stimulating, fast-growing business? At Inchcape, we're pursuing an exciting strategy to evolve our global business and lead our industry's transformation.Join Inchcape Digital, part of Inchcape global network. You'll explore and develop cutting-edge technology and data solutions that are driving our...
-
Senior Security Analyst
5 days ago
Pasig, National Capital Region, Philippines Converge ICT Solutions Inc. Full timeJob DescriptionSeeking a highly skilled Senior Security Analyst to serve as our technical cornerstone for offensive security, application security, and vulnerability management. In this senior, hands-on role, you will lead our most complex technical assessments, shape our testing strategy, and build custom tools to solve unique security challenges. While...