Secure Infrastructure: Design and implement security controls across colocation facilities and cloud platforms (AWS, Azure, GCP).
Policy & Governance: Develop and maintain security policies, standards, and procedures aligned with industry best practices and compliance requirements.
Vulnerability Management: Lead vulnerability assessments and remediation efforts, working cross-functionally with DevOps and infrastructure teams.
Application & Web Security: Configure and manage Web Application Firewalls (WAFs) and security rules, particularly with tools like Cloudflare and AWS WAF.
Incident Response: Participate in detection, triage, and response to security incidents, conducting root cause analysis and post-mortems.
Penetration Testing: Coordinate internal and third-party penetration testing, validate findings, and ensure timely resolution of vulnerabilities.
Security Monitoring: Enhance monitoring capabilities and investigate anomalies using SIEM tools and security analytics platforms with tools like Wazuh and Crowdstrike.
Cloudflare Management: Administer Cloudflare policies, performance configurations, and DDoS mitigation strategies.
Compliance Support: Contribute to audit readiness and compliance initiatives (e.g., SOC 2, ISO 27001, PCI-DSS).
Requirements
5-8 years of experience in cybersecurity, with hands-on experience securing hybrid infrastructure (cloud + physical datacenter).
Strong knowledge of network and application security principles.
Proficient in managing security tools and platforms like WAFs, SIEMs, vulnerability scanners (e.g., Qualys, Tenable), and Cloudflare.
Experience writing and enforcing security policies, playbooks, and procedures.
Familiarity with scripting and automation (Python, PowerShell, Bash) is a plus.
Certifications such as CISSP, GSEC, or Security+ are valued but not required.
Benefits
Full time employees will also be eligible for enrollment in a wide range of choices of benefits, including medical, dental, vision, basic life insurance, short/long term disability, 401(k) participation (with company match).
The Company provides a minimum of 10 days of vacation for new employees, sick time based on state requirements, 8 Company-paid holidays and 2 personal holidays per year.
This role will also be eligible for participation in a Company profit sharing bonus plan. Plan details will be provided to you upon hire.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
vulnerability managementpenetration testingincident responsenetwork securityapplication securityscriptingautomationsecurity policiessecurity standardsroot cause analysis