Source description
About the role
Cloud Security Admin - Geneva
WIPO is seeking an experienced Cloud Security Administrator / Security Specialist, to be responsible for establishing, enhancing cloud security standard operating procedures, implementing and administering security services and mechanisms in the cloud. The incumbent will closely work with the Senior Security Architect, Security Engineer, Solution Architecture and other relevant stakeholders to ensure that the security controls defined in the security architecture and subsequent designs are implemented accordingly. The key objective for this role will be the efficient, automated, orchestrated management and optimization of the technical cloud security control environment to enable deterrence, prevention, detection, containment of threat and the rapid business recovery in case of risk crystallization. This role will require the handling of sensitive or highly confidential data. Active or prior government security clearance is preferred.
Duties and Responsibilities
The incumbent will be expected to perform the following principal duties:
a. Operating procedures: Work with the Security Engineer to develop standard operating procedure for cloud security administration.
b. Information Protection & Data Security administration: Configure and administer Information protection, data security mechanisms and services such as classification tools, data leakage prevention, data-at-rest, data-in-transit and data processing encryption, secure deletion and secure cloud migration tools.
c. Identity and access management Administration: work with the Senior Security Architect, the Security Engineer and the IAM Specialist to implement manage the IAM Model, Roles and IAM Policies that enforce separation of duty, the least privilege principle and need-to-know
d. Application Security administration: configured and administer application security mechanisms and services such Web Application Firewall (WAF), API Gateways and Content Delivery Network.
e. DDOS protection & Response administration: configure and administer centralized DDOS Protection services and mechanisms
f. Network Security: leverage central mechanisms, manage programmatic Cloud firewall management tools to performance rule optimization across multiple cloud accounts, and administer different policies.
g. Perform the administration of the Security/logging account in the cloud.
h. Administration of endpoint security and security operation support: Work with the iSOC Manager to support the configuration and administration of the following:
Central administration of Security Hardening & Golden AMI configuration.
Central administration and Deployment of Next Generation EDR and Next Generation AV agent on cloud workload.
Central administration of configuration of Container Security mechanisms.
Work with the Information Security Operation Center for the configuration and execution of vulnerability assessments or posture analysis services or mechanisms.
Work with the central teams and stakeholders such as application development teams, the Information Security team and infrastructure team to ensure security mechanisms that are part of CI-CD pipeline are configured, administered and managed accordingly when it comes to cloud workloads.
Centralized configuration and administration of the container security solution
Implementation and administration of centralized Cloud Threat Detection services and mechanisms
i. Level II Support: Provide level II support for cloud related incident and problem management involving specific Cloud security mechanisms
j. Perform any other duties as assigned.
Education
Essential
Advanced university degree in information security, computer science, engineering, mathematics, business or related discipline. A first-level university degree in a relevant discipline plus two years of relevant experience in addition to the experience requested below may be accepted in lieu of an advanced degree.
Certification:
CISSP and/or CCSP Certification.
AWS Certified SysOps Administrator and/or AWS Certified Security Specialist.
Additional certifications such as AWS Certified Solution Architect Associate, CCNP-Security, JNCP, MCITP, RHCSS, CEH, ITIL Certified Foundation.
Successful completion of the SANS SEC545 course - Cloud Security Architecture and Operations
Job Related Competencies
Familiarity with a broad range of technologies supplemented by in-depth knowledge in specific areas of relevance. In particular, cloud security administration technologies, data security administration, identity and access management, key management and encryption, application and network security.
Excellent analytical skills and attention to detail.
Excellent interpersonal skills with the ability to establish and maintain effective partnerships and working relations in a multi-cultural environment with sensitivity and respect for diversity.
Knowledge and/or skills in the following areas: i) development of Cloud security administration standard operating procedures, ii) Information protection & Data Security administration: AWS Macie, AWS KMS and AWS Encryption,S3,RDS,EFS Security iii) Identity and access Management: IAM role lifecycle management, AWS Policies, AWS Service control policies (SCP), AWS Cognito, Cross account access, Boundary policies, Identity federation, SSO, Multiple factor authentication (MFA), Secure programmatic access. iv) Application security: AWS WAF, AWS API Gateway configuration, AWS Inspector, CFN-NAG, AWS Cloud Front. v) DDOS Protection & response administration: AWS Shield. vi) Network Security: NACL, Security group administration, AWS Firewall Management. Vii) Endpoint protection and security operation support: AWS Golden Pipeline, AWS Security Hub, Security logging Viii) AWS CloudFormation, advanced scripting with Python, JSON.
Crowdstrike, Juniper remote access gateways, SIEMS, Knowledge of orchestration tools such as ANSIBLE, Chef or Puppet, Terraform, Cloud Custodian. Job type: Permanent Division: eTeam Workforce Limited Reference: 19-01152
More at eTeam