Sr. Cloud Information Security Engineer
What We Do
Today the modern enterprise is an Enterprise of Things. We are on a mission to secure the Enterprise of Things with active defense by identifying, segmenting, and enforcing compliance of every connected thing. In real time. And at scale. Our unified security platform enables enterprises and government agencies to focus on Zero Trust segmentation, IT/OT convergence and OT/ICS innovation, all supporting our mission and vision.
Join us as we secure the world with our products. We are looking for resourceful and gritty individuals to collaborate as one team while ensuring a world-class customer experience. We are cyber-obsessed about addressing the world’s most challenging security problems. Innovation starts here, everyone’s ideas are valued, visionaries welcomed!
(US Citizenship required for this role)
What You Will Do
We're looking for a Sr. Cloud Information Security Engineer who will be primarily responsible for the day-to-day cloud platform security operations on our Information Security Operations team supporting our Cloud products team. You will work close with the Information Security Operations and Compliance, Information Technology, Product Engineering, and DevOps teams. You will be the SME for securing third-party platform solution configurations in AWS, GCP, and Azure against such frameworks as NIST 800-53 and CIS Hardening guidelines. You will be responsible for configuring Web Application firewalls and ensuring changes are scoped correctly. You will act as a participant in internal security control testing for these environments and take part in threat modeling exercises. Additionally, you will also:
- Triage and respond to incidents according to the Incident Response Cycle
- Work closely with global Information Security teammates through video conference and messaging technology
- Work with various tools such as: cloud environment configuration scanners, vulnerability scanners, security incident and event managers, testing tools (like Burp Suite), and firewalls
- Compile and present monthly operational metrics
- Build process and environment docuementation
- Assist with compiling evidence for compliance audits
- Assist with assigned projects
- Be the Subject Matter Expert (SME) on assigned tools
What You Bring To Forescout
- Bachelor's degree in Information Security, Information Assurance, Computer Science, Information Technology, or similar
- A current and active Cloud and/or Information Security certification (CCSP, AWS, Security Specialty, GCP Professional Security Engineer, etc.)
- 5+ years of experience in a cloud information security role supporting a corporate information security program
- A passionate, team-focused, and indepedently driven work ethic
- In depth, hands-on knowledge and skills with AWS and GCP
- In depth knowledge and experience with cloud-based vulnerabilities and exploits, as well as remediation
- Knowledge and exposure to cybersecurity frameworks
- CI/CD pipelining and automation knowledge
- Cybersecurity incident response (Cloud experience preferred)
- Network support and architecture knowledge (On premise and cloud)
- Web application firewall configuration using Infrastructure as Code (IaC) with Cloudflare/GCP WAF preferred)
- Cloud-based threat modeling
- Ability to work with all levels of the business to obtain information related to existing controls, configurations, and processes
- Ability to communicate complex information security risks and scenarios to a general audience
- Ability to work with minimal supervision
Preferred skills
- Experience with vulnerability management tools (Rapid7, Nessus, etc.)
- Experience/exposure to security frameworks (FedRAMP and SOC2 preferred)
- Programming experience in Python, Perl, Powershell, or C#
- Information security incident triage and handling
- Ticket/case management
- Gitlab/Terraform/IAC
- Ability to create and maintain documentation
What Forescout Offers You
- Competitive compensation and benefits – we cover 80% of employee and dependents’ benefits premiums (US only), 401K match, generous PTO policy, and much more
- Collaborative and innovative environment – make an impact on worldwide security while working on the hottest technology
- Leadership that supports and encourages professional growth and development
- Want a glimpse of Life @ Forescout? Check us out on Facebook and Instagram
- Learn more at: www.forescout.com
#LI-BS2
Forescout is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.