Cyber Security Specialist - W2 Only
Saransh Inc · Phoenix, AZ · 2 wk ago
On-siteEngineeringContract
Responsibilities
- Conduct security reviews of OCI services, SaaS applications, architectures, integrations, and configurations.
- Identify security risks, control gaps, and remediation opportunities.
- Evaluate solutions against enterprise security standards, policies, and regulatory requirements.
- Provide security guidance for secure deployment and adoption of cloud and SaaS services.
- Map OCI and SaaS implementations to enterprise controls and industry frameworks (NIST, ISO 27001, CSA CCM, CIS).
- Validate compliance with secure configuration baselines and reference architectures.
- Support development and maintenance of OCI and SaaS security standards, guardrails, and onboarding requirements.
- Assess new cloud and SaaS capabilities and provide security recommendations.
- Implement OCI-native security controls and governance capabilities.
- Aid in the development of security automation through Infrastructure-as-Code (Terraform) and policy-as-code frameworks.
- Support deployment and integration of security monitoring, posture management, and compliance capabilities.
- Partner with platform engineering teams to embed security into deployment and operational processes.
- Perform SaaS onboarding assessments and certification reviews.
- Evaluate SaaS architectures, integrations, data flows, and security controls.
- Conduct SaaS posture reviews and assess configuration drift, identity governance, and data protection controls.
- Support SaaS inventory management, Shadow IT discovery, and vendor security assessments.
- Collaborate with cloud engineering, architecture, DevOps, security operations, compliance, procurement, and risk teams.
- Document findings, recommendations, and evidence to support governance and certification decisions.
- Provide security expertise during design reviews, onboarding activities, exception management, and remediation efforts.
Qualifications & Skills Required
- Proven experience performing cloud security assessments within OCI or comparable cloud platforms.
- Experience conducting SaaS security reviews and certifications.
- Strong understanding of: Identity & Access Management, Network Security, Data Protection, Cloud Logging & Monitoring, Container & Platform Security, Tooling & Frameworks (OCI security services, SSPM platforms, CASB technologies, cloud governance frameworks), Infrastructure as Code (reviewing Infrastructure-as-Code (Terraform) and cloud architecture designs).
- Strong comprehension of cloud shared responsibility models and secure-by-design principles.
- Experience with Policy-as-Code, automated compliance tooling, GitHub, CI/CD pipelines, and cloud security automation.
- Experience supporting AI/GenAI security assessments.