Senior Cyber Cloud Security Engineer
About the role
The Senior Cloud Security Engineer will work with all NYC agencies to ensure compliance with NYC cybersecurity policies and standards, industry best-practices and data security practices; analyze the identity and access management posture to provide actionable results in collaboration with other members of the Cloud Security Team; follow-up with tasks executed by agencies and appropriate risk management strategies are undertaken; and assist the agency resources with security challenges and advise on remediation techniques.
Responsibilities
- Ensure that cloud and on-prem technologies are integrated, tested, operated, and configured to meet the objectives of NYC Cyber Command’s defensive efforts.
- Responsible for the operation of key strategic defensive technologies including cloud-based security implementation controls and responder environments, network defenses, Citywide email filtering technology, and endpoint protection.
- Provide guidance at various stages of planning and implementing security design, processes and solutions.
- Pivot between numerous technical projects and communicate status at different stakeholder levels.
- Document and report to management the execution phases and project-level solution deployment plans to leverage the NYC agencies' technology departments and executive leadership.
- Handle special projects and initiatives as assigned.
Minimum Qualifications
A baccalaureate degree from an accredited college and four years of satisfactory full-time experience related to projects and policies required by the particular position; or education and/or experience which is equivalent to the above.
Preferred Skills
- Expert in knowledge of one of the following areas:
- Information Security concepts related to Governance, Risk & Compliance
- Proven track record of securing Data across multiple platforms
- Understanding of Zero Trust framework
- Office 365 and Microsoft Exchange Online Defender for Office 365, Defender for Cloud Apps, Microsoft Purview, Azure Entra Active Directory security services (PIM, CAA, CA, MFA), and Azure AD Application Proxy
- Knowledge of at least three of the following areas:
- Mapping policies into security controls across on-premise, hybrid and cloud environments
- SMTP routing and email security concepts
- Common networking protocols and services including TCP, UDP, DNS, DHCP, HTTP, and LDAP
- Developing and supporting Intune Endpoint MDM, MAM, & BYOD policies
- Troubleshooting workstation (Windows, Mac) and server (Windows, Linux) issues
- Scripting skills (Python, Bash, Powershell)
- Microsoft Windows Server stack (Active Directory, DNS, WMI, DHCP, etc)
- Change Management platforms and Scrum processes (ServiceNow, Jira, etc)
- Ability to problem solve in situations of ambiguity and to work effectively and efficiently in a high pressure environment
- Ability to pivot to work on emergent issues, events, or requests while keeping completing existing deliverables on time
- Experience in documenting systems designs and configurations of architected solutions (conceptual, logical, and physical diagrams; new environment design documents; write-ups on technical capabilities and solution configurations; or runbooks for agency adoption)
- Understanding of security and compliance policies and incident response processes; ability to work with different agencies to determine sensitive data that needs to be protected with DLP and information protection technology based on the citywide standards and policies
- Ability to achieve goals with minimal supervision; self-starter; self-motivated and a capacity to get things done