Lead Security Engineer
How is this team contributing to the vision of Providence?
We, at Enterprise Services, the healthcare consulting and services arm of Providence India, help build technology solutions that modernize and simplify each step of the healthcare delivery process. And we do that by putting the patient and the provider at the center of everything we do. Using the most promising and practical ideas, combined with the experience and expertise from people from the healthcare industry, we are creating experiences that work for care facilities, their patients and move us ahead on our mission of “Health for a better world“.
What will you be responsible for?
- Be part of Security Engineering team. Participate and advance the Security Engineering capability operating out of India.
- Ensure that Cloud platforms/solutions are securely built/configured, modified/changed, tested, and deployed as per defined policies, standards, and industry good practices.
- Ensure continuous consistency to applicable compliance, regulatory, and legal frameworks for the Cloud infrastructure within the Security Engineering scope.
- Provide analysis and recommendations for continuous improvement of Cloud network and security.
- Participate in creation and maintenance technical security policies, standards, configuration baselines, benchmarks, guidelines, and SOPs.
- Support Cloud security platform/tool engineering efforts such as platform/tool management, upgrades, changes, and integrations.
- Support other Security Engineering efforts such as development and testing of automation.
What would your day look like?
- Engineer security for Cloud native network and security services/components, and Cloud Security Assurance platforms/tools, supporting complex hosting and integration.
- Identify, develop, and enforce technical security policies, standards and procedures, including security hardening.
- Collaborate with cross-functional teams on Cloud platform/solution security related matters, esp. to identify, investigate, and remediate security vulnerabilities and mitigate risks.
- Perform security readiness audits and support internal and external security auditing on platforms/solutions. Report on platform/solution security status.
- Identify major platform/solution deficiencies and define/craft pragmatic approaches on how to remediate them at scale.
- Investigate and report suspected breaches in Cloud and IT infrastructure.
- Participate in new technology/product evaluations through Proof of Concept (PoC) with other architects/engineers.
- Review technology objectives for Cloud programs and services and make recommendations for their security requirements.
- Evangelize and promote IT Security culture across the organization.
Who are we looking for?
- 4-year University (Bachelor’s) degree in Computer Science, Information Technology, or STEM fields, or equivalent experience.
- 7+ years of Information Systems experience, 4+ years of hands-on implementing secure Cloud environment for large scale enterprises.
- Hands on experience and knowledge in Cloud native network and security services/components like – Security Group, IAM policies, Multi-factor Authentication (MFA), Key Management, Cloud/Virtual WAN, Direct Connect / ExpressRoute, Virtual Private Cloud (VPC) / Virtual Network (VNet), VPN Gateway, Firewall, DDoS protection, AWS Config / Azure Policy, AWS Security Hub / MS Defender for Cloud, etc.
- Thorough knowledge of Public Cloud environments, Cloud-Native services, multi-cloud, complex integrations.
- Commendable knowledge on Security Assurance platforms/tools for Cloud Security, Vulnerability Assessment, Cloud Access Security Broker (CASB), Cloud Security Posture Management (CSPM), Cloud Workload and Network Security, Cloud Exposure Management.
- Preferred experience in implementing secure Cloud environment and services adhering to Cloud security standards (NIST SP 800-53, 800-123, 800-125 and 800-144, CSA, ISO/IEC 27002, ISO/IEC 27017, ISO/IEC 27018).
- Preferred experience with scripting or programming (shell scripting, PowerShell, Python, etc.)
- Ability to perform work independently with a high degree of initiative and problem-solving skills.
- Strong technical aptitude, attention to detail and high commitment to quality.
- Proficient in writing/creation of formal documentation such as reports, slide decks, and architecture diagrams.
- Preferred CCSP, CCSK, AWS / Azure Security, CISSP or equivalent Information Security certification.