Staff Cloud Security Engineer
CollectorsFull Time
Expert & Leadership (9+ years)
Candidates should possess an intermediate-level understanding of AWS, Azure, or GCP, with emphasis on identity, security, networking, compute, serverless, and storage services. Fundamental knowledge of cloud architecture and design principles, including security and resiliency, is required. Familiarity with logging, monitoring, and alerting for cloud resource security, ability to create search queries and dashboards in analytics platforms, and write automation scripts in Python or another scripting language are necessary. Knowledge of API authentication and authorization, including identity protocols like OAuth, SAML, and OpenID Connect, is needed. Hands-on experience reviewing cloud security configurations, including configuration chaining and attack path mapping, is essential. Strong communication skills to convey analysis findings to technical and executive audiences are required. Experience or training in cloud incident response methodologies and DevSecOps, CI/CD pipelines, containers, and Kubernetes is beneficial.
The Cloud Security Consultant will perform technical analysis to identify risky configurations, attack paths, and architectural flows that may expose cloud resources to cyber threats. They will produce high-quality written and verbal reports, presentations, recommendations, and findings to security stakeholders. Additionally, the consultant will contribute to tool development and methodologies to continuously improve and evolve service offerings.
Cloud-native endpoint security solutions provider
CrowdStrike specializes in cybersecurity, focusing on protecting businesses from cyber threats through cloud-native endpoint security solutions. Their main product, the Falcon platform, includes services like Falcon Pro, which replaces traditional antivirus with next-generation antivirus that integrates threat intelligence, Falcon Insight for endpoint detection and response, and Falcon Device Control to manage connected devices. Unlike many competitors, CrowdStrike's services are subscription-based, allowing clients to choose different levels of protection based on their needs. The company serves a diverse clientele, including many Fortune 100 companies, and is recognized as a leader in the cybersecurity field, known for its effectiveness in threat detection and response.