Security Engineer, Cloud Security
OpenAIFull Time
Mid-level (3 to 4 years), Senior (5 to 8 years)
Candidates should possess 8+ years of experience in information security or compliance engineering roles, along with practical experience in DevOps security practices, including integrating security controls into CI/CD pipelines such as GitLab CI, Jenkins, or GitHub Actions. They should have a strong understanding and hands-on experience with ISO 27001, SOC 2 (Type I and II), and NIST SP 800-53, and familiarity with cloud-native security (AWS, GCP, or Azure), container orchestration, and infrastructure-as-code tools like Terraform, Helm, or Ansible.
The Staff Sw Engineer will lead and support enterprise security, compliance, and risk management initiatives, following established processes for implementing and maintaining security controls aligned with ISO 27001, SOC 2, and NIST 800-53. They will collaborate with security leadership and internal/external auditors, develop and maintain automated security and compliance monitoring tools and dashboards, translate regulatory requirements into technical requirements, and execute tasks related to the implementation and upkeep of compliance controls. Additionally, the role involves conducting gap assessments and risk analysis, defining and tracking remediation efforts, and possessing strong hands-on experience with Kubernetes security, including RBAC, pod security policies, network policies, and secrets management.
Provides advanced networking solutions and services
Extreme Networks specializes in advanced networking solutions that optimize and secure network operations for a variety of clients, including educational institutions, retail businesses, government agencies, and healthcare facilities. Their products include network infrastructure such as switching and routing solutions, wireless connectivity, and data center fabrics, along with cloud-based services and advanced security measures. Extreme Networks differentiates itself by offering both hardware and software solutions, as well as professional and managed services that ensure efficient network operations. Their goal is to provide comprehensive support and training to help clients maximize their networking capabilities.