cFocus Software is seeking an experienced
Cloud Cybersecurity Analyst to ensure the security and integrity of DHS's cloud-hosted information systems. The Cloud Cybersecurity Analyst will play a critical role in developing and implementing secure cloud architectures, providing expert advice on security policies, and managing cloud security risks. With over 8 years of experience, the ideal candidate will have extensive knowledge in cloud security, cyber defense, and risk management, working to ensure that DHS's cloud systems meet the highest standards of security and compliance.
Key Responsibilities:
- Cloud Security Architecture & Design:
- Ensure the architecture and design of cloud-hosted information systems are functional, secure, and compliant with DHS security standards.
- Collaborate with cross-functional teams to design and implement secure cloud infrastructures, focusing on minimizing risks and addressing potential vulnerabilities.
- Conduct security assessments of cloud systems and recommend appropriate solutions for securing cloud environments.
- Strategic Planning & Implementation:
- Lead strategic planning efforts related to cloud cybersecurity, identifying and addressing risks associated with cloud-hosted applications and services.
- Develop and recommend implementation strategies for securing cloud systems and data, ensuring compliance with DHS security policies and industry best practices.
- Security & Privacy Policy Advisory:
- Advise and assist DHS leadership on security and privacy policies related to cloud-hosted applications and services, ensuring compliance with federal regulations (e.g., FISMA, NIST).
- Assist in the development and enforcement of cloud security policies, procedures, and controls to protect sensitive data in cloud environments.
- Trusted Product Assessment & Enterprise Security Engineering:
- Assess trusted products for use in cloud environments, ensuring they meet security standards and integrate seamlessly with existing DHS infrastructure.
- Provide expertise in enterprise security engineering, ensuring that cloud systems are architected with a focus on confidentiality, integrity, and availability.
- Cyber Defense and Threat Management:
- Conduct penetration testing and exploitation of cloud-hosted systems to identify vulnerabilities and assess risk exposure.
- Lead efforts in insider threat analysis and protection within cloud environments, implementing monitoring and response measures to detect and mitigate malicious activities.
- Implement and manage cyber situational awareness tools and techniques, including attack sensing, warning systems, and incident detection to protect cloud-hosted systems.
- Secure Systems & Data Management:
- Develop and maintain secure cloud operating systems, workstations, and data management practices, ensuring that cloud data is encrypted and stored in accordance with DHS requirements.
- Advise on and implement secure wireless networking and mobile computing practices within the cloud environment to ensure safe access and communication.
- Provide expertise in securing web technologies, protocols, and authentication methods used in cloud-hosted systems.
- Incident Response & Risk Management:
- Lead incident response efforts for cloud-based security breaches, conducting investigations and managing resolution.
- Provide recommendations on risk management strategies for the cloud, identifying potential threats and implementing mitigations to safeguard DHS’s cloud infrastructure.
- Collaboration & Training:
- Collaborate with IT, network, and security teams to integrate cloud security best practices into all operational systems.
- Provide training and guidance to internal teams on cloud security technologies and policies to ensure compliance and enhance awareness.
Qualifications:
- Education:
- Bachelor’s or Master’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- Experience:
- 8+ years of experience in cybersecurity, with a focus on cloud security and cyber defense.
- Proven experience with cloud platforms (AWS, Microsoft Azure, Google Cloud) and securing cloud-hosted applications and systems.
- Experience in the assessment, design, and implementation of secure cloud architectures.
- Strong background in penetration testing, threat analysis, risk management, and incident response in cloud environments.
- Expertise in security and privacy policy, enterprise security engineering, insider threat protection, and secure data management.
- Skills and Competencies:
- In-depth knowledge of cloud security frameworks, protocols, and technologies (e.g., encryption, secure web technologies, secure authentication).
- Expertise in securing cloud-based infrastructures, services, and applications, including secure wireless networking and mobile computing.
- Strong understanding of security standards and frameworks (e.g., NIST, FISMA, FedRAMP) and their application to cloud environments.
- Experience in cyber situational awareness, attack sensing, and incident response within cloud platforms.
- Strong communication skills, with the ability to convey complex cybersecurity concepts to both technical and non-technical stakeholders.
- Leadership and project management skills, with a proven ability to manage multiple priorities and ensure timely delivery of security solutions.
- Certifications (Preferred):
- Certified Information Systems Security Professional (CISSP)
- Certified Cloud Security Professional (CCSP)
- AWS Certified Security – Specialty, Azure Security Engineer, or similar cloud security certifications.
- Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP).
Security Clearance:
Due to the sensitive nature of the role, candidates must possess or be able to obtain the required security clearance.