Role: Cloud Cyber Security Operations Specialist
Experience: 12+ Years
Location: Pittsburgh, PA
Work Mode: Onsite Client Location
Role Overview
The Cloud Cyber Security Operations Specialist will work closely with the Security Operations Center (SOC), Infrastructure, Cloud Engineering, DevOps, and Compliance teams to maintain a secure cloud ecosystem and strengthen the organization's overall cybersecurity posture.
The role will focus on cloud security operations, incident response, threat hunting, security monitoring, identity and access security, compliance, Policy as Code, and security automation across Azure, AWS, and Google Cloud Platform environments.
Key Responsibilities
Security Monitoring & Incident Response
- Monitor cloud environments for security threats, suspicious activities, vulnerabilities, and policy violations.
- Investigate security alerts and incidents generated by SIEM, XDR, CSPM, and cloud-native security tools.
- Lead incident triage, containment, eradication, and recovery activities.
- Perform root-cause analysis and document incident findings, remediation actions, and lessons learned.
- Develop and maintain cloud security incident response playbooks.
- Provide resolution support for security and compliance exposures identified through monitoring and alerts.
Cloud Security Operations
- Manage and continuously improve security posture across Microsoft Azure, AWS, and Google Cloud Platform.
- Identify and remediate cloud misconfigurations, vulnerabilities, and security gaps.
- Conduct cloud security risk assessments and security reviews.
- Monitor compliance against cloud security baselines, policies, and regulatory requirements.
- Establish preventative procedures to address newly identified security exposures before they impact production environments.
- Evaluate and implement appropriate cloud security tooling for vulnerability scanning, monitoring, alerting, and reporting.
Identity & Access Security
- Monitor privileged access and enforce least-privilege principles.
- Review and manage IAM, RBAC, MFA, Conditional Access, SSO, and Privileged Identity Management (PIM).
- Investigate identity-based threats, unauthorized access attempts, and anomalous authentication activity.
Threat Hunting & Detection Engineering
- Perform proactive threat hunting across cloud workloads, identities, endpoints, and services.
- Develop security detection use cases, analytics rules, and monitoring capabilities.
- Leverage the MITRE ATT&CK Framework to improve threat detection and response.
- Identify emerging cloud threats and recommend appropriate security controls and improvements.
Security Automation & Reporting
- Support security automation initiatives using SOAR, scripting, and automated response capabilities.
- Develop dashboards, reports, security metrics, and operational KPIs for management review.
- Establish security support processes in partnership with Product, Infrastructure, Cloud Engineering, and Information Security teams.
- Recommend process improvements to increase the efficiency and effectiveness of cloud security operations.
Cloud Security & Policy as Code
- Understand and apply corporate information security frameworks, policies, implementation standards, and supporting security tools.
- Translate corporate security policies into actionable cloud security requirements.
- Identify applicable compliance standards and develop policies and controls aligned with frameworks such as SOC 2, NIST 800-53, ISO 27001, and CIS Benchmarks.
- Implement Policy as Code to enforce security and compliance requirements.
- Apply Policy as Code for pre-deployment compliance validation of Infrastructure as Code, including Terraform and Helm.
- Implement continuous compliance and configuration monitoring of running cloud environments.
- Use native cloud policy engines to prevent unauthorized or out-of-band configuration changes across Azure, AWS, Google Cloud Platform, and OCI environments.
- Partner with Product and Information Security teams to establish cloud security controls and operational processes.
- Implement automated vulnerability scanning, alerting, reporting, and incident response wherever practical.
Required Technical Skills
- Strong hands-on experience with one or more major cloud platforms
- Strong understanding of:
- Cloud security architecture
- Cloud networking
- Firewalls, VPNs, WAF
- Zero Trust Architecture
- IAM, SSO, MFA, RBAC
- Vulnerability Management
- Security monitoring and log analysis
- Experience with:
- Microsoft Sentinel / Azure Sentinel
- Microsoft Defender for Cloud
- Microsoft Defender XDR
- AWS Security Hub
- CrowdStrike
- CSPM / KSPM / SSPM solutions
- Working knowledge of:
- PowerShell
- Python
- Bash
- KQL
- Experience with Policy as Code and Infrastructure as Code security.
- Knowledge of cloud-native security and policy tools such as Azure Policy, Microsoft Defender for Cloud, AWS security services, Google Cloud Platform Security Command Center, OCI Cloud Guard, and CSPM platforms.
Security Knowledge
- Security Operations Center (SOC) processes
- Incident Response and Threat Hunting
- Security Monitoring and Log Analysis
- Cloud Security Best Practices
- MITRE ATT&CK Framework
- NIST Cybersecurity Framework
- NIST 800-53
- CIS Benchmarks
- ISO 27001
- SOC 2
- Cloud Security Posture Management (CSPM)
- Kubernetes Security Posture Management (KSPM)
- SaaS Security Posture Management (SSPM)
Preferred Experience
- Experience working in enterprise-scale cloud environments.
- Experience collaborating with SOC, DevOps, Infrastructure, Cloud Engineering, Product, and Compliance teams.
- Strong analytical, troubleshooting, documentation, and communication skills.
- Experience implementing security controls across multi-cloud environments.

