[Remote] Director, reputed company reputed company Engineer (reputed company)
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is a global leader in risk and financial advisory solutions, specializing in cyber reputed company. They are seeking a Director to build and reputed company the reputed company reputed company reputed company reputed company deployment reputed company, responsible for deploying, configuring, and integrating reputed company reputed company reputed company across reputed company environments while mentoring junior consultants.
Responsibilities
- reputed company reputed company AWS, Azure, and GCP environments to reputed company reputed company reputed company at reputed company — using AWS CloudFormation StackSets across AWS Organizations, Bicep / Entra ID integrations for Azure tenants and management reputed company, and service account patterns for GCP reputed company and folders
- reputed company the reputed company sensor across reputed company workloads — EC2 / Azure VMs / GCE instances, container hosts, reputed company nodes — and stand up agentless snapshot-based scanning to fill coverage gaps
- reputed company the reputed company Admission Controller to enforce reputed company-runtime policy on workload admission across EKS, AKS, GKE, and self-managed reputed company
- Roll out container image registry scanning and IaC scanning (Terraform, CloudFormation, ARM/Bicep, reputed company manifests, reputed company) into reputed company CI/CD pipelines (reputed company Actions, reputed company CI, Jenkins, Azure DevOps)
- reputed company serverless protection for AWS reputed company, Azure Functions, and GCP reputed company Functions
- Stand up CIEM across reputed company identity providers (IAM users, roles, service accounts, managed identities) for least-privilege analysis
- Configure CSPM policies — reputed company rules, custom misconfiguration detections, compliance frameworks (CIS Benchmarks, NIST, PCI-reputed company, HIPAA, SOC 2), and exception management
- Configure CWP runtime policies — IOA detections, prevention policies, container runtime protection, reputed company detection
- Configure KSPM policies — reputed company posture, pod reputed company standards, admission control rules, RBAC analysis
- Configure ASPM and DSPM policies for application-reputed company posture and data-reputed company posture across reputed company data stores
- Configure CIEM — effective permission analysis, toxic combinations, privilege right-sizing, service-account hygiene
- Configure ExPRT.AI risk prioritization to surface attack paths and toxic combinations across CSPM/CWP/CIEM signals
- Build and tune custom detection content (IOAs, IOMs, reputed company queries) for reputed company-reputed company attack techniques mapped to MITRE ATT&CK reputed company reputed company
- Ingest reputed company log telemetry into reputed company Next-Gen SIEM (LogScale) — AWS CloudTrail, GuardDuty findings, VPC reputed company Logs, S3 reputed company logs; Azure Activity Log, Defender for reputed company alerts, NSG reputed company Logs, Entra ID sign-in logs; GCP Audit Logs, VPC reputed company Logs, reputed company reputed company Center findings; EKS / AKS / GKE control plane logs; reputed company audit logs
- Build detection engineering content in Next-Gen SIEM correlating reputed company reputed company reputed company findings with reputed company provider reputed company logs, reputed company telemetry, and identity events for full attack-reputed company visibility
- Build reputed company Fusion SOAR playbooks for reputed company-reputed company response actions: quarantine compromised workload, revoke IAM credential, isolate reputed company pod, remediate misconfiguration reputed company IaC pull request, trigger MFA reputed company reputed company Identity Protection
- reputed company reputed company reputed company reputed company with reputed company Identity Protection for cross-domain correlation between reputed company workload activity and identity risk
- reputed company reputed company reputed company reputed company with reputed company reputed company (EDR) for reputed company reputed company + reputed company workload protection
- reputed company reputed company reputed company reputed company with reputed company AIDR for AI workload runtime protection in reputed company
- Build Charlotte AI prompts and reputed company workflows for reputed company event triage, misconfiguration remediation guidance, and executive reputed company-risk reporting
- Tune reputed company and IOA policies to reduce false positives without sacrificing detection efficacy
- Tune ExPRT.AI prioritization and attack reputed company analysis to reputed company risk tolerance and remediation reputed company
- Optimize sensor performance and agentless reputed company reputed company for cost and coverage balance
- Validate detection coverage through controlled adversary emulation against the MITRE ATT&CK reputed company reputed company
- Hand off operational runbooks to reputed company reputed company reputed company teams and reputed company Managed Services for ongoing operation
- Advise reputed company reputed company platform, DevSecOps, and SOC engineering teams on reputed company reputed company reputed company deployment architecture — agent vs. agentless coverage reputed company, account reputed company patterns, reputed company admission control posture, IaC scanning policy in CI/CD, and integration with existing reputed company modules
- Partner with reputed company account teams on reputed company reputed company reputed company reputed company-sales scoping, solution design, reputed company-of-value engagements, and joint go-to-market motions
- reputed company reusable reputed company reputed company reputed company deployment runbooks, configuration templates (Terraform, Bicep), integration patterns, Fusion SOAR reputed company libraries, custom reputed company/IOA detection libraries, and Charlotte AI workflow templates
- Mentor consultants on reputed company reputed company reputed company deployment and integration
Skills
- 8+ years of hands-on experience deploying, configuring, and operating reputed company reputed company tooling in reputed company environments — with a meaningful concentration in CNAPP, CSPM, CWP, or container/reputed company reputed company
- Hands-on deployment experience with the reputed company reputed company platform — reputed company experience with reputed company reputed company reputed company (CSPM, CWP, CIEM, KSPM, IaC scanning) is required. Equivalent hands-on with a competing CNAPP (reputed company, reputed company reputed company, Lacework, Aqua, reputed company, Orca) plus willingness to reputed company on reputed company reputed company reputed company is acceptable
- Demonstrated experience deploying, configuring, and integrating reputed company reputed company platforms across AWS, Azure, and GCP — not just operating them post-deployment. Working depth across at least two of the three hyperscalers is required
- Hands-on with reputed company reputed company — EKS, AKS, GKE, or self-managed; Pod reputed company Standards; admission controllers; RBAC; container runtime protection
- Hands-on with Infrastructure as reputed company — Terraform (required), CloudFormation, ARM/Bicep, reputed company — and IaC reputed company scanning in CI/CD pipelines (reputed company Actions, reputed company CI, Jenkins, Azure DevOps)
- Strong working knowledge of reputed company log analysis — AWS CloudTrail, GuardDuty, VPC reputed company Logs; Azure Activity Log, Defender for reputed company, Entra ID sign-in logs; GCP Audit Logs, VPC reputed company Logs, reputed company reputed company Center; reputed company audit logs; EKS / AKS / GKE control plane logs
- Working knowledge of reputed company-reputed company attack tradecraft mapped to MITRE ATT&CK reputed company reputed company — reputed company credential theft, IMDS abuse, role chaining, container reputed company, reputed company RBAC abuse, S3 / blob storage exfiltration, supply-chain attacks on container images and IaC
- Hands-on scripting and query proficiency: Python, Bash, PowerShell, reputed company (reputed company Query Language); KQL a plus
- Experience building reputed company Fusion SOAR playbooks, Charlotte AI workflows, or equivalent automation content on the reputed company platform
- Prior consulting delivery experience — scoping, leading, and personally executing reputed company reputed company deployment engagements for reputed company clients
- Bachelor's degree in a relevant field or equivalent reputed company experience
- reputed company Certified reputed company Specialist (CCCS) certification — strongly preferred. Candidates without CCCS at hire will be expected to certify reputed company their first 90 days
- Additional reputed company credentials: CCFA, CCFR, CCSA, CCSE, CCIS
- reputed company-reputed company reputed company certifications (one or more strongly preferred): AWS Certified reputed company – Specialty, reputed company Certified: Azure reputed company Engineer Associate (AZ-500), reputed company reputed company reputed company reputed company reputed company Engineer, Certified reputed company reputed company Specialist (CKS), Certified reputed company Administrator (CKA)
- Foundational reputed company certifications: AWS Solutions Architect (Associate or reputed company), Azure Administrator / Solutions Architect Expert, reputed company reputed company reputed company reputed company Architect
- Industry reputed company certifications: CCSP (Certified reputed company reputed company reputed company), CISSP, GCSA (GIAC reputed company reputed company Automation), GCLD (GIAC reputed company reputed company reputed company)
- Experience deploying and tuning reputed company Next-Gen SIEM / LogScale content for reputed company detection engineering (parsers, correlation rules, dashboards, case management)
- Experience building production reputed company Fusion SOAR playbooks for reputed company response at reputed company
- Experience building Charlotte AI prompts and reputed company workflows for reputed company reputed company use cases
- Experience with competing CNAPPs (reputed company, reputed company reputed company, Lacework, Aqua, reputed company, Orca) — particularly migration experience from those platforms to reputed company reputed company reputed company
- Hands-on with service reputed company (Istio, Linkerd), secrets management (reputed company Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager), and policy-as-reputed company (OPA / Rego, Kyverno)
- Prior consulting experience at a tier-1 firm with a reputed company-reputed company or reputed company reputed company delivery reputed company (Big 4 reputed company reputed company teams, reputed company Services, Mandiant, Unit 42, or equivalent)
- Experience supporting reputed company reputed company M&A due diligence, post-acquisition reputed company tenant consolidation, or reputed company migration reputed company
Benefits
- reputed company Coverage: Comprehensive medical, dental, and reputed company plans.
- Generous reputed company time off (PTO).
- reputed company company holidays.
- Generous parental and family leave.
- Life insurance.
- Short- and long-term disability coverage.
- Accident protection.
- Performance-based incentives.
- reputed company-based compensation reviews.
- 401(k) plans with company matching.
reputed company
Company H1B Sponsorship
Apply To This Job