Overview: The Principal Security Engineer will be responsible for helping ensure the security of Inovalon’s customers, staff, systems, and data across complex multi-cloud environments. The Principle Security Engineer will support the implementation, maintenance, and upkeep of our cloud security systems across AWS, Azure GCP, and OCI cloud environments. This includes auditing and hardening existing cloud implementations and architecting and implementing solutions with a “Zero Trust” mindset.
The successful candidate will perform security assessments, analyze alternatives, develop recommendations, provide hands on trouble shooting and diagnosis for tools, and work across teams as needed to maintain the security health of the corporation.
Duties and Responsibilities:
· Design and develop zero-trust architectures across multi-cloud environments (AWS, Azure, GCP, OCI)
· Performs analysis, design, and development of security automation tools / scripts
· Design and develop automated security policy enforcement mechanisms using policy-as-code methods
· Designing and integrating data protection processes, threat management, and monitoring and platform tools
· Conduct threat modeling, security architecture reviews, risk assessment, and provide guidance on mitigating identified issues.
· Developing and updating cloud templates, standards, and best practices to be used by multiple cloud projects.
· Conduct architecture reviews and security impact assessments for technology and software development issues.
· Provides technical expertise and direction for the selection and implementation of a diverse suite of information security countermeasures;
· Provides technical leadership to assess threats, identifies gaps in capabilities, and supports development of a roadmap to evolve the corporation’s security posture;
· Provides technical leadership to recommend appropriate information security frameworks, requirements, direction and system recommendations;
· Stay abreast of security best practices and technologies, and foster the growth of team members by providing, training, guidance and mentoring;
· Configure existing technologies in an effort to solve operational issues; and
· Additional responsibilities as assigned by management.
· Adhere to all confidentiality and HIPAA requirements as outlined within Inovalon’s Operating Policies and Procedures in all ways and at all times with respect to any aspect of the data handled or services rendered in the undertaking of the position;
· Fulfill those responsibilities and/or duties that may be reasonably provided by Inovalon for the purpose of achieving operational and financial success of the Company;
· Uphold responsibilities relative to the separation of duties for applicable processes and procedures within your job function; and
· We reserve the right to change this job description from time to time as business needs dictate and will provide notice of such.
Job Requirements:
· 10+ years of experience in progressive cyber security technical leadership roles;
· Proficient in one or more programming languages (Python, Java, Golang, PowerShell, Bash)
· Strong knowledge of cloud platforms and their security features, including zero trust architectures across multi-cloud environments (AWS, Azure, GCP, OCI)
· Hands on experience with some of the following:
o Infrastructure as Code tools (CloudFormation, Terraform)
o Policy as Code tools (OPA)
o CI/CD and DevSecOps Tooling
o Security administration in AWS/GCP/Azure/OCI
o Docker and Kubernetes
o Developing and securing serverless applications
o Core understanding of IP networking, routing, VPN
o Cloud native security related tools
· Experience with data protection, cryptography, key management, identity and access management, network security within multi-cloud environments.
· Familiarity with cloud automation and orchestration tools for optimizing security processes.
· Knowledge of industry regulatory and compliance requirements, such as HIPAA, PCI-DSS, NIST, HITRUST
Education:
· Required: Bachelor of Science in an engineering or technical discipline;
· Preferred: Bachelor of Science in a cybersecurity discipline or a Masters in an engineering or technical discipline with cybersecurity coursework; and
· Preferred – CISSP, AWS Security.
Physical Demands and Work Environment:
· Sedentary work (i.e. sitting for long periods of time);
· Exerting up to 10 pounds of force occasionally and/or negligible amount of force;
· Frequently or constantly to lift, carry push, pull or otherwise move objects and repetitive motions;
· Subject to inside environmental conditions; and
· Travel for this position will include less than 5% locally usually for training purposes.