Job Location : Maryland Line,MD, USA
Develop and implement cloud security controls, cloud-based processes and tools, and cloud security task automation. Perform security assessments, working closely with DevOps and Developer teams on identifying security and privacy issues in AWS or Azure and finding solutions to provide required functionality securely. Continuously monitor the Health Benefit Exchange (HBX) and ancillary systems, not limited to cloud security operations, responding to security issues and escalating as necessary. Conduct security impact analysis of controls on proposed system changes. Conduct cloud security assessments and Penetration testing. Perform Incident Response and Forensics evaluation using security information and event management (SIEM) tools. Ensure that the MHBE system security requirements are addressed during all phases of the system development life cycle. Review and update systems security documentation and artifacts such as Systems Security Plan, Information Security Risk Assessment, Privacy Impact Assessment, Systems Security Report, Correction Action Plan, Plan of Action & Milestones (POA&M). Create and track POA&M requirements for resolving security findings. dminister cloud-based and physical firewalls. Deploy and administer Identity and Access Management products in various operating systems. Perform monitoring and operations of Identity and Access Management implementation. Design enhancements in Identity and Access Management products ForgeRock and SailPoint. Maintain, monitor, and provide operational support for IAM products, computer programs, systems, and other security technologies and revise system design and quality standards. Make changes to IAM and underline applications for enhancing enterprise security and ensure safe and secure operation to enable access to our systems for our employees, contractors, consumers, and stakeholders. Perform Security Incident Response and Forensics evaluation using security information and event management (SIEM) tools. Provide operational support for other security technologies. Perform account/access management with IAM and other security tools.