Information Security Analyst Job at Kimley-Horn and Associates, Inc., Raleigh, NC

cGhuaTQybE9iTzBUZ1hmMm45ZEhncjd0Rmc9PQ==
  • Kimley-Horn and Associates, Inc.
  • Raleigh, NC

Job Description

Overview

Kimley-Horn, one of Fortune Magazine's "100 Best Companies to Work For," is looking for a Cloud Security Analyst to join the Information Security team in our Raleigh, NC office. As a Cloud Security Analyst, you will play a critical role in ensuring the security of our organization's technology infrastructure and assets. You will be responsible for ensuring the security of our cloud infrastructure and applications, as well as identifying and mitigating security risks.

This is not a remote position.

Responsibilities

  • Familiarity with Azure SSO integration and SCIM automated user provisioning
  • Experience with IAM / Modern Authentication / Identity tooling is a plus (e.g., ServiceNow, MFA, Security Token, OAUTH, Azure AD conditional access, AWS, etc.)
  • Working knowledge of security risk oversight, CVSS (Common Vulnerability Scoring System), CVE (Common Vulnerabilities and Exposures), and technical security vulnerability remediation/mitigation
  • Practical experience analyzing cloud infrastructure vulnerability data to understand and communicate risks, concerns, and outcomes of decisions
  • Accountable for tracking application vulnerabilities through security tools and meeting with development teams to formulate remediation plans
  • Prepare reports detailing metrics and KPIs of the security program and tools
  • Build automation to actively audit the infrastructure for security misconfigurations by using cloud-native policies/scripts
  • Work closely with the Product Engineering, Platform and Security Architecture teams to engineer and implement cloud security controls with a focus on DevSecOps
  • Ability to design and implement secrets management solutions in cloud environments, including hands-on experience in building out systems utilizing tools such as AWS Secrets Manager or Azure Key Vault
  • Experience in CI/CD pipeline using Jenkins, IaC like Terraform added advantage
  • Broad knowledge of web standards relating to APIs (OAuth, SSL, CORS, JWT, etc.)
  • Proficiency in scripting and programming languages like Python, PowerShell, or Bash
  • Conduct thorough investigations of security incidents to determine the root cause and impact
  • Proactively identify potential security vulnerabilities and weaknesses in the system and recommend appropriate remediation actions
  • Participate in tabletop exercises and simulations to test and improve incident response plans
  • Prepare detailed incident reports, documenting the findings, actions taken, and lessons learned

Qualifications

  • Bachelor's degree in information security, cybersecurity, or a related field
  • 4+ years of experience with Azure DevOps, Azure Security, or a similar role within an enterprise-level organization
  • Strong scripting skills in PowerShell
  • Experience with infrastructure as code (IaC) concepts & being open to working with PowerShell+ DSC as your main IaC tool
  • Solid understanding of incident response methodologies, tools, and frameworks
  • Experience with change-management policies and procedures
  • Excellent problem-solving skills and the ability to think critically under pressure
  • Strong communication skills, both written and verbal, with the ability to convey complex technical concepts to non-technical stakeholders
Desired Skills:
  • Relevant certifications such as Certified Secure Software Lifecycle Professional (CSSLP), Certified Information Systems Security Professional (CISSP), or Azure certifications
  • Experience working with common security protocols, encryption, server technologies, modern authentication, and cloud app authorization architectures
  • Familiarity with query languages, advanced queries, and penetration testing tools
  • Knowledge of the MITRE ATT&CK framework or NIST Cyber Security Framework (CSF)
Applicants must be legally authorized to work for Kimley-Horn in the U.S. without employer sponsorship. We do not typically sponsor H1-B or any other work visa petitions.

Job Tags

Work visa,

Similar Jobs

Capital One Careers

Lead UX Designer - GenAI Experiences Job at Capital One Careers

Lead UX Designer GenAI Experiences We are currently seeking a Lead UX Designer to join our AI and ML Design team to help lead...  ...fidelity prototypes Planning and facilitating workshops with internal and external stakeholders to align with business needs... 

Headway

LPC (Virtual) Job at Headway

 ...LPC (Virtual) at Headway summary: As a Remote Licensed Professional Counselor (LPC) with Headway, you will provide psychotherapy...  ...to set your own hours. Headway assists mental health clinicians with insurance credentialing, billing, and marketing support to grow their... 

WMCHealth

Anesthesiologist Job at WMCHealth

 ...Job Summary: The Department of Anesthesiology at WMCHealth, is currently recruiting a well-rounded Anesthesiologist at Health Alliance Hudson Valley in Kingston in upstate New York. Join a reputable community hospital with a new campus and a state of the art operating... 

European Wax Center

Wax Specialist - Waxer/ Licensed Esthetician or Cosmetologist Job at European Wax Center

 ...Esthetician / Cosmetologist European Wax Center began as a family-owned salon where two brothers had an idea to revolutionize the...  ...week; must have current Minnesota Esthetician or Cosmetology License. Typical Total Compensation: Following Training: $18-$2... 

Southjerseyspeedpro

Wide Format Print Production Manager Job at Southjerseyspeedpro

 ...developmentSpeedPro Boston Metrowest is seeking a talented Production Manager to join our fast-growing Studio. Do you love producing beautiful...  ...possess: Management experienceA background in the sign or print industry.Experience with large-format printers, laminators,...