Emory

The Carter Center: Cloud Security Analyst, IT

Job Number
108018
Job Type
Regular Full-Time
Division
The Carter Center
Department
The Carter Center
This position may involve the following Health and Safety issues:
Not Applicable
Job Category
Information Technology
Campus Location (For Posting) : City
Atlanta
Location : Name
Carter Center

Discover Your Career at Emory University

Emory University is a leading research university that fosters excellence and attracts world-class talent to innovate today and prepare leaders for the future. We welcome candidates who can contribute to the diversity and excellence of our academic community.

Description

The_Carter_Center

 

The Carter Center is a 501(c)(3), not-for-profit, nongovernmental organization founded in 1982 in Atlanta, GA, by former U.S. President Jimmy Carter and his wife, Rosalynn, in partnership with Emory University. The Center has helped to improve millions of lives in more than 80 countries by waging peace, fighting disease, and building hope. The Carter Center is guided by a fundamental commitment to human rights and the alleviation of human suffering. It seeks to prevent and resolve conflicts, enhance freedom and democracy, and improve health.


The Carter Center collaborates with other organizations, public and private, in carrying out its mission around the world. Current information about the Center’s many programs and activities are available at The Carter Center.

 

SUMMARY:

 

The Cloud Security Analyst works within the Carter Center Information Technology (IT) Team to evaluate, implement, and monitor security controls for cloud services, primarily associated with Microsoft Azure.  The position is responsible for optimizing application monitoring and network threat detection, event analysis and correlation, and incident response activities; automating the secure design and deployment of cloud-based resources and endpoints; and developing secure migration procedures for transferring and storing data in the cloud environment.

 

FORMAL JOB DESCRIPTION:

  • The Cloud Security Analyst works within The Carter Center IT Team to evaluate, implement, and monitor security controls for cloud services, primarily associated with Microsoft Azure.
  • Responsible for optimizing application monitoring and network threat detection, event analysis and correlation, and incident response activities; automating the secure design and deployment of cloud-based resources and endpoints; and developing secure migration procedures for transferring and storing data in the cloud environment.
  • Maintains and monitors the security of cloud infrastructure using Intrusion Prevention Systems (IPSes), Anomaly Detection Systems (ADSes), rule-based network flow appliances like WAFs, conditional access rules, compliance policies and other tools to detect potential vulnerabilities, prevent active malicious activity and recover from security incidents.
  • Establishes and supports standard incident containment, digital forensics, and other security procedures to limit the impact of security incidents.
  • Queries and correlates events from source devices and activity logs using Python-based regular expressions, a query language like KQL or SQL, and data analysis techniques like filters, joining and pivoting.
  • Captures security incident details, prepares reports and reviews meetings, and plans and participates in periodic tabletop exercises.
  • Supports and provides guidance to the security architecture, including identity and access management (IAM), virtual private networks (VPNs), wireless access points, backup/recovery technologies and procedures, data storage and transfer, application and service hardening, and endpoint configuration compliance.
  • Supports troubleshooting activities for managed applications and devices as needed by the IT Team.
  • Provides assistance regarding information security matters such as the interpretation of information security policies and requirements or their applicability to specific situations.
  • Supports, maintains, monitors, troubleshoots, and enhances security infrastructure tools, methodologies, software, and hardware across Carter Center sites.
  • Drafts and reviews information security policies, processes, and procedures.
  • Determines and documents information security requirements and controls necessary for the protection of information resources.
  • Supports and trains IT managers in effective security operations as they are formalized.
  • Supervises interns or contractors as needed, and must be able to work effectively within the IT Team and across different departments and country offices. 
  • Maintains professional growth and development of self by identifying educational/training programs, professional organizations, activities, and resources to maintain knowledge of international security trends and to promote leading edge expertise.
  • May travel and perform other related responsibilities as required.
  • Hostile Environment Awareness Training (HEAT) may be required for certain travel locations.

MINIMUM QUALIFICATIONS:

  • A bachelor's degree in Cybersecurity or Digital Forensics and two years of relevant IT cloud experience which includes security analyst/support and knowledge of cybersecurity frameworks, OR an equivalent combination of education, training, and/or experience. CompTIA Cybersecurity Analyst (CySA+), GIAC Security Essentials (GSEC), EC-Council Certified Ethical Hacker (CEH) or equivalent certification is a plus.

PREFERRED QUALIFICATIONS:

  • Familiarity with common cybersecurity frameworks, including NIST CSF, CIS Controls, CSA Cloud Controls Matrix, OWASP Top 10, and MITRE ATT&CK CSA Certificate of Cloud Security Knowledge (CCSK), (ISC)2 Certified Cloud Security Professional (CCSP), Microsoft Certified: Security Operations Analyst Associate, and/or Microsoft Certified: Azure Security Engineer Associate certifications.
  • Familiarity with Windows, Linux, and MacOS authentication mechanisms and log configuration and monitoring. Experience securing and monitoring SaaS, IaaS and PaaS resources in Microsoft Azure and Microsoft 365.
  • Familiarity with the configuration and deployment of cloud-based security appliances and event monitoring systems, such as Microsoft Sentinel, Microsoft Defender for Cloud, Application Insights, Azure Monitor, and Azure Application Gateway.
  • Experience with log analysis, event correlation, incident management, mobile device management, service and protocol hardening, application deployment and configuration, penetration testing, and vulnerability assessment.

NOTE: This role will be granted the opportunity to work from home regularly but must be able to commute to The Carter Center on a flexible weekly schedule based upon business needs. Schedule is based on agreed upon guidelines. The Carter Center reserves the right to change remote work status with notice to employee.

Applicants must be currently authorized to work in the United States for any employer. The Carter Center requires employees to be fully vaccinated against COVID-19 or have an approved exemption.

Emory Supports a Diverse and Inclusive Culture

The COVID-19 vaccine or an approved exemption is currently only required for individuals working in a clinical setting. For more information on the University or Hospital policies, including exemptions, please see our website.

Emory University is dedicated to providing equal opportunities and equal access to all individuals regardless of race, color, religion, ethnic or national origin, gender, genetic information, age, disability, sexual orientation, gender identity, gender expression, and veteran's status. Emory University does not discriminate in admissions, educational programs, or employment on the basis of any factor stated above or prohibited under applicable law. Students, faculty, and staff are assured of participation in University programs and in the use of facilities without such discrimination. Emory University complies with Executive Order 11246, as amended, Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veteran's Readjustment Assistance Act, and applicable executive orders, federal and state regulations regarding nondiscrimination, equal opportunity and affirmative action. Emory University is committed to achieving a diverse workforce through application of its affirmative action, equal opportunity and nondiscrimination policy in all aspects of employment including recruitment, hiring, promotions, transfers, discipline, terminations, wage and salary administration, benefits, and training. Inquiries regarding this policy should be directed to the Emory University Department of Equity and Inclusion, 201 Dowman Drive, Administration Building, Atlanta, GA 30322.

Emory University is committed to providing reasonable accommodations to qualified individuals with disabilities upon request. To request this document in an alternate format or to request a reasonable accommodation, please contact the Department of Accessibility Services at 404-727-9877 (V) | 404-712-2049 (TDD). Please note that one week advance notice is preferred.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed

Connect With Us!