- Salary
- $160k – $185k
- Location
- PSC003, United States of America
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Experience
- 7+ years
- Source
- Workday
Description
The Aspen Group (TAG) is one of the largest and most trusted retail healthcare business support organizations in the U.S. and has supported over 20,000 healthcare professionals and team members with close to 1,500 health and wellness offices across 48 states in four distinct categories: dental care, urgent care, medical aesthetics, and animal health. Working in partnership with independent practice owners and clinicians, the team is united by a single purpose: to prove that healthcare can be better and smarter for everyone. TAG provides a comprehensive suite of centralized business support services that power the impact of five consumer-facing businesses: Aspen Dental, ClearChoice Dental Implant Centers, WellNow Urgent Care, Chapter Aesthetic Studio, and Lovet. Each brand has access to a deep community of experts, tools and resources to grow their practices, and an unwavering commitment to delivering high-quality consumer healthcare experiences at scale.
Job Description:
The Senior Cloud Security Engineer architects, deploys and operates a secure cloud application infrastructure that aligns with business needs. The position owns the technical direction of cloud security controls and sets the standards that product and engineering teams build against. The senior cloud security engineer is expected to resolve ambiguous problems independently, act as the senior technical escalation point for cloud security, and raise the technical bar of the team. The role requires depth across disparate applications and data systems, along with ownership of policy design, guardrail engineering and ongoing maintenance.
This is a single, dedicated cloud security function serving a multi-brand business. The engineer works across multiple brands and business units, each with its own cloud footprint and maturity level, and is responsible for bringing consistent security across all of them.
Acting as a technical peer to security leadership, the senior cloud security engineer drives assessment of the cloud threat landscape and translates it into a prioritized control roadmap. The role is highly technical and requires at least 7 years of experience in security and systems administration across a wide variety of cloud infrastructure, including software as a service (SaaS), infrastructure as a service (IaaS) and platform as a service (PaaS). A strong work ethic, analytical and critical thinking, and the ability to meet change requests at a moment’s notice are expected. Because the role interfaces regularly with other business units and serves as a design authority, strong listening and communication skills are essential. This is an individual contributor role with no direct reports, and it carries a standing expectation of technical leadership and mentorship.
Essential Job Duties:
Architecture and Engineering
- Define and maintain the cloud security baseline and reference architectures across public, private and hybrid cloud infrastructure, and own the assessment program that measures resource architecture and configuration against them.
- Establish and hold a consistent set of cloud security standards across all brands and business units, accounting for differing cloud footprints and maturity levels.
- Plan, implement, automate and operate cloud security controls across SaaS, IaaS and PaaS environments, including strong identity and access management (IDAM) controls.
- Design and deliver production quality tooling, dashboards, automation and policy as code that improve cloud security posture and make secure configuration the default for product, application and development teams.
- Carry proof of concept work through to production ownership, and own the automation and integration code that supports it, including scripts for custom extract, transform, load (ETL) work with a security focus for data flow.
Detection and Response
- Respond to and investigate cloud security alerts raised by the SOC and detection teams, taking cloud originated incidents through deeper investigation, containment and resolution, and serving as senior escalation for cloud specific detections.
- Design detection content and log pipelines that give security operations usable visibility into cloud and SaaS activity.
- Lead post incident review for cloud incidents and drive the resulting control changes to closure, with strict documentation and reporting.
Advisory and Governance
- Serve as security design authority in architecture review, project and change management forums, and act as the escalation point for product and development teams on cloud security design decisions.
- Protect business applications in compliance with privacy, security, business resiliency and compliance frameworks as defined in corporate policies, and translate those frameworks into enforceable technical guardrails and evidence.
- Own the remediation program following security assessment findings, set priority based on risk, and hold owning teams to committed dates.
- Lead security assessment of cloud vendors and third party integrations, and own the escalation path to security management and business unit leads when material risk is discovered.
- Assess the cloud threat landscape and translate it into a prioritized control roadmap, including build versus buy evaluation and tool selection. Stay apprised of current and proposed changes to regulatory, privacy and security industry guidance, and apply that knowledge across key lines of business.
Program Leadership
- Own the cloud security program roadmap across all brands and drive measurable improvement in overall cloud security maturity over time.
- Author and maintain the cloud security policy, standard and process library, keeping it current as the environment, the brands and the threat landscape evolve.
- Maintain a cloud security risk register that tracks risks, owners and remediation status across the business.
- Define cloud security KPIs and posture metrics, and report them to security leadership on a regular cadence.
- Establish and run the operating model for cloud security across the organization, partnering directly with each brand's engineering and product leads and participating in architecture and change forums to drive security decisions without direct authority.
- Build and maintain self-service security capabilities for engineering teams, including guardrail documentation, secure-by-default patterns and targeted enablement, so teams can build securely without depending on a single gatekeeper.
Technical Leadership
- Mentor and technically review the work of other engineers, including design review and code review.
- Document and communicate risk and tradeoffs to both engineering and executive audiences, and drive areas of security improvement that balance risk with business operations without diminishing efficiency or innovation.
- Perform other duties as assigned.
Skills and Experience
- At least 7 years of experience in cybersecurity as a practitioner, with at least 4 years of hands on cloud security experience in Google Cloud Platform (GCP), Microsoft Azure, or Amazon Web Services (AWS). Depth in one platform with working knowledge of the others is expected.
- Experience delivering cloud security in a regulated environment, healthcare preferred.
- Deep hands on experience with cloud native application protection platform (CNAPP) and cloud security posture management (CSPM) solutions.
- Experienced in cloud networking architecture and cloud operations. SaaS security posture management and cloud access security broker (CASB) experience preferred.
- Infrastructure as code experience, including a cross platform tool such as Terraform and the native option for at least one cloud, along with infrastructure as code security scanning.
- Policy as code and preventative guardrail experience using native cloud policy engines and open policy frameworks.
- Continuous integration and continuous delivery pipeline security and software supply chain security experience, including secrets management with a cloud native or third party vault, and practical use of Git based workflows and a pipeline platform.
- Demonstrated experience securing container and Kubernetes workloads, including admission control, image scanning and runtime protection.
- Security information and event management (SIEM) and detection engineering experience, including log pipeline design and correlation content authoring.
- Cloud identity depth beyond OAuth and OpenID, including conditional access, workload and federated identity, and privileged access management.
- Network and encryption experience, including virtual private networks (VPNs), IPsec, SSL/TLS, LDAP and public key infrastructure (PKI).
- Data security and data loss prevention experience across cloud and SaaS environments.
- Exposure to securing artificial intelligence and large language model workloads.
- Proficient in Python and PowerShell, writing maintainable code and working in version control with peer review.
- Able to read and reason about cloud automation and configuration (for example Terraform, YAML and JSON) well enough to review it from a security perspective and collaborate with engineering teams on guardrails.
- Comfortable operating inside developer workflows, including pull request and code review, branching strategies, and modern software development lifecycle and DevOps practices, so security is embedded in how teams already build rather than bolted on afterward.
- Experienced in the use of threat intelligence services in a production environment.
- Experience and understanding of various regulatory requirements and laws, including but not limited to: Payment Card Industry (PCI), Health Insurance Portability and Accountability Act (HIPAA). Additionally, experience in one or more of the following: ISO 27001/2, CIS, ITIL or NIST.
- Up to date understanding of a wide range of incident response, system configuration, vulnerability management and hardening guidelines.
- Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively.
- Demonstrated experience delivering security consistently across multiple business units, brands or independently run environments.
Additional Qualifications:
- Demonstrated problem solving ability on complex and ambiguous security requirements with limited direction.
- Ability to influence without authority across engineering, product and business organizations.
- Self motivated and self directed, well organized, and able to position controls in anticipation of threats.
- Successful track record collaborating with technical and non technical teams to promote ideas that support business enablement.
- Familiarity with United States federal and state privacy laws.
- Experience writing technical documentation.
Education Requirements:
- Bachelor’s degree in computer science, information assurance, MIS or related field. Equivalent industry experience is fully acceptable in place of a degree.
Experience Requirements:
- 7+ years of related experience required, including at least 4 years of hands on cloud security experience.
Certification Requirements:
- One or more of the following preferred: CCSP, CISSP, Google Professional Cloud Security Engineer, Microsoft Certified Azure Security Engineer Associate (AZ-500), AWS Certified Security Specialty, or GIAC GCSA, GPCS or GCLD.
Annual Salary Range: $160,000-$185,000/year, with a generous benefits package that includes paid time off, health, dental, vision, and 401(k) savings plan with match.
If you are an applicant residing in California, please view our privacy policy here: https://careers.aspendental.com/us/en/tag-privacy-policy-for-california-employees