Greetings from Pan Asia Software Solutions!!!
We have an Immediate Opening AWS Cloud SDM with our reputed Client.
Client Location KL Malaysia
Experience: 5+ years
Responsibilities:-
- To cover Cloud Security which including the following responsibilities:
- Identity and Access Management (IAM):
a. Provide two (2) dedicated personnel for IAM operational work.
b. Manage IAM users, including creation, modification, deletion, and security credentials such as MFA, keys, password resets.
c. Assign permissions and roles to users based on least privilege principles and Zero Trust principles.
d. Create and manage IAM roles for users, services, applications, and cross-account access.
e. Write, attach, and regularly review custom IAM policies for security and compliance.
f. Use AWS CloudTrail to monitor and audit IAM activities, such as logins and role and/or policy changes.
g. Secure and manage AWS root accounts with MFA and robust password policies.
h. Manage encryption keys using AWS Key Management Service for data security.
i. Organize AWS accounts with AWS Organizations, applying Service Control Policies (SCPs) for governance.
- j. Regular auditing and pruning of Ghost Account or over-privileged roles to ensure Least Privilege.
- k. Verified that the two (2) dedicated personnel for IAM operational work hold the required certification as stipulated under Schedule D of this Agreement.
Cyber Assurance (CA):
- a. Provide two (2) dedicated personnel for consultation and document reviews.
- b. Implement AWS security controls and policies to meet compliance with applicable laws and standards in accordance with this Agreement which shall also include but not limited to NIST, Payment Card Industry Data Security Standard (PCI DSS) and ISO 27001.
- c. Assist in audits and provide evidence for Information Security Management System (ISMS), PCI DSS, and compliance audits.
- d. Conduct Cyber Security Risk Assessments (CSRA) and configure workloads to meet the Client’s requirements.
- e. Evaluate third-party security posture and manage risks with tools like AWS Audit Manager.
- f. Provide comprehensive security reporting and metrics such as posture dashboards and compliance metrics
- g. Establish security policies, SOPs, and governance tools such AWS Configuration for compliance monitoring.
- h. Verified that the two (2) dedicated personnel hold the required certification as stipulated under Schedule D of this Agreement.
- i. Incorporate the disaster recovery protocols and backups integrity (immutability)
- j. Ensure any audit scope covers pipeline security, including secret scanning and container image signing.
- k. Obtain the mandatory monthly compliance reports from the Service Provider, specifically mapped to the gap matrix.
Cloud Security Threat Detection (CSTD):
- a. Monitor AWS CloudTrail, GuardDuty, and Security Hub for threat detection.
- b. Analyze security metrics and investigate alerts for unauthorized activities or vulnerabilities.
- c. Automate security responses such as isolating resources, disabling accounts using AWS Lambda.
- d. Use Amazon Macie for sensitive data monitoring and Amazon Inspector for vulnerability analysis.
- e. Collaborate on Level 1 Support, Level 2Support, and Level 3 Support incident responses, including penetration testing and remediation actions.
- f. Integrate AWS threat intelligence with third-party platforms for enriched detection capabilities.
- g. Ensure audit scope covers pipeline security, including secret scanning and container image signing.
- h. Verified that the two (2) dedicated personnel holds the required certification as stipulated under Schedule D of this Agreement.
- i. Monitor outbound traffic for data exfiltration patterns and communication with malicious the intrusion Prevention System (IPS).
- j. To include Operating System (OS) level and container scanning for Elastic Compute Cloud (EC2) and Elastic Kubernetes Services (EKS) or Elastic Container Service (ECS).Security Operations (SecOps):
- i. Deploy and maintain security infrastructure such asfirewalls, Endpoint Detection and Response (EDR), Web Application Firewall (WAF), Distributed Denial of Service (DDoS) protection.
- ii. Monitor traffic patterns and implement alarms for anomaly detection.
- iii. Collaborate with Client’s internal stakeholders to expedite security incident resolution and ensure the SLA under this Agreement is duly complied.
- iv. Provide twenty-four (24) x seven (7) and auto-remediation for security incidents, addressing misconfigurations, vulnerabilities, and application risks.
- v. Mentor and transfer knowledge to internal teams on AWS infrastructure and security
tools.
- vi. Verifiy that the two (2) dedicated personnel hold the required certification as stipulated under Schedule D of this Agreement
- vii. To incorporate disaster recovery protocols and backups integrity (immutability) into the four security pillars.
- viii. To include OS-level and container scanning for EC2 and EKS/ECS environments.
- ix. To perform annual ‘mock’ security breach exercise led by the Service Provider to validate the backup/disaster recovery plan
- x. To implement automated guardrails for common misconfiguration such as auto remediating public S3 buckets. S3 buckets means a storage container within AWS Simple Storage Service (“S3”) provided by for storing data objects and associated access controls
Qualification:-
- AWS Certified Security Specialty and;
- Certification in CISSP, CISM or Security+ And
- Minimum of five (5) years relevant experience in any Cloud related services.
- Microsoft Certified: Azure Security Engineer Associate and;
- Certification in CISSP, CISM or Security+ And
- Minimum of five (5) years relevant experience in any Cloud related services.
Interested Share updated resume to ************* or Watsapp: +************* along with below details
Current Salary:
Expected Salary:
Notice Period:
Total Exp:
Relevant Exp:
{Note: if it doesn't suit you, please refer your matching friends or kindly ignore it}
Nithya Senior IT Talent Acquisition Specialist
HP : +************* 0562
Pay: RM7,000.00 - RM10,000.00 per hour
Work Location: In person