Shutterstock is looking to hire a skilled Cloud Security Engineer (Detection & Response) to be part of our Cybersecurity Operations & Incident Management team. As a Cloud Security Engineer on the team, you will collaborate with other security & infrastructure teams on identifying & remediating suspicious activities in our environment while improving visibility/governance & implementing AWS security best practices. The ideal candidate will possess a strong background in security engineering & automation to apply this experience in the cloud.
Responsibilities of this role include, but are not limited to, the following activities:
- Identify AWS Security gaps & implement AWS security best practices for our cloud environment (Security Groups, VPC Design, S3 Buckets, IAM Roles, etc.)
- Work closely with Security & Infrastructure groups to create, test & deploy threat detection analytics for our environment.
- Collaborate with engineering & product teams to help define security requirements & architectures.
- Build, improve & automate operational tooling & workflows using a reliable software language such as Python
- Create & maintain comprehensive documentation related to AWS Security & Incident Response
- Review alerts & data from systems/networks & respond accordingly, including documentation & escalation
- Develop tactical response procedures for security incidents
- Perform security monitoring, security event triage, & incident response; coordinate with other team members & management to document & report incidents
- Due to the necessary technical support duties of this position in a 24/7 operation, candidate will be part of rotating shifts & will be required to work periodic weekends and/or nights/evenings
Skills & Experience:
- 5+ years of experience in evaluating technical designs & functional requirements in order to determine weaknesses in security. The candidate must be able to provide constructive feedback & achievable recommendations.
- Required industry security certification (e.g., CISSP, CISM, CISA, CCSP, etc.)
- Operational experience with network security appliances with a clear understanding of the architecture behind secure networks, DMZs, NATs, rule placement, VPN setup, & system maintenance
- Hands-on experience with Cloud technologies & cloud networking constructs AWS Preferred (EC2, ELB, RDS, Route53, CloudFront, S3)
- Experience with attacks & mitigation methods, working in two or more of the following: Network protocols & secure network design; Operating system internals & hardening (e.g. Windows, Linux, OS X, Android); Web application & browser security; Security assessments & penetration testing; Authentication & access control; Applied cryptography & security protocols; Security monitoring & intrusion detection, Incident response & forensics; Development of security tools, automation or frameworks
- Strong organizational & project management skills
- Proven ability to develop effective partnerships with senior management & peer organizations. Must be able to explain technical concepts & problems to nontechnical senior executives effectively
- Strong written & verbal communication skills. Strong interpersonal skills, resourceful, responsive with strong follow through
We are one team collectively focused on creating an unrivaled experience for our Customers & Contributors. Our principles represent the mindset of the employee who will thrive at Shutterstock. If you are passionate about what you do, & want to become part of a cutting-edge technology company building industry leading products, please apply.
Shutterstock (NYSE: SSTK), directly & through its group subsidiaries, is a leading global provider of high-quality licensed photographs, vectors, illustrations, videos & music to businesses, marketing agencies & media organizations around the world. Working with its growing community of over 1 million contributors, Shutterstock adds hundreds of thousands of images each week, & currently has more than 330 million images & more than 18 million video clips available.
Headquartered in New York City, Shutterstock has offices around the world & customers in more than 150 countries. The companys brands also include Bigstock, a value-oriented stock media offering; Shutterstock Custom, a custom content creation platform; Offset, a high-end image collection; PremiumBeat, a curated royalty-free music library; & Shutterstock Editorial, a premier source of editorial images for the world's media.
For more information, please visit www.shutterstock.com & follow Shutterstock on Twitter & on Facebook.
Equal Opportunity Employer, M/F/D/V