What are the responsibilities and job description for the Cloud Security Engineer position at RIT Solutions, Inc.?
Title : Cloud Security Engineer
Domain : Retail
Location : Chicago, IL. Must be onsite Tue-Thurs every other week.
Scope of Work : The Cloud Security Engineer will work closely with the Integration Modernization team to design, implement, and monitor security measures across various integration tools. They will ensure the integrity, confidentiality, and availability of data as it flows between systems. The security engineer will also assist in defining policies and best practices for integrating TIBCO, APIGEE, Kafka, and any future tools. This role will involve both strategic planning and tactical implementation.
Key Responsibilities :
- Security Assessment and Risk Management :
- Conduct security risk assessments for integration tools (TIBCO, APIGEE, Kafka, etc.)
- Identify and mitigate potential vulnerabilities in cloud-based architectures.
- Ensure proper encryption and key management protocols are in place.
- Architecture and Design :
- Collaborate with solution architects to design secure integration architectures, ensuring proper authentication, authorization, and data protection across the platforms.
- Work with cross-functional teams to integrate security into DevOps pipelines, CI / CD workflows, and API lifecycle management.
- Tool and Platform Security :
- Ensure security configurations of TIBCO, APIGEE, Kafka, and other integration tools are aligned with industry standards and organizational policies.
- Manage security integrations with the client's identity management systems.
- Monitoring and Incident Response :
- Set up continuous monitoring for security events and anomalies across the integration platforms.
- Respond to security incidents and provide remediation guidance in the event of breaches or vulnerabilities.
- Compliance and Auditing :
- Ensure compliance with relevant industry standards and regulations (e.g., GDPR, HIPAA, SOC 2, etc.) for the tools and services in use.
- Conduct regular audits of security controls and recommend improvements as needed.
- Documentation and Knowledge Transfer :
- Maintain up-to-date security documentation for each platform transferring monitoring and incident response to the Security Operations Center.
- Conduct knowledge transfer sessions for the wider IT and security teams to ensure ongoing security practices are followed.
Skills and Experience Required : The ideal candidate will have a combination of the following skills and experience :
Technical Skills :
Experience :