Cloud Security Analyst II
CongaUSA1w ago
Job description
About the role
Conga is seeking a Cloud Security Analyst II to join their growing team and play a critical role in safeguarding the company's cloud-based infrastructure and software platforms. This position is centered on monitoring, analyzing, and responding to security events that occur across distributed cloud environments. The analyst will partner with engineering, operations, and development teams to maintain a strong and proactive security posture for all cloud-hosted services. This is a hands-on individual contributor role that demands both deep technical expertise and the ability to translate complex security findings into clear, actionable recommendations for a variety of stakeholders.
Key facts
What you'll do
- Monitor cloud environments continuously for security threats, anomalies, and indicators of compromise on a daily basis.
- Analyze incoming security alerts and determine the severity, scope, and potential business impact of each detected incident.
- Investigate suspicious activity within cloud infrastructure, virtual machines, and application workloads to identify root causes and attack vectors.
- Collaborate closely with development and engineering teams to identify and remediate security vulnerabilities found in cloud deployments.
- Maintain and regularly update security policies, standard operating procedures, and technical documentation covering all cloud services.
- Conduct periodic security assessments, configuration reviews, and automated vulnerability scans across all cloud-hosted systems and applications.
- Respond to confirmed security incidents by following established incident response playbooks, escalation paths, and containment procedures.
- Provide internal guidance, training sessions, and reference materials to team members on cloud security best practices and trends.
- Review user access controls, role-based permissions, and privilege assignments to ensure least-privilege principles are consistently applied.
- Coordinate with external third-party vendors and business partners on cloud security assessments, audits, and shared threat intelligence.
- Document all investigation findings, remediation actions, and lessons learned in the centralized incident tracking and reporting system.
- Participate in post-incident reviews and contribute to improving detection rules, response procedures, and overall cloud security architecture.
Requirements
- Bachelor's degree in computer science, information technology, cybersecurity, or a closely related technical discipline is required.
- A minimum of three years of professional experience in cloud security, information security, or a comparable role.
- Demonstrated strong understanding of major cloud platforms including Amazon Web Services, Microsoft Azure, or Google Cloud Platform.
- Hands-on experience with security information and event management platforms, log aggregation tools, and threat detection workflows.
- Solid knowledge of network security protocols, firewall configurations, intrusion detection systems, and endpoint protection solutions.
- Proven ability to analyze large volumes of system logs, telemetry data, and network traffic to identify potential threats.
- Familiarity with recognized security frameworks and compliance standards such as NIST, ISO 27001, or SOC 2 Type II.
- Outstanding written and verbal communication skills with the ability to report findings clearly to both technical and business audiences.
- Experience working with ticketing systems and case management tools to track security incidents from detection through resolution.
- Strong attention to detail and the ability to manage multiple concurrent security investigations in a fast-paced environment.
Nice to have
- Prior experience with infrastructure as code tools such as Terraform, CloudFormation, or Ansible for provisioning cloud resources.
- Active professional certifications including AWS Security Specialty, Certified Information Systems Security Professional, or Certified Cloud Security Professional.
- Previous work experience in a regulated industry such as healthcare, financial services, or government contracting environments.
- Working knowledge of container security, Kubernetes cluster hardening, and securing orchestration platforms in production deployments.
- Familiarity with DevSecOps methodologies and integrating security checks into continuous integration and continuous delivery pipelines.
Skills & tools
- Demonstrated proficiency with Amazon Web Services, Microsoft Azure, or Google Cloud Platform and their native security features.
- Practical experience with SIEM platforms including Splunk, Microsoft Sentinel, IBM QRadar, or comparable enterprise solutions.
- Familiarity with vulnerability assessment and scanning tools such as Nessus, Qualys, Tenable, or similar industry-standard products.
- Comfort and competence with scripting and automation languages including Python, PowerShell, or Bash for security tasks.
- Solid understanding of identity and access management systems, single sign-on protocols, and multi-factor authentication mechanisms.
- Working knowledge of containerization technologies including Docker, Kubernetes, and related orchestration and security tooling.
- Experience with cloud-native security tools such as AWS GuardDuty, Azure Sentinel, or Google Security Command Center.
Practical notes
- This position is physically based in either Boston, Massachusetts or Houston, Texas, and is not a remote role.
- Candidates should expect to work standard full-time business hours, with the possibility of on-call rotations for after-hours incident response duties.
- The role requires regular and ongoing collaboration across multiple internal teams, including engineering, product, operations, and executive leadership.
- All applicants must be currently authorized to work in the United States on a full-time basis without the need for visa sponsorship or relocation support.
- The hiring process may include technical interviews, a practical security assessment, and reference checks with previous employers or managers.