01Responsibilities
Monitor Azure Defender and Optum Security Platform to identify vulnerabilities, misconfigurations, and security risks across cloud, infrastructure, and application environmentsTriage security findings and determine appropriate remediation paths, performing hands on remediation when within scope and creating actionable work items for development teams when code level fixes are requiredOversee remediation efforts by development teams to ensure application functionality while maintaining industry best level security practicesPerform direct remediation of cloud, infrastructure, and configuration issues, including production environments when appropriate and in accordance with change and risk management practicesReview application level security findings and apply secure coding knowledge to assess severity, validate findings, and recommend remediation approaches aligned with security best practicesTrack, manage, and report vulnerability remediation efforts to ensure compliance with defined SLAs, release timelines, and enterprise security mandatesAttend ESRO public cloud monthly calls and manage follow up work resulting from new security publications, standards, and Optum wide mandatesCoordinate security remediation work with Product Owners, Scrum Masters, and Release Engineers to plan releases and hotfixes, balancing risk reduction with delivery commitmentsCommunicate security risks, remediation status, and release impacts clearly to technical and non technical stakeholders, providing guidance on secure design and implementation where neededComply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do soRequired Qualifications:
Undergraduate degree or equivalent experience4+ years combined experience in cloud security, secure code development, and/or Azure Cloud engineering supporting large-scale production enterprise environments2+ years of hands on experience securing Microsoft Azure environments, including Microsoft Defender for Cloud (Azure Defender), Azure resource configuration, identity, networking, and remediation of cloud security risks and misconfigurationsHands-on experience performing direct remediation of security issues, including cloud configuration fixes, infrastructure hardening, policy enforcement, and production changes following change, risk, and RRB approval processesHands-on experience using GitHub for source control, including creating, reviewing, and merging pull requests in accordance with security and change standardsExperience using enterprise security platforms such as the Optum Security Platform or equivalent tools for vulnerability detection, risk tracking, and remediation managementExperience with enterprise application development languages and technologies such as Java, C#, and REST based services deployed in cloud environmentsExperience working with GitHub Actions or similar CI/CD tooling to support secure build, validation, and deployment workflowsExperience tracking vulnerability remediation against defined SLAs, release timelines, and enterprise security mandatesPractical experience reviewing, understanding, and modifying application code to assess security findings and recommend or implement secure remediation approaches Familiarity with Agile/Scrum delivery models and coordinating security work with Product Owners, Scrum Masters, Release Engineers, and change approversSolid working knowledge of application security best practices and common vulnerability classes, including authentication and authorization flaws, secrets management, input validation, injection risks, and secure dependency managementProven ability to triage security findings across cloud, infrastructure, and application layers and determine appropriate remediation paths independentlyProven ability to create clear, actionable remediation work items for development teams when .