Jobs and Careers
EY

GPS - Network Security Cloud Engineer - Supervising Associate

EY
Alpharetta, United Statesfull_timeVerifiedPosted 28 Jan 2025
💰 $186,400/yr($87,700/yr$186,400/yr)

About the role

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better. Join us and build an exceptional experience for yourself, and a better working world for all.   The exceptional EY experience. It's yours to build.   EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.  

From strategy to execution, the Government & Public Sector (GPS) practice of Ernst & Young LLP provides a full range of consulting and audit services to help our Federal, State, Local and Education clients implement new ideas to help achieve their mission outcomes. We deliver real change and measurable results through our diverse, high-performing teams, quality work at the highest professional standards, operational know-how from across our global organization, and creative and bold ideas that drive innovation. We enable our government clients to achieve their mission of protecting the nation and serving the people; increasing public safety; improving healthcare for our military, veterans and citizens; delivering essential public services; and helping those in need. EY is ready to help our government build a better working world. 

 

Our GPS Technology Organization is a structure within the US GPS practice that implements and maintains a new operate and technology model designed specifically to support U.S. defense and Government engagements.

 

The opportunity

We are seeking a highly skilled and motivated Network Security Engineer to join our team. The ideal candidate will have extensive experience in managing and securing cloud environments, specifically within Azure Cloud in the Azure.gov space.

 

As the Network Security Engineer, you will focus on securing the cloud network infrastructure, ensuring compliance with security standards, detecting vulnerabilities, and responding to security incidents. You will be responsible for ensuring compliance with 800-53 and 800-171 security controls, maintaining FedRAMP and CMMC certifications and collaborating closely with Cloud Network Engineers.

 

In short, ensure the network infrastructure within our cloud is robust, secure, and compliant, while maintaining optimal performance and scalability.

 

Your key responsibilities

 

Secure Network Architecture

Collaborate with the Cloud Network team and other stakeholders in configuring and securing the following:
• Designing secure and scalable network infrastructures in the cloud.
• Implementing secure Virtual Private Clouds (VPCs), subnets, and routing configurations.
• Managing and securing communication between on-premises and cloud environments (e.g., via VPNs, Direct Connect, or ExpressRoute).

Cloud Security Implementation
• Configuring and managing security groups, firewalls, and access control lists (ACLs).
• Enforcing zero-trust network access principles.
• Work with the Cloud Network Engineering teams to Implementing encryption for data in transit and at rest.

Threat Detection and Response
• Monitoring network traffic for anomalies or malicious activity.
• Setting up intrusion detection and prevention systems (IDS/IPS).
• Responding to network security incidents and performing root cause analysis.

Identity and Access Management (IAM)
• Work with the IAM team with implementing role-based access control (RBAC) for cloud network resources.
• Managing identity federation and secure access to cloud services.
• Ensuring least-privilege access for network users and services.

Automation and Infrastructure as Code (IaC)
Collaborate with the Cloud Network team and other stakeholders in configuring and securing the following:

  • Automating network security configurations using tools like Azure devops, Bicep, Terraform, CloudFormation, or Ansible.
  • Consult cloud engineering on security controls and collaborate on final product designs from a network security perspective.
  • Validating secure configurations of IaC templates.

 

Compliance and Risk Management

  • Ensuring compliance with regulations and standards (CMMC, FedRAMP).
  • Conducting regular network security audits and risk assessments.

 

Securing Cloud-Specific Services

  • Collaborate with the Cloud Network team and other stakeholders in configuring and securing the following:
  • API Gateways, Load Balancers, and DNS services.
  • Managing endpoint security for cloud-native

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

EY

View company profile →