Cybersecurity Engineer II
Atlantic Health SystemAbout the role
Job Description
The Cybersecurity Engineer II – Cloud Security and Identity is responsible for helping secure the organization's cloud environments and the identities that access them. This role focuses primarily on cloud security engineering and operations—with an emphasis on Amazon Web Services (AWS), supported by Microsoft Azure and Microsoft 365, and using a cloud-native application protection platform (CNAPP) such as Wiz to maintain visibility into cloud configuration, workload, data, and permission risk. Alongside this cloud focus, the Engineer II supports enterprise identity and access security, with particular attention to Microsoft Entra ID, hybrid Active Directory, conditional access, multifactor authentication, and privileged access. The successful candidate is a well-rounded security practitioner: while cloud and identity are the primary areas of contribution, this role sits on a small, versatile team and requires solid working knowledge across the broader cybersecurity landscape, including vulnerability management, data protection, application security, and endpoint and email security. As with every member of this team, the Engineer II serves as part of a dynamic team responsible for cybersecurity incident response and other cybersecurity initiatives, works to safeguard electronic protected health information (ePHI) and other regulated data, and shares in a rotating on-call schedule.
Duties and Responsibilities
Support the design, implementation, and ongoing operation of security controls across the organization's cloud environments, with a primary emphasis on AWS and additional coverage of Microsoft Azure and Microsoft 365.
Administer, configure, and optimize a cloud-native application protection platform such as Wiz to continuously discover cloud assets, identify misconfigurations, excessive permissions, exposed data, and vulnerable workloads, and surface findings for triage.
Perform risk-based analysis and prioritization of cloud security findings using severity, exploitability, data sensitivity, and business context, and drive remediation to closure in partnership with cloud, infrastructure, application, and vendor teams.
Evaluate cloud environments against recognized benchmarks and best practices—such as the CIS Benchmarks, the AWS Well-Architected Framework security pillar, and internal standards—and track configuration drift and remediation over time.
Support cloud identity and entitlement security, including the review and right-sizing of AWS IAM roles, policies, and permission boundaries, and the reduction of standing and excessive privilege across cloud accounts.
Administer and support Microsoft Entra ID and hybrid Active Directory identity services, including conditional access policies, multifactor authentication, authentication methods, application registrations, and single sign-on integrations.
Configure and operate Microsoft Entra Privileged Identity Management (PIM) and support privileged access practices, just-in-time elevation, and periodic access reviews and certifications for sensitive roles and applications.
Monitor, triage, and investigate cloud and identity security alerts from sources such as Wiz, AWS-native security services (GuardDuty, Security Hub, CloudTrail), Microsoft Defender for Cloud, Microsoft Entra ID Protection, and the enterprise SIEM.
Contribute to secure cloud onboarding and architecture reviews for new cloud services, SaaS applications, and third-party integrations, including evaluation of authentication, authorization, logging, encryption, and data handling.
Maintain familiarity with infrastructure-as-code and container technologies—such as Terraform or CloudFormation templates, CI/CD pipelines, and Kubernetes—sufficient to review security findings in these areas and route them appropriately.
Serve as a well-rounded contributor across the broader security program, assisting with vulnerability management, data protection, application security, and endpoint and email security work as team priorities and organizational risk require.
Serve as part of a dynamic team responsible for cybersecurity incident response, contributing to the detection, triage, investigation, containment, and remediation of security incidents, including cloud and identity-based attacks.
Develop and maintain cloud and identity security metrics,
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s