Senior Cloud Security Expert for AWS & Snowflake
New Era TechnologyAbout the role
Join New Era Technology, where People First is at the heart of everything we do. With a global team of over 4,500 professionals, we’re committed to creating a workplace where everyone feels valued, empowered, and inspired to grow. Our mission is to securely connect people, places, and information with end-to-end technology solutions at scale.
At New Era, you’ll join a team-oriented culture that prioritizes your personal and professional development. Work alongside industry-certified experts, access continuous training, and enjoy competitive benefits. Driven by values like Community, Integrity, Agility, and Commitment, we nurture our people to deliver exceptional customer service.
If you want to make an impact in a supportive, growth-oriented environment, New Era is the place for you. Apply today and help us shape the future of work—together.
SUMMARY: Client requires a AWS Snowflake Security Expert to lead and execute a NIST SP 800-53 Rev 5 moderate-baseline cybersecurity assessment of a multi-account Snowflake data-warehouse deployment on AWS, producing a security assessment report with findings and recommendations.
PRIMARY DUTIES:
- Planning & Scoping
- Facilitate scoping workshop and interviews with the IAM Lead, Cloud Security Engineering, Site Reliability Engineering, Snowflake DBA Team, Network Security Engineering, IT GRC, Security Engineering, Security Architecture, Internal Audit, Security Operations, Vulnerability Management, Application Security, Red Team and Threat Hunting
- Select applicable NIST control baseline and overlays (HIPAA, CJIS, PCI-DSS, FedRAMP Moderate).
- Create detailed assessment plan & schedule
- Execute the Security Assessment
- Identity & Access
- Inventory AWS IAM roles, SCPs, KMS key policies, IAM Identity Center mappings.
- Map to Snowflake RBAC objects (users, roles, warehouses, resource monitors) and test separation-of-duties matrix.
- Validate MFA, Private link DNS, key-rotation cadence, IdP claims.
- Encryption & Data Protection
- Inspect column-level encryption keys, tri-secret strategy, dynamic data-masking policies, secure data-sharing agreements, and customer-managed KMS versus Snowflake-managed keys.
- Logging & Monitoring
- Ensure CloudTrail org-trail + S3 object-lock is present; validate Snowflake Access History & Account Usage retention ≥ 1 year.
- Gather custom metrics in CloudWatch and Snowflake Resource Monitor alerts.
- Test log integrity (KMS-MAC signatures) and SIEM onboarding (Splunk, Sentinel, or Elastic).
- Network & Segmentation
- Review VPC design, Transit Gateway attachments, Security Groups, NACLs, Guard Duty, and Private Link endpoint policies.
- Obtain TLS version scan against *.snowflakecomputing.com endpoints.
- Vulnerability & Configuration
- Execute vulnerability reports reviews; run Inspector & Qualys against EC2 bastions.
- Validate Snowflake parameter drift and golden-Terraform state alignment.
- Incident Response & Contingency
- Verify runbooks for session kill, key rotation, and account failover scripts.
- Governance & Supply-Chain
- Evaluate Snowflake FedRAMP package, SOC 2 Type II, AWS Artifact docs, partner-connect integrations, and data-processing addendums (DPAs) for GDPR/CCPA
- Identify third party governance for Snowflake and related vendors (e.g., API gateways, etc.) is in place
COMP
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s