Cloud Security Specialist
SoftheonAbout the role
Job Title: Cloud Security Specialist
Job Location: Remote
About us:
Softheon is a dynamic and forward-thinking Software as a Service (SaaS) organization that is dedicated to ensuring affordable, accessible, and plentiful healthcare for every American. We are a pioneering force in the healthcare technology industry, driven by our mission to empower individuals and organizations with innovative solutions that transform the healthcare landscape. Our commitment to improving healthcare access and delivery is unwavering, and we are looking for top-tier talent to join our journey and contribute to our vision. If you're seeking an environment where your contributions are impactful and deeply valued, don't just join a company with ambition. Align with a purpose backed by a committed company.
Our Company Culture:
Our culture is built on collaboration, innovation, and appreciation. We value each employee's unique talents and contributions and understand that every individual plays a critical role in our mission to transform healthcare. Every day, we celebrate our team's dedication, creativity, and expertise, which drive us closer to our goals.
At Softheon, Our Mission is powering growth to make healthcare more productive, intelligent, and successful. Our Vision is Making healthcare affordable, accessible, and plentiful for every American.
About the role:
This role demands strong collaboration with cross-functional teams, ensuring the seamless integration of security practices across all cloud services, including IaaS, PaaS, and SaaS.
The Cloud Security Specialist will also develop and enforce security policies, monitor cloud configurations, respond to threats, and automate security processes, ensuring compliance with industry regulations such as HIPAA. This role is crucial for enhancing our organization's overall security posture and supporting our business goals through proactive cloud security measures.
Requirements
You will:
Cloud Security Management:
Design and implement cloud security frameworks: Architect and deploy robust security controls for Azure-based cloud infrastructure, ensuring alignment with organizational security policies and standards.
Cloud configuration and hardening: Review and improve security configurations for Azure services, ensuring appropriate access control, encryption, and security monitoring.
Policy management and enforcement: Define and enforce security policies for cloud usage, ensuring that data is protected, encrypted, and appropriately monitored.
Continuous security assessments: Perform regular security audits of cloud environments, including vulnerability scanning and penetration testing, to identify and mitigate risks.
Threat Management:
Incident detection and response: Act as the primary point of contact for cloud security incidents. Lead efforts to contain, investigate, and remediate breaches or threats.
Proactive threat hunting: Conduct threat-hunting activities within Azure cloud environments to uncover potential risks and misconfigurations before they lead to security incidents.
Security event correlation: Leverage tools like Microsoft Sentinel to correlate security events and detect abnormal patterns in network and system activity.
Forensics and root cause analysis: In the event of a security breach, perform forensic analysis to determine the cause and prevent future occurrences.
Compliance & Governance:
HIPAA, SOC, and PCI audit preparation: Lead efforts to ensure the cloud environment meets regulatory requirements and is fully prepared for external and internal security audits.
Cloud security governance: Develop and enforce governance frameworks to ensure ongoing compliance with security standards and legal requirements (e.g., HIPAA, GDPR, SOC 2).
Third-party vendor risk management: Assess the security posture of third-party vendors, ensuring that their practices meet compliance and security requirements when integrating with the organization’s cloud systems.
Security Tools & Technologies:
Security automation: Automate repetitive security tasks using tools like Microsoft Azure Security Center, Microsoft Defender, and Sentinel to improve operational efficiency.
Zero Trust architecture: Design and implement a Zero Trust security model within the Azure environment, ensuring secure access to resources.
Continuous securi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s