Cloud Security - Configuration Review, core responsibility overview: It involves examining the settings, configurations, and policies used in the IT environment, identifying potential security gaps and vulnerabilities, and recommending best practices to improve the security posture of the organization. The assets in scope can be (Network appliances, security appliances and popular operating systems such as Microsoft windows, Unix, and Linux), the reviewer is expected to look into configurations, setting as well as the man made rules such as firewall rules or access lists to check for any deviations.
Configuration review process:
- Validate the Scope: Confirm and validate the scope of the assessment, including the systems and devices to be reviewed, the types of configuration settings to be assessed, and any specific security policies and standards that apply.
- Prepare the Assessment Criteria or checklist: Develop assessment criteria and checklist based on vendor best practices, industry standards and applicable client policies and procedures. The standards can include frameworks such as CIS Controls or NIST Cybersecurity Framework.
- Conduct the Assessment: Conduct the assessment, reviewing the configurations of systems and devices against the assessment criteria. This can be done using automated tools, manual review, or a combination of both.
- Identify Findings: Identify any findings or deviations from the assessment criteria. This can include misconfigurations, missing patches, or insecure settings.
- Analyze Findings: Analyze the findings to determine their impact on the security posture of the organization. Prioritize the findings based on the risk they pose to the organization.
- Develop Recommendations: Develop recommendations for remediation of the findings, including specific actions to be taken and timelines for completion.
- Present Findings and Recommendations: Present the findings and recommendations to key stakeholders in the organization.
Overall, a configuration review assessment involves a thorough review of configurations against established criteria and checklist to identify potential security risks and develop recommendations for remediation.
E xperience in the those or similar tools is preferred: Nipper, Tripwire, Qualys, Nessus, Algosec...etc
Role requirements:
- Good understanding and practical experience in infrastructure and Cloud platform security
- Good understanding of Microsoft Sentinel and KQL
- Experience and proven record of success in integrating custom connectors with Sentinel using APIs. If you have no direct experience with Sentinel, individuals with good developer skills will be considered
- Experience with M365 Threat Protection technologies including Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office 365, and Microsoft Defender for Cloud Apps
- Experience with Azure Security technologies including Microsoft Defender for Cloud, Key Vault, Azure DDoS Protection, and other
- Experience with Information Protection technologies such as Azure Information Protection, Windows Information Protection, and Data Loss Prevention
- Hands-on experience establishing and configuring security controls for Microsoft Azure components (i.e. Defender for Cloud, Azure Firewall, Azure DDOS Protection, Azure Bastion and Sentinel)
- Hands-on experience establishing and configuring security controls for Microsoft 365 components (i.e. Microsoft Purview, Defender for Cloud App, Endpoint, Identity and Vulnerability Management)
- Hands-on experience establishing and configuring security controls for general security solution (i.e. Azure Active Directory, Azure Identity Protection and Azure RBAC)
- Experience with compliance technologies including Advanced eDiscovery, Data Retention, and Insider Risk Management
- Experience with Identity technologies including Azure Active Directory P1 & P2
- Familiarity with a programming or scripting languages (esp. in KQL and PowerShell) is a plus
- Familiarity with Power BI, Power Apps, or Power Automate is a plus
- Knowledge of well-known SaaS technologies (i.e. SAP, Oracle) is a plus
- At least 1 year of relevant work experience for Associate grade
- At least 3 years of relevant work experience for Senior Associate grade
- Open minded seeking innovative solutions
- Ability to work within a fast-paced & unstructured environment
- Ability to adapt to and communicate with different working styles
- Ability to interact efficiently with senior members of the firm across multiple time zones
Essential skills & attributes:
- Demonstrates extensive knowledge in infrastructure and cloud security
- Experience in Consulting or in working within multinational environments
- Excellent communication and presentation skills
- High level of customer orientation and a convincing demeanour
- Ability to work within a fast-paced & unstructured environment.
- Must be able to multi-task and effectively and continually prioritise
- Excellent oral and written English skills. German language proficiency is a plus
Education
- University degree, ideally in the fields of Computer and Information Science, Business Informatics, Computer Engineering, Cyber Security, Information Technology, Management Information Systems
The following Microsoft certifications are a significant plus:
- Azure Security Engineer Associate (AZ-500)
- Azure Solutions Architect Expert (AZ-303 or AZ-304 or AZ-405)
- Cybersecurity Architect Expert (SC-100)
- Security Operations Analyst Associated (SC-200)
- Identity and Access Administrator Associate (SC-300)
- Information Protection Administrator Associate (SC-400)
Desired Candidate Profile
- At least 1 year of relevant work experience for Associate grade
- At least 3 years of relevant work experience for Senior Associate grade
- Open minded seeking innovative solutions
- Ability to work within a fast-paced & unstructured environment
- Ability to adapt to and communicate with different working styles
- Ability to interact efficiently with senior members of the firm across multiple time zones
- Demonstrates extensive knowledge in infrastructure and cloud security
- Experience in Consulting or in working within multinational environments
- Excellent communication and presentation skills
- High level of customer orientation and a convincing demeanour
- Ability to work within a fast-paced & unstructured environment.
- Must be able to multi-task and effectively and continually prioritise
- Excellent oral and written English skills. German language proficiency is a plus
- University degree, ideally in the fields of Computer and Information Science, Business Informatics, Computer Engineering, Cyber Security, Information Technology, Management Information Systems
- The following Microsoft certifications are a significant plus: Azure Security Engineer Associate (AZ-500), Azure Solutions Architect Expert (AZ-303 or AZ-304 or AZ-405), Cybersecurity Architect Expert (SC-100), Security Operations Analyst Associated (SC-200), Identity and Access Administrator Associate (SC-300), Information Protection Administrator Associate (SC-400)
أمن السحابة - مراجعة التكوين، نظرة عامة على المسؤوليات الأساسية: يتضمن فحص الإعدادات والتكوينات والسياسات المستخدمة في بيئة تكنولوجيا المعلومات، وتحديد الثغرات والمخاطر الأمنية المحتملة، وتوصية أفضل الممارسات لتحسين وضع الأمن في المؤسسة. قد تكون الأصول ضمن النطاق (أجهزة الشبكة، وأجهزة الأمن وأنظمة التشغيل الشائعة مثل Microsoft Windows وUnix وLinux)، من المتوقع أن يقوم المراجع بالنظر في التكوينات والإعدادات وكذلك القواعد البشرية مثل قواعد الجدار الناري أو قوائم الوصول للتحقق من أي انحرافات.
عملية مراجعة التكوين:
- تحقق من النطاق: تأكيد والتحقق من نطاق التقييم، بما في ذلك الأنظمة والأجهزة التي ستتم مراجعتها، وأنواع إعدادات التكوين التي ستُقيَّم، وأي سياسات ومعايير أمان محددة تنطبق.
- إعداد معايير التقييم أو قائمة المراجعة: وضع معايير التقييم وقائمة المراجعة بناءً على ممارسات البائع وأطر الصناعة والسياسات والإجراءات الخاصة بالعميل. يمكن أن تشمل المعايير أطر مثل CIS Controls أو NIST Cybersecurity Framework.
- إجراء التقييم: إجراء التقييم، مراجعة تكوينات الأنظمة والأجهزة مقابل معايير التقييم. يمكن القيام بذلك باستخدام أدوات آلية، مراجعة يدوية، أو مزيج من الاثنين.
- تحديد النتائج: تحديد أي نتائج أو انحرافات عن معايير التقييم. قد تشمل التهيئات الخاطئة، الثغرات المفقودة، أو الإعدادات غير الآمنة.
- تحليل النتائج: تحليل النتائج لتحديد تأثيرها على وضع الأمان في المؤسسة. تحديد أولويات النتائج بناءً على المخاطر التي تشكلها للمؤسسة.
- وضع التوصيات: وضع توصيات للإصلاح استناداً إلى النتائج، بما في ذلك إجراءات محددة وتواريخ لإكمالها.
- عرض النتائج والتوصيات: عرض النتائج والتوصيات للأطراف الرئيسية في المؤسسة.
بشكل عام، تتضمن مراجعة التكوين فحصاً شاملاً للتكوينات مقابل المعايير والقوائم المعتمدة لتحديد مخاطر أمانية محتملة وتطوير توصيات للإصلاح.
الخبرة في تلك الأدوات أو ما يماثلها مفضلة: Nipper, Tripwire, Qualys, Nessus, Algosec...إلخ
متطلبات الدور:
- فهم جيد وخبرة عملية في أمان البنية التحتية ومنصة السحابة
- فهم جيد لـ Microsoft Sentinel و KQL
- خبرة وسجل ناجح في دمج الموصلات المخصصة مع Sentinel باستخدام APIs. إذا لم تكن لديك خبرة مباشرة مع Sentinel، فسيُنظر في الأفراد ذوي مهارات مطور جيدة
- خبرة في تقنيات Threat Protection من M365 بما في ذلك Microsoft Defender for Endpoint وMicrosoft Defender for Identity وMicrosoft Defender for Office 365 وMicrosoft Defender for Cloud Apps
- خبرة في تقنيات أمان Azure بما في ذلك Microsoft Defender for Cloud وKey Vault وAzure DDoS Protection وغيرها
- خبرة في تقنيات حماية المعلومات مثل Azure Information Protection وWindows Information Protection وData Loss Prevention
- خبرة عملية في إنشاء وضبط ضوابط أمان لمكونات Microsoft Azure (أي Defender for Cloud، Azure Firewall، Azure DDOS Protection، Azure Bastion وSentinel)
- خبرة عملية في إنشاء وضبط ضوابط أمان لمكونات Microsoft 365 (أي Microsoft Purview، Defender for Cloud App، Endpoint، Identity وVulnerability Management)
- خبرة عملية في إنشاء وضبط ضوابط أمان لحلول أمان عامة (أي Azure Active Directory، Azure Identity Protection وAzure RBAC)
- خبرة في تقنيات الامتثال بما في ذلك Advanced eDiscovery وData Retention وInsider Risk Management
- خبرة في تقنيات الهوية بما في ذلك Azure Active Directory P1 & P2
- الإلمام بلغات برمجة أو سكريبت خاصةً في KQL وPowerShell ميزة إضافية
- الإلمام بـ Power BI وPower Apps أو Power Automate ميزة إضافية
- معرفة بتقنيات SaaS المعروفة مثل SAP وOracle ميزة إضافية
- خبرة عملية لا تقل عن سنة واحدة للدرجة المساعدة
- خبرة عملية لا تقل عن 3 سنوات للدرجة Senior Associate
- فتح الذهن والبحث عن حلول مبتكرة
- القدرة على العمل في بيئة سريعة الإيقاع وغير منظمة
- القدرة على التكيف والتواصل مع أساليب عمل مختلفة
- القدرة على التفاعل بكفاءة مع أعضاء كبار في الشركة عبر مناطق زمنية متعددة
المهارات الأساسية والسمات:
- يظهر معرفة واسعة في البنية التحتية وأمان السحابة
- خبرة في الاستشارات أو العمل ضمن بيئات متعددة الجنسيات
- اتصالات ممتازة ومهارات عرض
- مستوى عالٍ من التوجه نحو العملاء وسلوك مقنع
- القدرة على العمل في بيئة سريعة الإيقاع وغير منظمة.
- يجب أن يكون لديه القدرة على تعدد المهام وتحديد الأولويات بشكل فعال ومستمر
- مهارات الإنجليزية الشفوية والكتابية ممتازة. إتقان الألمانية ميزة
التعليم
- درجة جامعية، ويفضل في مجالات علوم الحاسوب والمعلومات، معلومات الأعمال، هندسة الحاسوب، الأمن السيبراني، تكنولوجيا المعلومات، نظم معلومات الإدارة
الشهادات من مايكروسوفت التالية تعتبر ميزة كبيرة:
- Azure Security Engineer Associate (AZ-500)
- Azure Solutions Architect Expert (AZ-303 أو AZ-304 أو AZ-405)
- Cybersecurity Architect Expert (SC-100)
- Security Operations Analyst Associated (SC-200)
- Identity and Access Administrator Associate (SC-300)
- Information Protection Administrator Associate (SC-400)
الملف الشخصي المرغوب للمرشح
- خبرة عملية لا تقل عن سنة واحدة للدرجة المساعدة
- خبرة عملية لا تقل عن 3 سنوات للدرجة Senior Associate
- فتح الذهن والبحث عن حلول مبتكرة
- القدرة على العمل في بيئة سريعة الإيقاع وغير منظمة
- القدرة على التكيف والتواصل مع أساليب عمل مختلفة
- القدرة على التفاعل بكفاءة مع أعضاء كبار في الشركة عبر مناطق زمنية متعددة
- يظهر معرفة واسعة في البنية التحتية وأمان السحابة
- خبرة في الاستشارات أو العمل ضمن بيئات متعددة الجنسيات
- اتصالات ومهارات عرض ممتازة
- مستوى عالٍ من التوجه نحو العملاء وسلوك مقنع
- القدرة على العمل في بيئة سريعة الإيقاع وغير منظمة.
- يجب أن يكون لديه القدرة على تعدد المهام وتحديد الأولويات بشكل فعال
- مهارات الإنجليزية الشفوية والكتابية ممتازة. إتقان الألمانية ميزة
- درجة جامعية، ويفضل في مجالات علوم الحاسوب والمعلومات، معلومات الأعمال، هندسة الحاسوب، الأمن السيبراني، تكنولوجيا المعلومات، نظم معلومات الإدارة
- الشهادات من مايكروسوفت التالية تشكل إضافة كبيرة: Azure Security Engineer Associate (AZ-500)، Azure Solutions Architect Expert (AZ-303 أو AZ-304 أو AZ-405)، Cybersecurity Architect Expert (SC-100)، Security Operations Analyst Associated (SC-200)، Identity and Access Administrator Associate (SC-300)، Information Protection Administrator Associate (SC-400)