Full-Time

Lead Cloud Infrastructure Vulnerability Analyst

Confirmed live in the last 24 hours

Blue Yonder

Blue Yonder

1,001-5,000 employees

Data & Analytics
Automotive & Transportation
Industrial & Manufacturing

Compensation Overview

$137.1k - $172.9kAnnually

+ Annual Performance Bonus + Commission Program

Senior, Expert

Remote in USA

Candidates can work remotely but are preferred to be based in Dallas, TX or Scottsdale, AZ.

Category
DevOps & Infrastructure
Site Reliability Engineering
Cloud Engineering
Required Skills
Kubernetes
Microsoft Azure
Docker
AWS
Google Cloud Platform

You match the following Blue Yonder's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • 8 to 12+ years of proven experience in Information Security and/or Vulnerability Management.
  • 5+ years of public cloud security infrastructure experience within Azure, AWS or GCP.
  • Must have experience with at least one of the following CSPM (Cloud Security Management) tools; Prisma Cloud (Palo Alto Networks), Wiz, AWS Security Hub, Microsoft Defender for Cloud (formerly Azure Security Center), Check Point Cloud Guard, Lacework OR Orca Security.
  • Strong understanding of Threat Sources/Feeds like CISA, Threat Intelligence, and the latest Vulnerabilities like Log4J, Spring4shell, etc.
  • Bachelor’s degree in Information Security, MIS or Computer Science.
Responsibilities
  • Discover and continuously monitor for vulnerabilities in the public cloud infrastructure, cloud workloads including dockers, Kubernetes, and containers, etc.
  • Create golden images for virtual machines, dockers and containers to be spun up for the business.
  • Identify gaps in Identity and Management (IAM) in Public Cloud.
  • Perform vulnerability scans and report findings for On-prem and Cloud networks.
  • Publish the vulnerability status reports to senior management and track remediation.
  • Define and participate in implementation of On-prem and Cloud architecture and security controls.
  • Proactive identification of threats and risk remediation.
  • Discover the assets in the cloud infrastructure to identify and continuously monitoring for security vulnerabilities and misconfigurations.
  • Maintain security by monitoring and ensuring compliance to standards, policies, and procedures; conducting incident response analyses; developing and conducting training programs.
  • Upgrade security systems by monitoring security environment; identifying security gaps; evaluating and implementing enhancements.
  • Participate in and assist with incident response team, as appropriate.
  • Generate metrics for the Management as needed.
  • Prepare system security reports by collecting, analyzing, and summarizing data and trends.
Desired Qualifications
  • Certifications such as CCSK, CCSP, GCSA, Microsoft Certified Azure Security Engineer Associate, CISSP or equivalent.
  • Thorough understanding of Identity and Access Management best practices in Public cloud.
  • Deep and diverse experience architecting and implementing network security designs. Expert in network security, system security and endpoint security.
  • Through understanding of security vulnerabilities and misconfigurations in the cloud infrastructure.
  • Thorough understanding of native cloud solutions like dockers, containers, Kubernetes, VDIs, cloud storage, cloud infrastructure, etc.
  • Familiarity with security frameworks and regulatory requirements such as NIST, ISO 27001/2, and SSAE-18.
  • Proven experience with products dealing with vulnerability management services which include Qualys, Nessus, Nexpose, etc.
  • Practical experience with the development, implementation, and management of security related technologies (i.e., SIEM, WAF, AV, Firewalls, Internet-facing services).
  • Excellent customer service including strong written and oral communication skills.
  • Knowledge of security network devices (firewalls, switches, SIEM, Antivirus, cryptography, etc.) and other security networking hardware/software tools.
  • Demonstrated understanding of information security concepts, standards, practices, including but not limited to firewalls, intrusion prevention and detection, TCP/IP and related protocols, device monitoring and log management and event monitoring/reporting.
  • Results focused and attention to detail.

Company Stage

Late Stage VC

Total Funding

$73M

Headquarters

Scottsdale, Arizona

Founded

2008

Simplify Jobs

Simplify's Take

What believers are saying

  • Acquisition of One Network Enterprises strengthens Blue Yonder's end-to-end supply chain platform.
  • AI-driven logistics and inventory management are gaining traction, benefiting Blue Yonder.
  • Growing demand for real-time supply chain visibility supports Blue Yonder's advanced solutions.

What critics are saying

  • Integration challenges with One Network Enterprises could disrupt operations if not managed well.
  • Rapid acquisitions may strain financial resources and divert focus from core operations.
  • Increased competition from Oracle and Microsoft could impact Blue Yonder's market share.

What makes Blue Yonder unique

  • Blue Yonder is acquiring One Network Enterprises to enhance its supply chain ecosystem.
  • The company focuses on AI-driven supply chain solutions, aligning with industry trends.
  • Blue Yonder integrates blockchain technology to improve supply chain transparency and efficiency.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

401(k) Company Match

Unlimited Paid Time Off

Corporate Fitness Program

Pet Insurance