Job Title: Cloud Security & ESO Engineer |
Department: Information Security |
Division: Technology |
POSITION SUMMARY
The Cloud Security & Enterprise Security Operations (ESO) Engineer is a hands-on member of Provident Bank's Information Security team responsible for designing, implementing, integrating, and operating security controls across cloud platforms and the enterprise security technology stack. The role combines cloud security engineering with day-to-day ESO engineering, including security-tool administration, platform health, telemetry integration, control validation, automation, incident support, and lifecycle management. The engineer partners with Infrastructure, Architecture, Application Development, Identity, Risk Management, Internal Audit, managed security providers, and third parties to protect customer information, sustain resilient banking services, and align security capabilities with the Bank's risk appetite, policies, and regulatory obligations.
KEY RESPONSIBILITIES:
• 20% - Engineer and maintain secure cloud architectures, landing-zone controls, preventive guardrails, identity-first controls, and cloud-native security capabilities across Microsoft Azure and other approved cloud or SaaS platforms.
• 20% - Administer and engineer ESO platforms supporting email, endpoint and mobile, secure web access, data protection, privileged access, vulnerability management, security monitoring, and related protective controls; monitor operational health and readiness.
• 15% - Integrate cloud, identity, application, network, and security-tool telemetry into the SIEM and detection program; develop use cases, tune alerts, reduce false positives, and validate end-to-end visibility.
• 15% - Engineer secure integrations and automate repeatable ESO and cloud-security tasks using PowerShell, Python, Azure CLI, Terraform, Bicep, APIs, or similar technologies.
• 10% - Perform architecture reviews, threat modeling, risk assessments, and control validation for new systems, major changes, vendors, integrations, and data flows before production use.
• 10% - Partner with technology owners to remediate vulnerabilities, unsupported components, excessive access, control gaps, and misconfigurations; track risk exceptions and validate compensating controls.
• 10% - Support incident response, security-platform upgrades and migrations, formal change management, data protection, audit evidence, metrics, runbooks, operational handoffs, and on-call or after-hours support as required.
SKILLS AND TRAINING REQUIRED:
• Strong hands-on knowledge of Azure security, Microsoft Entra ID, networking, logging and monitoring, encryption, vulnerability management, security-tool administration, platform integrations, and operational troubleshooting.
• Hands-on ability to implement conditional access, multifactor authentication, privileged access management, service principles, workload and managed identities, and role-based access control.
• Experience with Microsoft Defender for Cloud, Microsoft Sentinel, Azure Policy, Key Vault, cloud security posture management, SIEM use cases, alert tuning, and telemetry integration.
• Ability to automate technical and operational tasks using PowerShell, Python, Azure CLI, Terraform, Bicep, APIs, or similar tools.
• Working knowledge of NIST Cybersecurity Framework, NIST SP 800-53, CIS Benchmarks, FFIEC guidance, GLBA Safeguards, NYDFS Part 500, and applicable privacy requirements.
• Knowledge of change management, incident response, problem management, vendor escalation, evidence preservation, secure architecture, and technology lifecycle practices in a regulated environment.
• Ability to translate technical findings into clear risk statements, remediation plans, procedures, and concise communications for engineers, management, auditors, and regulators.
WORK EXPERIENCE:
• Five or more years of information security or infrastructure engineering experience, including hands-on responsibility for production cloud environments or enterprise security platforms.
• Experience managing security controls or platforms across at least two areas such as SIEM, email security, endpoint or mobile security, secure web access, data loss prevention, privileged access management, cloud security posture management, or vulnerability management.
• Experience supporting operational troubleshooting, platform integrations, production changes, incident response, and technology lifecycle activities in a regulated environment.
• Banking, financial services, or other highly regulated industry experience is preferred.