Post Job Free
Sign in

Cybersecurity Analyst: IAM & Cloud Security

Location:
San Antonio, TX
Salary:
100000
Posted:
August 04, 2026

Contact this candidate

Resume:

UCHENNA ENWERE

CYBERSECURITY ANALYST IAM • CLOUD SECURITY • VULNERABILITY

Location: San Antonio, TX Contact: 361-***-**** Gmail: *************.**@*****.*** LinkedIn PROFESSIONAL SUMMARY

• Results-driven Cybersecurity Analyst with 10+ years of experience in security operations, identity and access management (IAM), vulnerability management, and cloud security across enterprise environments. Proven expertise in administering IAM frameworks, conducting risk-based vulnerability assessments, managing firewall policies, and monitoring multi-cloud environments (AWS, Azure, GCP) for security posture optimization. Strong background in regulatory compliance (SOC 2, PCI-DSS, ISO 27001, HIPAA, GDPR) with hands-on experience in incident response, SIEM monitoring, and DevSecOps integration. Demonstrated success in reducing security risks by 65% through systematic vulnerability remediation, enhanced access controls, and proactive threat detection strategies. TECHNICAL SKILLSET

Cloud Platforms - Microsoft Azure (Azure Blob Storage, Azure Data Factory, Azure AD, Azure CLI, Azure Migrate, Azure DMS, Azure DevOps & Pipelines, Azure Monitor, Azure Policies), CI/CD, DevSecOps integration. Security Tools - AWS Security Hub, Azure Security Center, CloudWatch, CloudTrail, GuardDuty, Prisma Cloud, Terraform, Ansible, Check Point, Palo Alto Networks, root cause analysis, TFSEC. Identity & Access Management - IAM, SSO, MFA, Okta, Azure AD, PAM, Google Workspace. Compliance & Standards - NIST, FEDRAMP, SOC 2, GDPR, HIPAA, PCI DSS, ISO 27001, CIS, FTC, SOC, SOX. Security Protocols - VPN, SSL/TLS, IPsec, SSH, SAML, OAuth 2.0, OpenID Connect. Incident Response - SIEM, IDS/IPS, WAF, DDoS protection, cloud-native security monitoring, Splunk. Automation - Terraform, Ansible, Python, Bash, CloudFormation. DevOps/CI/CD Tools - GitHub, Git, GitLab, GitHub Actions, CodePipeline, ECR, EKS, ECS, Terraform, Terragrunt, Jenkins, Ansible, Docker, Kubernetes, TeamCity, Azure DevOps, Bamboo. Containerization & Orchestration - Docker, Kubernetes, Elastic Container Service (ECS), Elastic Kubernetes Service (EKS), Azure Kubernetes Service (AKS).

Endpoint Security - CrowdStrike, SentinelOne.

Databases: SQL Server, MySQL, HBase

Operating Systems: Linux (RHEL/Ubuntu, CentOS), MS Windows Server EXPERIENCE

SOFT PLANET INC – (Remote) MAR 2022 – PRESENT

Senior Cybersecurity Analyst

• Managed enterprise security operations, monitoring and responding to security incidents using SIEM, EDR, and threat intelligence platforms to strengthen organizational security posture.

• Implemented and administered Identity and Access Management (IAM) solutions, including RBAC, MFA, SSO, and privileged access controls across on-premises and cloud environments.

• Conducted vulnerability assessments, risk analysis, and remediation activities using tools such as Nessus, Qualys, and Tenable to reduce security risks and improve compliance.

• Secured cloud infrastructures across AWS, Azure, and GCP by enforcing security baselines, access governance, encryption, and continuous monitoring controls.

• Performed incident response, threat hunting, and root cause analysis to identify, contain, and remediate cybersecurity threats and vulnerabilities.

• Collaborated with cross-functional teams to implement security policies, compliance standards, and governance frameworks aligned with NIST, ISO 27001, CIS, and SOC 2 requirements.

• Automated security monitoring, reporting, and remediation workflows using PowerShell, Python, and security orchestration tools to improve operational efficiency.

• Managed endpoint, network, and application security controls including firewalls, IDS/IPS, antivirus, and data loss prevention

(DLP) solutions.

• Conducted security audits, access reviews, and compliance assessments to ensure adherence to organizational and regulatory security standards.

• Supported DevSecOps initiatives by integrating security scanning, compliance checks, and vulnerability management into CI/CD pipelines and cloud-native deployments.

• Design and deliver role-based security awareness training modules focused on phishing recognition, data handling, and secure remote work practices.

CONCETRIX SEP 2017 – JAN 2022

Cloud Security/DevSecOps Engineer

• Engineered reusable and secure Terraform modules across AWS, Azure, and GCP, enabling scalable, compliant, and standardized Infrastructure as Code (IaC) aligned with CIS and NIST security frameworks.

• Architected and implemented secure CI/CD pipelines using GitHub Actions, Jenkins, and AWS CodePipeline, integrating DevSecOps practices including SAST, DAST, SCA, and IaC security scanning for shift-left security.

• Deployed and optimized CrowdStrike Falcon EDR for endpoint and container runtime protection, integrating with AWS Security Hub and Splunk SIEM for centralized threat monitoring, detection, and incident response.

• Orchestrated cloud-native workloads using Kubernetes (EKS, AKS, GKE) and Docker, enforcing container security, workload isolation, runtime protection, and policy-based governance.

• Automated infrastructure provisioning and governance using Terraform, AWS CloudFormation, and Azure ARM templates, ensuring repeatable, auditable, and policy-driven deployments across enterprise environments.

• Secured Terraform state management using encrypted S3 backends with DynamoDB locking, versioning, and granular access controls to ensure integrity, concurrency protection, and compliance.

• Implemented enterprise IAM solutions by integrating AWS IAM Identity Center (SSO) with Active Directory, enabling federated authentication, centralized access management, and secure user provisioning.

• Configured SCIM-based identity lifecycle management with RBAC enforcement and least-privilege access controls using fine- grained IAM policies and AWS Access Analyzer for continuous permission governance.

• Implemented advanced application and network security controls using AWS WAF, mitigating OWASP Top 10 vulnerabilities, bot attacks, and Layer 7 DDoS threats.

• Built centralized observability and security monitoring solutions using CloudWatch, Azure Monitor, and Splunk SIEM, enabling real-time alerting, log correlation, threat detection, and operational visibility.

• Authored and maintained security runbooks, incident response playbooks, and disaster recovery plans to improve operational readiness, resilience, and regulatory compliance.

• Led end-to-end incident response activities including threat triage, forensic investigations, containment, remediation, and root cause analysis (RCA) for enterprise security incidents.

• Strengthened cloud security posture management using AWS Config, Trusted Advisor, and automated remediation workflows to enforce continuous compliance and governance controls.

• Supported third-party and vendor security risk assessments, ensuring alignment with enterprise security policies, regulatory standards, and supply chain security requirements.

• Architected enterprise-grade encryption and key management solutions using AWS KMS and Azure Key Vault, implementing key rotation, envelope encryption, and compliance-driven data protection controls.

• Designed secure VPC architectures with private subnets, micro-segmentation, and least-privilege network access aligned with Zero Trust security principles.

• Enabled end-to-end TLS encryption across CloudFront, Application Load Balancers, and backend services using AWS ACM and PKI, while securing S3 origins through Origin Access Control (OAC).

• Enhanced threat detection and forensic analysis by correlating CloudTrail, GuardDuty, VPC Flow Logs, and AWS Detective to improve incident visibility, investigation, and response capabilities.

• Improved data protection and resiliency through S3 lifecycle policies, MFA-based EC2 administration via AWS Systems Manager (SSM), and Multi-AZ RDS backup strategies to ensure high availability and disaster recovery readiness. EDUCATION, CERTIFICATION

BACHELOR’S IN COMPUTER SCIENCE

CISA – CERTIFIED INFORMATION SYSTEMS AUDITOR

AWS CERTIFIED SOLUTIONS ARCHITECT – PROFESSIONAL

CERTIFIED CLOUD SECURITY PROFESSIONAL (CCSP) AND CompTIA SECURITY+ AWS CERTIFIED SECURITY, SPECIALITY

CompTIA Security+ CompTIA

POSTGRADUATE DIPLOMO (PGD) IN BUSINESS ADMINISTRATION



Contact this candidate