Carter R.
Cloud Security Specialist @ SPX/CUES Software | CompTIA Security+, GRC Professional
- Role
- Cloud Security Specialist at CUES Inc.
- Location
- Reno, NV, US
- LinkedIn followers
- 500 followers
About Carter R.
At CUES Inc, my focus is on enhancing cloud infrastructure security and driving SOC2 Type 2 compliance, a testament to our team\'s commitment to robust cybersecurity measures. By deploying core AWS Security tools and standardizing EC2 Security group protocols, we\'ve significantly reduced vulnerabilities across customer environments.Previously, as part of Renown Health\'s IT support, my role centered on delivering reliable tech solutions and managing critical IAM systems which bolstered healthcare service continuity. My expertise in software development security and cyber threat hunting, coupled with industry-recognized certifications, underpins my dedication to safeguarding digital assets and ensuring operational excellence in cybersecurity.
Experience
Cloud Security Specialist
Oct 2024 — Present · Orlando, FL, US
In this role with CUES software division I am working on putting together all requirements that CSD needs to obtain a SOC2 Type 2 this includes so far-Enabling core AWS Security tools-Enabling/managing all AWS inspector agents and their respective findings in the AWS inspector console, resulting in management of all vulnerabilities across over 100 customer EC2 environments. Addressing package vulnerabilities as needed, reducing the overall attack surface- Baseline patch management with the help of AWS Systems manager (SSM)+ Manual intervention of out of compliance instances via SSM documents via powershell scripts for en-masse missing KBs + vulns- EC2 Security group standardization across all EC2 instance SGs to address non-standard ports/protocols in use, working with DevOps teams on terraform playbooks for keeping legacy + new environments aligned to hardened build standards using CIS benchmarking where possible- SSO migration of AWS console to Okta, inventory of all users, groups, and their respective groups, working with SPX Info Sec team to align properly in Okta console- Writing Company policy to include overarching information Security policy, patching policy, build standards, encryption policy, etc to name a few- Spearheading management of annual penetration testing engagements with external pentesting entities ensuring all findings reports are prioritized + remediated-Building out the SDLC, ensuring findings from external penetration tests are prioritized with Development environments, coding repos, etc. Ensuring CWEs are addressed in coding environments, findings are shared with the appropriate Dev teams- AWS WAF and shield rulesets and ACLs are defined + managed, automation in place to interrogate traffic and reprioritize for evolving threat landscape- Utilizing Securonix SIEM to build out monitoring & alerting capabilities, building out an eventual 24/7 SOC team- Constantly documenting all steps, processes, procedures, in One Note.
Education
Western Nevada College
Associates Of Applied Science, Computer Information Technology
2012 — 2019
Western Governors University
Bachelor of Science - BS, Cyber Security and information assurance
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.