ClearView Healthcare Partners
Company Overview ClearView Healthcare Partners is a premier life sciences strategy consulting firm headquartered in Boston, with offices in San Francisco, New York City, London, Zurich and Gurgaon. Serving clients in the biopharmaceutical, medical device, and diagnostic spaces, we provide world-class strategic decision-making support across a diverse range of business issues. Our goal is to inform actionable recommendations that allow companies to achieve their business objectives. ClearView is in the process of migrating a significant portion of its local, on-premises resources to the cloud, and this role will be a key player in ensuring that migration happens securely and that our Azure environment is configured and governed to a high standard. ClearView is looking for a Cloud Security-focused Information Security Professional to join our Information Technology team. This role will be responsible for three main areas: Cloud Security Architecture & Operations (with an emphasis on Azure), SIEM engineering, and Monitoring/Testing to ensure compliance. This position requires the ability to work with minimal direction, flexibility to changing demands, and having an eye for process improvement. This position will work in our India office but will be responsible for ClearView's Information Security globally.
Cloud security architecture and operations Support the security workstream of ClearView's ongoing migration of on-premises resources to the cloud, helping ensure new Azure workloads are designed and configured securely from the outset. Help configure, monitor, and continuously improve security controls in Azure (with secondary support for AWS), including Defender for Cloud, Security Hub/GuardDuty, IAM, Network Security Groups (NSGs), and baseline configurations. Support identity governance in Microsoft Entra ID (Azure AD), including conditional access, privileged role assignments, and application/service principal reviews. Assist with authoring, deploying, and monitoring Azure Policy definitions and initiatives to enforce configuration standards and compliance guardrails across subscriptions. Support cloud security posture management (CSPM) efforts, identifying and remediating misconfigurations across Azure and AWS environments. Assist with design and review of cloud architecture for security best practices, including network segmentation (NSGs, firewalls), least-privilege IAM, and encryption at rest and in transit. Support secrets and key management practices using Azure Key Vault, including access policy reviews, rotation, and integration with applications and pipelines. Help assess and improve the security of containerized workloads (e.g., image scanning, registry access controls, AKS/container runtime configuration) as more services move to container-based architectures. Assist with periodic reviews of access controls, MFA configurations, and conditional access policies across cloud and on-prem environments. Support vulnerability management activities by collecting scan results, tracking remediation status, and validating fixes with relevant teams. Contribute to standard build/hardening checklists for cloud resources, servers, and laptops, and verify that new systems are deployed according to these baselines. Security monitoring and incident support Monitor cloud-native security tools and dashboards (e.g., Defender for Cloud, Security Hub, GuardDuty) as well as core SIEM, endpoint security, and email security tools for alerts and suspicious activity; help triage and escalate as needed. Support tuning of SIEM correlation rules and alert thresholds to reduce noise, under the guidance of senior staff. Build and maintain dashboards and reports (cloud and SIEM) that give IT and leadership visibility into security events and trends. Assist in initial investigation of security incidents (log collection, basic analysis, documentation) and support remediation steps defined by senior engineers. Follow established runbooks and procedures for incident response and request enhancements when gaps are identified. Endpoint and identity security Help manage endpoint security tools (EDR/AV, disk encryption, device posture checks) and respond to endpoint alerts following documented procedures. Assist with implementation and maintenance of identity and access controls (e.g., role-based access, privilege reviews, account lifecycle processes). Operational processes and documentation Maintain up-to-date technical documentation for cloud security controls, dashboards, playbooks, and standard operating procedures. Support periodic security reviews and audits by gathering evidence, screenshots, and exportable reports from cloud and security tools. Help implement and track security metrics (e.g., cloud misconfigurations remediated, mean time to acknowledge, patch/vulnerability closure rates) and suggest improvements. Assist with user onboarding/offboarding tasks related to security access, device setup, and cloud/security tooling enrollment. Collaboration and learning Partner with IT teams to ensure changes to cloud infrastructure or applications include appropriate logging and security controls. Stay current on security tooling and best practices relevant to cloud security, SIEM, and endpoint protection, and share useful findings with the team. Job Qualifications Bachelor's degree in technical, information security, or related discipline, or equivalent practical experience. 4–7 years of relevant security experience, with meaningful exposure to cloud environments (Azure and/or AWS). Strong technical aptitude with a primary interest in cloud security, alongside familiarity with security operations and endpoint protection. Experience with core Azure security services strongly preferred, such as Microsoft Entra ID, Network Security Groups (NSGs), Azure Key Vault, and Azure Policy. Exposure to securing containerized environments (e.g., image scanning, AKS/container runtime security) is a plus. Comfortable working with cloud consoles, logs, dashboards, and basic scripting or automation tools to troubleshoot and analyze issues. AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate (AZ-500), Security+, CySA+, or other relevant information security certifications. Demonstrates strong problem solving, analytical, interpersonal, and ownership skills. Possesses excellent collaboration skills for work with various internal team members. Additional Skills/Experience A broad understanding of how to secure cloud environments end to end — identity, network, data, and workload layers — rather than deep expertise in a single area. An understanding of cloud security concepts, encryption, system hardening, defense-in-depth designs, advanced persistent threats, anomaly detection, and next-generation technologies. Working knowledge and experience with any of the following: Microsoft Entra ID, Network Security Groups (NSGs), Azure Key Vault, Azure Policy, cloud IAM/PAM more broadly, Infrastructure-as-Code security scanning (Terraform, CloudFormation), container/Kubernetes security, CSPM/CWPP tools, and cloud logging (Azure Monitor, CloudTrail). Interest or prior experience supporting cloud migration initiatives, ideally with an eye toward building security in from the start rather than retrofitting it. Familiarity with traditional security technologies is a plus: VA, SIEM, DLP, IPS/IDS, AV, MFA, VPN, FW, AD, Wireless, ACLs, and port scanning. Cloud-native monitoring/log analysis experience preferred; experience with a SIEM platform (e.g., Rapid7) is a plus but not required. Working knowledge of Windows endpoints; familiarity with macOS or basic networking concepts is a plus. Awareness of security frameworks or standards (e.g., ISO 27001, NIST CSF, CIS Benchmarks for Azure/AWS) and interest in learning how they apply in practice. Knowledge of a variety of security tools, with depth in cloud-native security tooling. What We Value We recognize that not every candidate will meet every qualification listed. If you’re excited about this role and believe you have relevant experience or transferable skills, we encourage you to apply. We value curiosity, a growth mindset, and a commitment to collaboration. Equal Opportunity Employer ClearView Healthcare Partners ("CV") is an Equal Opportunity employer. All qualified applicants will be considered for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by applicable law.