02 Aug
|
CDK Global
|
Hyderabad
02 Aug
CDK Global
Hyderabad
We have an excellent chance for Staff Platform Security Engineer. Below are details of the position:
:
Role: Staff Platform Security Engineer
Key Skills: Cloud Security, Azure
Exp: 13 to 17 Year
Location: Hyderabad
Work Mode: Work From Office
Summary
Position Summary
As a Staff Platform Security Engineer, you will play a pivotal role in shaping and securing our cloud and on-premises compute infrastructure. You will be responsible for implementing and maintaining robust security solutions for our Cloud environments. This role requires a deep understanding of security principles, cloud technologies and infrastructure as code practices.
As a Platform Security Engineer, you will participate in security reviews, design and develop innovative security solutions and tools to enhance our security posture and visibility.
Responsibilities
Leadership & Technical Strategy
- Architect the North Star: Define and establish the multi-year cloud security roadmap, aligning technical debt reduction with business velocity.
- Strategic Influence: Partner with business stakeholders to ensure security is a core architectural pillar and a fundamental requirement in all product development.
- CoE Leadership: Provide technical leadership to the Security Center of Excellence (CoE), aligning the Security Champions roadmap with platform engineering goals to ensure a consistent security posture across all environments.
- Data-Driven Governance: Define high-level KPIs (e.g., MTTR, Policy Coverage, Identity Risk scores) to provide executive visibility and drive cross-functional accountability for platform risk.
Cloud Security Architecture & Engineering
- Scalable Governance: Architect and govern multi-tenant cloud environments using standardized landing zone patterns (e.g., CAF or Control Tower). Establish global guardrails that balance developer velocity with enterprise security requirements.
- Identity Governance: Architect a Zero Trust identity ecosystem centering on automated Conditional Access, Just-In-Time (JIT) elevation via Privileged Identity Management (PIM), and Workload Identity Federation to eliminate standing high-privileged access.
- Zero Trust Networking: Oversee the transition to a Zero Trust network architecture. Implement deep-defense strategies including private connectivity, centralized egress/ingress control, and application-layer protection.
Policy-as-Code & IaC Governance
- Scalable Guardrails: Transition from manual reviews to automated governance using Policy-as-Code (e.g., Azure Policy, OPA) to enforce "Security by Default" across the infrastructure lifecycle.
- Standardized Modules: Develop and maintain a library of "Hardened" Infrastructure-as-Code (IaC) modules to provide pre-configured, compliant templates for common cloud services.
- Drift Management: Implement automated detection and remediation systems to identify and resolve infrastructure drift across cloud subscriptions.
Automated Remediation and Orchestration
- Autonomous Remediation: Design event-driven automation and SOAR playbooks to identify and remediate configuration drift and routine threats in real-time, enabling a "Self-Healing" infrastructure.
- Shift-Left Architecture: Integrate automated security "gates" into CI/CD pipelines, including IaC scanning and container analysis, ensuring security feedback is delivered directly to engineers within their existing workflows.
- Operational Efficiency: Develop custom automation and scripting to eliminate manual security tasks, focusing on reducing the "Mean Time to Remediate" (MTTR) for critical platform vulnerabilities.
Preferred Qualifications Technical Architecture & Engineering
- Advanced Cloud Mastery: 8+ years of experience in Infrastructure or Security Engineering, with a deep architectural focus on Azure Enterprise environments (Management Groups, ALZ, and complex networking).
- Identity & Zero Trust Expert:
Proven track record of designing and implementing Zero Trust identity frameworks, specifically leveraging Microsoft Entra ID (PIM, Conditional Access) and Workload Identity Federation at scale.
- Systems Design: Strong ability to architect "Security-by-Design" patterns that solve for the entire lifecycle of a resource, from initial IaC commit to runtime protection.
Automation & Code Proficiency
- Infrastructure as Code (IaC) Expert: Expert-level proficiency with Terraform (including module development and provider management) and cloud-native templates (Bicep/ARM/AWS CloudFormation).
- Engineering Mindset: Proficiency in Python, Go, or PowerShell for building custom security tooling, automation, and API integrations. Experience with Policy-as-Code frameworks (e.g., OPA/Rego, Azure Policy) is highly preferred.
- Pipeline Security: Hands-on experience architecting security gates and automated scanning within GitHub Actions or Azure DevOps pipelines.
Leadership & Strategic Impact
- Strategic Influence: Experience leading large-scale technical initiatives that require cross-functional alignment across technical and non-technical stakeholders to align security goals with business priorities.
- Mentorship & CoE: Demonstrated experience by mentoring senior engineers and providing technical steering within a Security Center of Excellence (CoE).
- Metric-Driven Governance: Ability to define and report on technical risk through data (MTTR, posture trends) to drive organizational accountability.
Desired Qualifications
- Industry Frameworks: Deep familiarity with the Microsoft Cloud Adoption Framework (CAF) and Well-Architected Frameworks.
- Container Security: Extensive experience securing Kubernetes (AKS/EKS) and containerized workloads, including service mesh and admission controllers.
- Advanced Certification: Professional-level certifications such as AZ-500, SC-100 (Cybersecurity Architect), CISSP, or CCSP.
- Security Platform Expertise: Experience architecting enterprise-scale CNAPP, XDR, or SOAR solutions (e.g., Palo Alto/Cortex, Microsoft Sentinel).
Best Regards,
Harshad
📌 Staff Platform Security Engineer (Hyderabad)
🏢 CDK Global
📍 Hyderabad