Role & Responsibilities:
- Design, implement, and maintain security controls across cloud environments (AWS, Microsoft Azure, and/or Google Cloud Platform).
- Perform cloud security architecture reviews and provide recommendations based on industry best practices.
- Implement and manage cloud security solutions including:
1.
Cloud Security Posture
Management (CSPM)
2.
Cloud Workload Protection
Platforms (CWPP)
- Identity and Access Management (IAM)
- Cloud-native security services
5.
Security
Information and Event Management (SIEM) integrations
- Secure cloud infrastructure using Infrastructure as Code (IaC) practices (Terraform, CloudFormation, ARM templates).
- Conduct security assessments, vulnerability management, and risk analysis for cloud workloads.
- Develop and enforce cloud security policies, standards, and governance frameworks.
- Implement identity security controls including:
- Role-based access control (RBAC)
2.
Privileged Access
Management (PAM)
- Multi-factor authentication (MFA)
- Least privilege access models
- Monitor cloud environments for security threats, misconfigurations, and compliance violations.
- Investigate security incidents involving cloud platforms and coordinate remediation activities.
- Collaborate with DevOps, Infrastructure, Application Security, and SOC teams to integrate security into CI/CD pipelines (DevSecOps).
- Automate security processes using scripting and automation tools (Python, PowerShell, Bash).
- Perform container and Kubernetes security assessments and hardening.
- Support compliance requirements including ISO 27001, PCI-DSS, SOC 2, NIST, CIS Benchmarks,
and regulatory requirements.
- Prepare security documentation including architecture diagrams, risk assessments, security reports, and operational procedures.
- Stay updated on emerging cloud threats, vulnerabilities, and security technologies.
Experience & Technical Skills:
- 510 years of experience in cybersecurity, with strong focus on cloud security.
- Hands-on experience securing enterprise cloud environments such as AWS, Azure, and GCP.
- Strong understanding of cloud security architecture and shared responsibility models.
- Experience with cloud networking security, encryption, identity management, and threat detection.
- Knowledge of DevSecOps practices and security integration into CI/CD pipelines.
- Experience with security tools such as SIEM (Splunk, Sentinel), CSPM (Wiz, Prisma), and vulnerability scanners.
- Understanding of container security (Docker, Kubernetes).
- Strong scripting/automation skills using Python, PowerShell, or Bash.
- Experience with security frameworks like NIST, CIS, and ISO 27001.
Preferred Certifications:
- Highly valued certifications include CISSP, CCSP, AWS Security Specialty, Azure Security Engineer, and Google Professional Cloud Security Engineer.
Soft Skills:
- Strong analytical and problem-solving skills.
- Ability to communicate security risks to technical and non-technical stakeholders.
- Experience working in multinational or enterprise environments.
- Ability to manage multiple security initiatives and prioritize tasks.
- Robust documentation and reporting skills.
- Ability to work independently and collaborate with global teams.
📌 Cloud Security Engineer (India)
🏢 Good
📍 India