16 Aug
|
Cyberpwn
|
Bengaluru
16 Aug
Cyberpwn
Bengaluru
ABOUT CYBERPWN
CyberPwn is a cybersecurity services and managed security provider (“Empowering Cyber Resilience”), ISO 27001 certified and AICPA SOC-attested, and a Great Place to Work-Certified™ organisation. CyberPwn is building a dedicated onsite security delivery team in Bangalore to run Infrastructure Vulnerability Management, Application Security and DevSecOps, Offensive Security and Red Teaming, Continuous Threat Exposure Management (CTEM), Cloud Security Posture Management, and on-demand security advisory.
ROLE OVERVIEW
Own cloud security posture management across the client multi-cloud estate spanning Microsoft Azure, Amazon Web Services, Google Cloud Platform, and Alibaba Cloud, operating the Wiz platform end-to-end with Microsoft Defender for Cloud as a secondary posture layer. This role owns policy governance, compliance framework tracking, misconfiguration remediation coordination, and cloud risk reporting to client leadership.
KEY RESPONSIBILITY AREAS (KRA)
- Own cloud security posture management end-to-end across the in-scope multi-cloud estate, covering platform operations, policy governance, and delivery quality.
- Own Wiz CSPM policy ownership and lifecycle management, ensuring policy configuration remains aligned to client cloud security baselines across each cloud platform.
- Own compliance framework tracking and reporting across configured benchmarks and regulatory mappings, and drive posture score improvement against them.
- Direct cloud misconfiguration triage and prioritisation, ensuring findings are ranked by genuine exposure and business impact rather than raw finding count.
- Own remediation workflow governance with cloud platform owners, including ticket lifecycle, escalation of at-risk findings, and exception submission and tracking.
- Prioritise publicly exposed and actively exploited misconfigurations for accelerated handling, and own the escalation path where remediation is at risk.
- Own identity exposure governance, ensuring over-privileged identities and identity-related findings are surfaced, tracked, and notified to the responsible identity owners.
- Operate Microsoft Defender for Cloud as a secondary posture layer and reconcile its output with Wiz findings to avoid duplication and coverage gaps.
- Own the cloud risk register,
maintaining an accurate view of accepted, mitigated, and outstanding cloud risk across the estate.
- Ensure Wiz vulnerability data, workload findings, toxic combinations, and cloud exposure paths are provided into exposure management workflows for unified risk prioritisation.
- Own cloud account and subscription onboarding governance, ensuring new environments enter posture coverage promptly and completely.
- Coordinate with development and platform engineering teams on code-to-cloud remediation, working alongside the application security tower where findings originate in infrastructure code.
- Mentor and quality-check the work of the CSPM Engineer, and own workload sequencing across the tower.
- Present cloud posture trends, top residual cloud risks, and remediation progress to senior client leadership in monthly and quarterly governance forums.
KEY PERFORMANCE INDICATORS (KPIs)
- Cloud misconfiguration detection rate measured against periodic benchmark sampling.
- Critical cloud exposure remediation adherence, measured by findings closed within agreed timelines.
- Wiz posture and benchmark score trend across each in-scope cloud platform.
- Cloud exposure footprint reduction measured quarter-on-quarter.
- Over-privileged identity clearance achieved against the periodic review cycle.
- Identity exposure notification timeliness to the responsible identity owner.
- Cloud account and subscription onboarding timeliness into posture coverage.
- Compliance framework coverage, measured by configured frameworks fully tracked.
- Cloud risk register accuracy and currency at each review cycle.
- Quality-review pass rate for engineer-level output.
- Stakeholder satisfaction from governance forum and cloud platform team feedback.
REQUIRED TECHNICAL SKILLS & EXPERIENCE
- Deep multi-cloud security experience across at least two major cloud platforms,
with robust Microsoft Azure grounding and working capability across Amazon Web Services and Google Cloud Platform.
- Hands-on experience operating a cloud native application protection or cloud security posture management platform at enterprise scale, with Wiz strongly preferred.
- Strong command of cloud misconfiguration risk, attack path analysis, and the practical difference between a theoretical finding and a genuinely exploitable cloud exposure.
- Working experience with Microsoft Defender for Cloud, including its coverage characteristics and how it complements a primary posture platform.
- Solid understanding of cloud identity and entitlement management, including over-privileged identity detection, role and policy design, and least privilege remediation practice.
- Experience operating compliance framework tracking against benchmarks such as CIS, NIST, and ISO within a cloud posture platform.
- Practical understanding of Infrastructure as Code and the code-to-cloud remediation model, sufficient to work effectively alongside application security and platform engineering teams.
- Scripting and automation capability in Python or PowerShell for platform integration, reporting, and remediation support.
- Stakeholder management, including comfort presenting to cloud platform leadership, Head of Cyber, and CISO-level stakeholders, and coordinating remediation across teams that own execution.
- Exposure to Alibaba Cloud an advantage.
WORKING ENVIRONMENT & CONDUCT
- Onsite presence at the client delivery centre in Bangalore five days per week is a mandatory condition of the role.
- Candidates must meet client-defined competency, certification, background verification, and conduct standards prior to onboarding.
PREFERRED / EXPECTED CERTIFICATIONS
- Wiz certification (vendor-relevant, strongly preferred)
- Microsoft Azure Security Engineer or equivalent Azure security certification
- AWS Certified Security Specialty or Google Professional Cloud Security Engineer (preferred)
- CCSK, CCSP, or CISSP (preferred)
EDUCATIONAL QUALIFICATION
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).
📌 Cloud Security – Tower Lead (Bengaluru)
🏢 Cyberpwn
📍 Bengaluru