Experience: 6+ Years | Location: Bangalore, India
Role Summary
We are seeking an experienced Cloud Security Engineer to drive (Hands-On) cloud and infrastructure security. The role focuses on cloud security, CNAPP tools, EDR solutions, cloud posture management, patching, IaC security, and SIEM/SOC collaboration. You will secure enterprise workloads, implement automated compliance controls, and coordinate with SOC and DevOps teams while communicating risks and remediation clearly to stakeholders.
Key Responsibilities
Cloud & Infrastructure Security
- OWASP-DT Platform Administration.
- Amazon GuardDuty, AWS Inspector, IaC with Terraform, SSM Agent, SSM Document, Good knowledge in AWS Infrastructure, Linux, Ec2, Lambda Function.
- Harden Linux/Windows workloads using CIS Benchmarks/STIGs.
- Implement least privilege access and manage secrets securely.
CNAPP & Cloud Posture Management
- Continuously monitor cloud workloads using CNAPP platforms
- Assess and remediate misconfigurations and drift against CIS/NIST/internal standards.
- EDR & Threat Detection
- Deploy and manage EDR solutions
- Integrate endpoint and cloud logs into SIEM
- Participate in SOC operations, incident response, and threat hunting.
Patch Management & Vulnerability Remediation
- Lead automated patching workflows for servers,
containers, and cloud services.
- Conduct vulnerability scanning and remediation
- Automate security operations to reduce manual toil.
Compliance & Governance
- Maintain compliance with ISO 27001, NIST, CIS, GDPR, HIPAA.
- Generate audit reports, track remediation actions, and conduct risk assessments.
Communication & Collaboration
- Act as a security liaison between DevOps, SOC, and business teams.
- Communicate risks, remediation plans, and posture findings to technical and non-technical stakeholders.
- Promote security best practices across teams.
Required Skills & Expertise (Must have)
- OWASP-DT Tool Platform Administration (MUST HAVE)
- Cloud Security & CNAPP: AWS, GCP
- EDR & Endpoint Security
- Cloud Posture Management & IaC Security: Terraform, CloudFormation
- Patch & Vulnerability Management: Automated patching in AWS/GCP
- Threat Detection & SOC/SIEM: CloudWatch, Trend Micro Vision One, Cloudtrail
- Linux & Windows Security: OS hardening, permissions, network security
- Scripting & Automation: Python, Bash,
- Compliance & Governance: ISO 27001, NIST, CIS, GDPR, HIPAA
- Soft Skills: Robust communication, documentation, cross-team collaboration
📌 Cloud/App Security Specialist (India)
🏢 iKrux
📍 India