22 Aug
|
Accenture
|
Bengaluru
22 Aug
Accenture
Bengaluru
Project Role : Security Architect
Project Role Description : Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations.
Must have skills : Amazon Web Services (AWS) Security
Positive to have skills : NA
Minimum 5 Year(s) Of Experience Is Required
Educational Qualification : 15 years full time education
Summary:
We are looking for an AWS IAM Engineer with experience to provide L2/L3 operational support across IAM, SSO, MFA, RBAC, and PAM services. The role requires strong troubleshooting skills, a sound understanding of AWS identity services, and the ability to manage access policies, handle incidents, and deliver clear operational reporting.
Roles & Responsibilities:
Operations and service delivery
- Handle incidents, service requests and change requests across the AWS security service portfolio, meeting agreed response and resolution service levels.
- Triage and action findings, alerts and policy violations, escalating to the client or to vendor support where required.
- Deliver planned changes within approved maintenance windows, including firewall and WAF rule changes, policy updates and configuration amendments.
- Produce daily operational reports and maintain runbooks, standard operating procedures and knowledge articles.
- Participate in problem management, contributing root cause analysis for major incidents within agreed timelines.
Technical ownership
- Administer AWS WAF rule groups and conditions, tune rules to reduce false positives and false negatives, and manage Firewall Manager security policies.
- Maintain AWS Config rules, including custom rules,
organisation and organisational unit rules, and multi-account deployment.
- Operate AWS Security Hub, including central configuration policies, service integrations and findings workflow.
- Manage AWS GuardDuty findings and suppression rules, protection plans, runtime monitoring and cross-account aggregation.
- Administer AWS IAM roles, policies and permission boundaries perform access reviews, credential reporting and key rotation.
- Support AWS KMS and Secrets Manager operations, including key policy, rotation and access control.
- Maintain AWS CloudTrail configuration across accounts, including data events, retention and downstream log integrations.
- Operate AWS Shield Advanced and AWS Certificate Manager, including certificate lifecycle and renewal monitoring.
- Manage Palo Alto VM-Series firewalls deployed on AWS and maintain AWS Security Group rule sets.
Essential Skills And Experience
- AWS WAF — rule groups, conditions, rule tuning, Firewall Manager security policies.
- AWS Config — managed and custom rules, trigger and evaluation modes, organisation, OU and multi-account rules, configuration history and retention.
- AWS Security Hub — central configuration policies, integration with GuardDuty, Inspector and Macie, findings management.
- AWS GuardDuty — findings analysis, suppression rules, protection plans,
cross-region and cross-account aggregation.
- AWS IAM — roles, policies, permission boundaries, Access Analyzer, credential reports, access key and secret key rotation.
- AWS KMS and AWS Secrets Manager — customer managed keys, symmetric and asymmetric encryption, key and secret rotation, access control.
- AWS CloudTrail — multi-account trails, data events, log retention and aggregation.
- AWS Shield Advanced and AWS Certificate Manager.
- AWS Security Groups and network security concepts in a VPC context.
- Working within an ITIL service management framework — incident, change and problem management, ideally on ServiceNow.
- Depth across AWS WAF, Config, Security Hub and IAM is the core requirement. Candidates with particular strength in identity and key management — IAM, federated identity, IAM Identity Center and KMS — should highlight this, as a subset of the positions is weighted that way.
Professional & Technical Skills:
- Federated identity with AWS — OIDC and SAML identity providers, IAM Identity Center including Active Directory integration.
- Automated remediation using EventBridge and Lambda.
- Infrastructure as code and scripting — Terraform, CloudFormation, Python or Boto3.
- Palo Alto VM-Series and Panorama on public cloud.
- AWS CloudHSM.
- Log and monitoring platforms — CloudWatch, Splunk, Dynatrace.
- Regulated industry experience, particularly life sciences or pharmaceutical, and familiarity with GxP or CIS benchmark controls.
Additional Information:
- The candidate should have minimum 6 years of experience in AWS Administration.
- This position is based at our Bengaluru office.
- A 15 years full time education is required.
📌 Security Architect (Bengaluru)
🏢 Accenture
📍 Bengaluru