01 Sep
|
Workstreet
|
India
About Workstreet
At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of frameworks—including SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP—empowering companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the Cloud Security Engineering Team
The Cloud Security Engineering team bridges the gap between cloud operations and security compliance by working directly within client AWS, Azure, and Google Cloud Platform (GCP) environments to implement and maintain secure configurations. Partnering closely with engineering, DevOps, and security teams, we investigate and remediate failing security controls, support compliance initiatives across frameworks such as SOC 2, ISO 27001, HIPAA, CMMC, and FedRAMP, and help organizations maintain continuous compliance through GRC platforms like Vanta. Our focus is execution. We don't simply identify compliance gaps, we resolve them. Every failing control is investigated, remediated, validated, and returned to a compliant state with minimal disruption to client operations. By combining cloud engineering expertise with a security-first mindset, we help clients strengthen their environments while enabling them to continue building securely and confidently.
The Opportunity
We are seeking a Cloud Security Engineer with Oracle Cloud Infrastructure (OCI), including compute, networking, storage, and IAM experience, to help clients design, implement, and maintain security controls that meet compliance and security requirements. This role is ideal for professionals with hands-on experience in cloud security engineering, compliance frameworks, and cloud-based security best practices. You’ll work closely with clients and internal teams to strengthen their cloud security posture and automate security operations across AWS, GCP, and Azure environments.
What You'll Do
- Deploy and maintain robust cloud security controls across AWS, GCP, Azure, and OCI to eliminate misconfigurations and preserve strict regulatory compliance alignment.
- Execute deep-dive architectural risk assessments to surface cloud system vulnerabilities, evaluate asset exposures, and engineer targeted technical remediation blueprints.
- Configure and manage enterprise security tool suites, including SIEM solutions, log analytics platforms, identity management layers, IDS/IPS tools, and vulnerability management engines.
- Own the client relationship lifecycle as the primary trusted advisor for an assigned portfolio, establishing project milestones, managing communication pathways, and handling technical escalations with calm professionalism.
- Programmatically enforce security controls by engineering automated, repeatable IaC deployment playbooks and security testing infrastructure.
- Embed continuous security guardrails into CI/CD pipelines and containerized environments to intercept system vulnerabilities early in the software development lifecycle.
- Investigate and contain cloud-related security incidents, rapidly executing forensic logic and remediation steps to restore system integrity and minimize blast radiuses.
- Support continuous audit readiness within GRC platforms like Vanta by systematically gathering, testing, and validating cloud configuration evidence.
Who You Are
- Proven multi-cloud security engineer - Command direct operational ownership securing distributed cloud infrastructure, with hands-on validation across AWS, GCP, Azure, and Oracle Cloud Infrastructure (OCI) environments.
- Cloud security architecture expert - Mastered advanced identity and access management (IAM) strategies, cloud network zoning, payload encryption standards, and systemic risk mitigation workflows.
- Advanced security automation developer - Highly proficient utilizing Infrastructure as Code (IaC) architectures, specifically building and deploying automated guardrails through Terraform, AWS CloudFormation, Python, and Bash.
- GRC infrastructure strategist - Aligned technical, cloud-native configurations directly against global regulatory compliance and audit frameworks, including SOC 2, ISO 27001, GDPR, and HIPAA.
- Surgical technical problem-solver - Apply rigorous analytical diagnostics to isolate cloud infrastructure vulnerabilities, resolve failing controls, and execute zero-disruption remediation.
- High-impact client consultant - Confidently orchestrate multiple client portfolios concurrently, partnering directly with US-based technology founders, DevOps leads, and executive teams to scale cloud security maturity.
- Elite technical communicator - Deliver flawless written and verbal English communication that effortlessly translates dense cloud vulnerabilities and risk vectors into actionable business value.
What will help you succeed
- Deep data and monitoring tooling execution - Advanced manipulation of enterprise logging platforms, vulnerability management engines, threat hunting feeds, and network traffic analysers.
- Validated cloud security credentials - Hold active technical certifications such as AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, CISSP, CISM, or CISA.
- Container and DevSecOps engineering - Practical success auditing and isolating security boundaries within microservice architectures, Docker instances, and Kubernetes clusters.
- Zero Trust deployment models - Direct execution of identity-centric security policies, network micro-segmentation, and context-aware access structures.
- Commercial tenure in fast-growth environments - Documented history scaling infrastructure configurations within hyper-growth tech startups or elite managed security service providers (MSSP).
What We Offer
- Career Development: Clear path with mentorship and training opportunities
- Technical Training: Comprehensive onboarding on security and compliance frameworks
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- Growth Opportunity: Early-stage company with significant room for career advancement.
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What You'll Need to Thrive
- Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
- A reliable, high-speed internet connection and a qualified home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
- Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
- Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process
- Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
- Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
- Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
- Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
📌 Cloud Security Engineer (India)
🏢 Workstreet
📍 India