Role & responsibilities
- Design and build secure, multi-account AWS foundations using Infrastructure as Code (Terraform or CloudFormation), delivering reusable secure-by-default patterns rather than one-off configurations.
- Stand up and govern multi-account structure with AWS Organizations, Control Tower or Landing Zone Accelerator, SCPs, and resource control policies (RCPs), enforcing guardrails through policy rather than manual review.
- Implement least-privilege identity with IAM Identity Center, permission sets, IAM roles and policies, service-linked roles, and permission boundaries.
- Implement centralized SSO using AWS IAM Identity Center for AWS access, including identity source integration and permission set assignment across accounts.
- Implement workload identity federation and CI/CD OIDC (GitHub Actions OIDC) to eliminate long-lived cloud credentials in favor of short-lived, federated access.
- Design and implement network security: VPC architecture, segmentation, security groups, NACLs, PrivateLink, Transit Gateway, and traffic controls.
- Implement encryption defaults, key management, secrets management, and customer-managed keys where business, regulatory, or data classification requirements justify them (KMS, Secrets Manager, rotation).
- Configure logging and detection: onboard CloudTrail, Config, and VPC Flow Logs; configure GuardDuty and Security Hub controls, aggregate findings, route alerts, and drive remediation.
- Automate remediation using EventBridge and Lambda so common misconfigurations self-heal or open tracked tickets.
- Own findings end to end: triage, ownership mapping, exception governance, remediation tracking, and evidence collection.
- Integrate cloud security logs and findings with SIEM/SOAR platforms and support detection, triage, and remediation workflows.
- Produce production-readiness artifacts: runbooks, rollback plans, monitoring, exception handling, and change management.
Preferred candidate profile
- AWS Certified Security - Specialty, or AWS Solutions Architect (Associate or Qualified). CISSP or CCSP as optional pluses.
- CNAPP / CSPM / CIEM tooling (Wiz, Prisma Cloud, AWS Security Hub, or equivalent) with finding triage and remediation ownership.
- Additional AWS security services: Macie, Detective, AWS Network Firewall, WAF, Shield, Route 53 Resolver DNS Firewall, and ECR image scanning.
- Container and Kubernetes security: EKS security posture, image scanning, admission controls, workload identity, network policies, runtime visibility, and secrets management.
- Policy-as-code: OPA/Rego, SCPs/RCPs, and CI/CD policy gates with exception workflows.
- SIEM/SOAR integration (Splunk, Datadog, Sentinel, Chronicle, or equivalent).
- Exposure to a second cloud (Azure or GCP) and multi-cloud security patterns.
- Experience with AWS GovCloud and CMMC / NIST SP 800-171 delivery.
- Understanding of different compliance requirements (HIPAA, PCI, etc.) and ability to regulate infrastructure deployment in line with those compliance requirements.
📌 Aws Cloud Engineer (Hyderabad)
🏢 PwC
📍 Hyderabad