Engineer - Cybersecurity (Bengaluru)

Engineer - Cybersecurity (Bengaluru)

03 Sep
|
Eli Lilly
|
Bengaluru

03 Sep

Eli Lilly

Bengaluru

Overview

Cloud Security Analyst Overview: Cloud Security Analyst - Lilly Cyber is seeking a skilled Cloud Security Analyst with a robust understanding of cloud security technologies, cloud security posture management (CSPM), and vulnerability management best practices. The ideal candidate will join the Threat Mitigations team and play a pivotal role in supporting threat mitigation activities across Lillys cloud environments, including infrastructure, cloud-native applications, containers, and back-end pipeline management. This is an exciting position that will be dedicated to helping address cloud security risks.

As part of a cross-functional team, this analyst will collaborate closely with a broad set of teams to ensure effective threat reduction. This is an excellent opportunity to grow and experience a wide array of different aspects of cloud cybersecurity while performing a meaningful and impactful role.

Key Responsibilities

- Cloud Security Threat Mitigation
- Assist Cyber Threat Mitigation Leads in identifying, assessing, and developing solutions to reduce security threats.
- Manage vulnerabilities through their full lifecycle: discovery, triage, ownership assignment, SLA tracking, and remediation verification.
- Continuously monitor multi-cloud environments (AWS, Azure, GCP) using CSPM platforms such as Wiz to identify misconfigurations, excessive permissions, and compliance drift.
- Disposition findings from scanning tools, validating issues, and producing clear remediation guidance for developers.
- Participate in the implementation of mitigation strategies across cloud workloads, containers, APIs, and infrastructure-as-code.
- Contribute to threat modeling activities for new and existing cloud architectures and applications.
- Support burndown of risk with the deployment of security tools through hands on involvement for hard to solve issues.




- Collaborate with diverse teams and stakeholders to promote security best practices.
- Support tracking and reporting of security mitigation metrics to provide visibility into risk remediation efforts.

- DevSecOps Management
- Integrate security tooling into CI/CD pipelines to enable shift-left practices and automated security checks during build process.
- Support pull request gating, secrets scanning, dependency scanning, and infrastructure-as-code (IaC) scanning across engineering teams.
- Develop scripts to enable automation of scanning and triaging workflows.

Qualifications

Required Skills

- Bachelors degree in Computer Science, Information Security, or a related field (or equivalent work experience).
- 1-3 years of experience in cybersecurity, with a focus on cloud security and/or vulnerability management.
- Working knowledge of cloud security fundamentals across major cloud service providers (AWS, Azure, GCP), including identity and access management, network segmentation, encryption, and logging/monitoring.
- Hands-on experience with one or more Cloud Security Posture Management CSPM platforms (e.g., Wiz, Prisma Cloud, Orca Security, Microsoft Defender for Cloud, or similar).
- Experience with vulnerability scanners and management platforms (e.g., Wiz, Qualys, Rapid7, or similar).

- Solid understanding of vulnerability management processes, including CVSS scoring, and risk-based prioritization.
- Familiarity with cloud-native architectures (containers,



Kubernetes, serverless) and the security risks associated with each.
- Understanding of cloud IAM policies, least-privilege access, and authentication/authorization standards (OAuth 2.0, SAML) in cloud environments.

- General familiarity with security control technologies (firewalls, encryption, IAM, SIEM, and DLP).
- Strong problem-solving and analytical skills with a focus on identifying, addressing, and mitigating security risks.
- Ability to work effectively in a cross-functional team environment, fostering collaboration with developers, platform engineers, and security peers.

Preferred Skills

- Experience integrating security tooling into CI/CD pipelines (Jenkins, GitHub Actions, GitLab CI, or Azure DevOps) and familiarity with Git workflows and pull request gating.
- Working knowledge of container security (Docker, Kubernetes), image scanning, and IaC scanning (Terraform, CloudFormation).
- Comfort with at least one scripting language (Python, Bash, or PowerShell) for security automation.
- Multi-cloud experience across AWS, Azure, and GCP, including native security services (e.g., AWS Security Hub, Microsoft Defender for Cloud, GCP Security Command Center).

- Threat modeling experience using frameworks such as STRIDE, PASTA, or attack trees.
- Hands-on experience with security automation tools.
- Cybersecurity or cloud certifications: Security+, AWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer Associate, or a CSPM vendor certification (e.g., Wiz Certified Practitioner).

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Engineer - Cybersecurity (Bengaluru)
🏢 Eli Lilly
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: engineer - cybersecurity (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: engineer - cybersecurity (bengaluru) / bengaluru