03 Sep
|
Athena Bharatjobs
|
Bengaluru
03 Sep
Athena Bharatjobs
Bengaluru
JD
Azure Security L2 L3
Cloud Security Architect - Multi-Cloud Environment (AWS, Azure, GCP)
Position Overview
We are seeking an experienced Cloud Security Architect to design, implement, and maintain comprehensive security controls across our multi-cloud infrastructure spanning AWS, Azure, and Google Cloud Platform (GCP). This role combines strategic security architecture with hands-on operational responsibilities to ensure robust security posture across all cloud environments.
Key Responsibilities
Security Architecture and Controls
- Design and propose creative security controls to enhance overall security posture across AWS, Azure, and GCP environments
- Continuously improve existing security controls and configurations in multi-cloud deployments
- Maintain comprehensive security architecture documentation and ensuring accuracy and accessibility
Security Assessment and Baseline Management
- Conduct annual security baseline reviews across all cloud platforms (AWS, Azure, GCP)
- Identify, implement, and manage security controls including new implementations, modifications to existing settings, and removal of obsolete controls to address emerging threats
- Analyze monthly security baseline reports and collaborate with reporting teams to eliminate false positives
- Update non-compliance status within security baseline governance frameworks, including risk identification and target remediation dates
- Proactively perform security assessments to identify gaps in multi-cloud environments and escalate security incidents appropriately
Compliance Management
- Develop comprehensive action plans for addressing non-compliance issues across cloud platforms
- Assign and coordinate team responsibilities for remediation activities
- Partner with AWS, Azure, and GCP service providers to assess environments against industry security best practices
- Transform identified security gaps into actionable remediation items with clear timelines
Security Testing and Validation
- Own and manage the penetration testing process across all cloud environments (coordinating with external vendors)
- Ensure all prerequisites are met for vendor-conducted security testing
- Track, validate, and ensure timely closure of penetration test findings across AWS, Azure, and GCP
Access and Policy Management
- Review and approve firewall requests for multi-cloud environments
- Evaluate and approve proxy requests across cloud platforms
- Review and approve RACI matrices for services involving cloud security architecture
- Assess and approve security policy changes including AWS Service Control Policies, Azure policies, GCP IAM policies, KMS policies, and other cloud-native security configurations
- Oversee bi-annual Firewall Rule Reviews (FFR) to ensure network security compliance
Cloud Security Alert Response
- Serve as primary point of contact for CSOC team regarding cloud security alerts across all platforms
- Conduct thorough analysis of incoming security alerts from AWS, Azure, and GCP environments
- Provide contextual updates and technical insights to CSOC team on alert findings
- Investigate root causes of security incidents across multi-cloud infrastructure
- Validate alert legitimacy and implement processes to reduce false positives
- Recommend and coordinate remediation steps for identified security concerns
CNAPP Alert Response
- Review security vulnerabilities and misconfigurations detected by cloud security platforms (such as Wiz) across AWS, Azure, and GCP environments
- Validate identified security issues and eliminate false positives through technical analysis
- Document findings with comprehensive context and technical details for stakeholder communication
Risk Management
- Actively participate in Quantitative Risk Assessments (QRA) for cloud environments
- Communicate identified risks and develop actionable plans to address security concerns
- Coordinate with cloud governance teams to escalate and manage cloud security risks appropriately
Collaboration and Support
- Provide technical support to cloud operations and implementation teams across all platforms
- Address application team inquiries regarding security improvements and best practices
- Collaborate with second line of defense teams on developing and refining cloud security guidelines
- Identify opportunities for security process improvements to enhance protection and reduce operational ambiguity
Required Qualifications
- 5+ years of experience in cloud security architecture
- Hands-on experience with AWS, Azure, and Google Cloud Platform security services
- Strong understanding of cloud-native security tools and CNAPP solutions
- Experience with security frameworks and compliance standards
- Knowledge of network security, identity and access management, and encryption technologies
- Strong analytical and problem-solving skills
- Excellent communication and collaboration abilities
Preferred Qualifications
- Relevant cloud security certifications (AWS Security Specialty, Azure Security Engineer, Google Cloud Security Engineer)
- Experience with security automation and Infrastructure as Code
- Knowledge of DevSecOps practices and CI/CD security integration
📌 Azure Security (Bengaluru)
🏢 Athena Bharatjobs
📍 Bengaluru