04 Sep
|
Argus Consulting (India)
|
Bengaluru
04 Sep
Argus Consulting (India)
Bengaluru
Senior Cloud (AWS) Security EngineerExperience: 6–10+ Years
Location: Pune/Bangalore
Employment Type: Full-time
About the RoleWe are looking for a Senior Cloud (AWS) Security Engineer to design, implement, and secure cloud infrastructure supporting EKS-based containerized workloads, open-source firewall hosting, CI/CD pipelines, and artifact management.
The ideal candidate will have strong hands-on experience with AWS security, Kubernetes/EKS, container security, CI/CD security, observability, SIEM integration, and infrastructure automation. You will work closely with cloud, DevOps, application, and security teams to build a secure, highly available, and well-monitored AWS environment.
Key Responsibilities
- Design and implement secure AWS infrastructure following AWS security best practices and least-privilege principles.
- Secure and harden Amazon EKS clusters, including cluster configuration, networking, IAM/RBAC, workload security, secrets, and node security.
- Implement security controls across VPC, IAM, Security Groups, Network ACLs, KMS, CloudTrail, GuardDuty, AWS Config, and other relevant AWS security services.
- Implement and manage Amazon ECR security, including image scanning, vulnerability management, image lifecycle policies, and secure image deployment.
- Configure and integrate Amazon Inspector for vulnerability assessment and security monitoring.
- Establish container and Kubernetes security controls covering images, workloads, admission policies, RBAC, secrets, network policies, and runtime security.
- Implement EKS observability, including logs, metrics, security events, audit logs, and integration with SIEM/security monitoring platforms.
- Build and maintain secure GitHub CI/CD pipelines, incorporating security scanning, vulnerability checks, secrets management, approvals, and controlled deployment mechanisms.
- Integrate JFrog Artifactory or similar artifact repositories with AWS/EKS and CI/CD workflows.
- Design secure artifact and container-image promotion workflows across development, testing, staging, and production environments.
- Support secure hosting and deployment of open-source firewall solutions within AWS/EKS or supporting AWS infrastructure.
- Implement network segmentation, ingress/egress controls, firewall policies, and secure connectivity between AWS services and external systems.
- Automate infrastructure and security controls using Terraform, CloudFormation, AWS CLI, or similar IaC/automation tools.
- Establish security monitoring, alerting, incident investigation, and remediation processes.
- Perform vulnerability assessments, security reviews, configuration audits, and remediation of identified risks.
- Develop security standards and documentation for AWS, Kubernetes, containers, CI/CD, and cloud operations.
- Work with engineering teams to implement DevSecOps practices and shift security controls left into the development lifecycle.
Required SkillsAWS Security
- Strong hands-on experience with AWS security architecture and services.
- IAM, VPC, Security Groups, NACLs, KMS, CloudTrail, GuardDuty, AWS Config, Inspector.
- Experience implementing least-privilege access and secure cloud networking.
Kubernetes / EKS
- Solid experience with Amazon EKS administration and security.
- Kubernetes RBAC, network policies, secrets, service accounts, pod security, ingress/egress controls.
- EKS logging, monitoring, audit logs, and security hardening.
Container Security
- Amazon ECR and container image security.
- Vulnerability scanning and remediation.
- Experience with tools such as Amazon Inspector, Trivy, Clair, Falco, or equivalent.
- Understanding of Docker/container security best practices.
DevSecOps / CI/CD
- Strong experience with GitHub Actions / GitHub CI/CD.
- Security integration into CI/CD pipelines.
- SAST, SCA, container scanning, secrets scanning, and policy enforcement.
- Experience integrating JFrog Artifactory or similar artifact repositories.
Observability & SIEM
- EKS and AWS security/log monitoring.
- CloudWatch, CloudTrail and Kubernetes audit/application logs.
- Experience integrating AWS/EKS logs and security events with SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, Elastic, or similar.
Infrastructure as Code
- Terraform and/or CloudFormation.
- Automation using Python, Bash, or AWS CLI.
Preferred Qualifications
- AWS Certified Security – Specialty.
- Certified Kubernetes Security Specialist (CKS) or CKA.
- Experience with DevSecOps and cloud security architecture.
- Experience securing production-grade Kubernetes environments.
- Experience with open-source firewalls such as pfSense, OPNsense, or similar.
- Experience with zero-trust architecture and network segmentation.
- Familiarity with CIS AWS Foundations and CIS Kubernetes benchmarks.
- Experience working in regulated or security-sensitive environments.
What We're Looking For
- Strong hands-on engineering mindset rather than purely theoretical security knowledge.
- Ability to troubleshoot AWS, Kubernetes, networking, containers, and CI/CD security issues.
- Strong understanding of cloud attack surfaces and practical mitigation strategies.
- Ability to work independently and collaborate with DevOps, developers, infrastructure, and security teams.
- Strong documentation and communication skills.
Key Technologies
- AWS | EKS | ECR | Amazon Inspector | IAM | VPC | KMS | CloudTrail | GuardDuty | AWS Config | GitHub Actions | JFrog Artifactory | Docker | Kubernetes | Terraform | SIEM | CloudWatch | DevSecOps | Container Security
📌 Senior AWS Cloud security Engineer (Pune or Bangalore only) (Bengaluru)
🏢 Argus Consulting (India)
📍 Bengaluru