08 Sep
|
Cargill
|
Bengaluru
Job Purpose and Impact
Sr Consultant - Surface Area Management safeguards the organization's Digital footprint both On-Prem/Cloud by leading the continuous improvement of security controls, guardrails, and remediation of the exposures. This role serves as a trusted advisor and technical leader, driving enterprise cloud vulnerability/exposure management strategy, standards, and posture improvement initiatives. With minimal supervision, the Senior Consultant partners with cybersecurity, cloud platform, infrastructure, engineering, risk, and business leaders to reduce cloud risk exposure and improve the exposures and other issues of cloud adoption at scale. qualified individual contributor and is recognized as subject matter expert in vulnerability management and exposure reduction strategies.
Key Accountabilities
- Lead enterprise-wide Cloud Vulnerability Management programs across AWS, Azure, GCP, and OCI.
- Design and implement preventive security guardrails using SCPs, Azure Policy, and organization policies to enforce secure-by-default controls.
- Analyze CSPM/CNAPP findings and prioritize remediation based on exposure, business criticality, data sensitivity, and compensating controls.
- Drive remediation accountability, govern security exceptions, and manage risk acceptance processes across platform and application teams.
- Develop automation, auto-remediation capabilities, dashboards, and integrations to improve control coverage, efficiency, and reporting.
- Lead cloud identity and access security initiatives, including privileged access, federation, workload identities, secrets management, and least privilege enforcement.
- Establish risk-based prioritization models incorporating threat intelligence, exploitability, business impact, and compensating controls.
- Coordinate responses to zero-day threats, actively exploited vulnerabilities, and critical CVEs.
- Identify systemic security trends and drive strategic improvements in scanning coverage, asset visibility, attack surface management, and remediation effectiveness.
- Conduct cloud security assessments and architecture reviews, translating findings into prioritized remediation roadmaps.
- Deliver executive-level risk reporting and partner with Incident Response, Threat Intelligence, Security Architecture, and engineering teams.
ESSENTIAL FUNCTIONS
VULNERABILITY MANAGEMENT STRATEGY & GOVERNANCE
Leads the design, implementation, operation, and continuous improvement of enterprise vulnerability management capabilities.
Establishes standards, governance processes, performance metrics, and risk management practices to reduce organizational exposure.
EXTERNAL ATTACK SURFACE MANAGEMENT
Provides strategic oversight of the organization's external attack surface, identifying emerging risks, prioritizing remediation efforts, and guiding improvements to overall exposure management practices.
THREAT-INFORMED VULNERABILITY MANAGEMENT
Integrates vulnerability management with threat intelligence, threat hunting, offensive security, and incident response capabilities to improve detection, prioritization, and remediation outcomes.
PROGRAM LEADERSHIP & CONTINUOUS IMPROVEMENT
Leads cross-functional initiatives that improve scanning coverage, asset visibility, remediation performance, governance processes, and overall program maturity.
EXECUTIVE COMMUNICATION & STAKEHOLDER MANAGEMENT: Communicates complex technical risks to executive leadership and business stakeholders, influencing strategic decisions and prioritization of remediation activities.
PREVENTIVE CONTROLS & GUARDRAIL ENGINEERING: Provides strategic and hands-on ownership of preventive cloud controls, ensuring insecure configurations are blocked by default, and guardrail coverage keeps pace with cloud service adoption.
CLOUD POSTURE & MISCONFIGURATION REMEDIATION: Develops and maintains enterprise risk models for cloud posture findings, ensuring remediation efforts focus on the most significant business and cybersecurity risks, and advances automated remediation where appropriate.
CLOUD SECURITY ARCHITECTURE & CONTROL VALIDATION: Provides technical leadership for cloud security architecture reviews, control validation, secure landing zone alignment, workload protection, encryption, network segmentation, key management, and identity-based access controls to ensure cloud environments remain resilient, compliant, and secure by design.
Qualifications
- Bachelor’s degree in computer science, Cybersecurity, Information Security, Information Systems, or a related technical field, or equivalent practical experience.
- 6+ years of cybersecurity experience,
including 4+ years focused on cloud security engineering, cybersecurity, vulnerability management, attack surface management, or exposure management experience.
- Hands-on experience securing enterprise -scale vulnerability management in at least one of AWS, Microsoft Azure, Google Cloud, or Oracle Cloud Infrastructure, with working knowledge of a second.
- Proven experience designing and operating preventive cloud guardrails – AWS service control policies, Azure Policy, Google organization policies, or equivalent policy-as-code enforcement – not detection and reporting alone.
- Strong expertise in cloud security architecture and cloud-native security controls across IaaS, PaaS, and SaaS, including network security, data protection, and key management such as Azure Key Vault or AWS KMS.
- Deep expertise in cloud identity and access management, including least-privilege role design, federation and workload identity, privileged access management, conditional access, and Zero Trust principles.
- Hands-on experience operating a CSPM or CNAPP platform at enterprise scale – Wiz, Microsoft Defender for Cloud, Prisma Cloud, AWS Security Hub, or equivalent – including onboarding, policy tuning, finding triage, and remediation ownership routing.
- Hands-on experience with infrastructure as code security and policy enforcement using Terraform, Bicep, ARM templates, or CloudFormation, and integrating security controls into CI/CD pipelines and DevSecOps practices.Proven experience conducting cloud security assessments, posture reviews, threat modeling, architecture reviews, and security control validation, and translating findings into prioritized remediation roadmaps.
- Strong knowledge of cloud security frameworks and standards including CSA Cloud Controls Matrix, CIS Benchmarks, NIST, ISO 27001, and cloud provider Well-Architected security principles.
- Experience driving remediation accountability across platform and application teams, governing security exceptions and risk acceptances, and communicating cloud risk to senior leaders and executive audiences.
Preferred Certifications
- Cloud-specific certifications strongly preferred: CCSP, CCSK, AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect Expert (SC-100), or Google Professional Cloud Security Engineer.
- CISSP or an equivalent broad security certification is preferred.
📌 Sr. Consultant, Surface Area Management (Bengaluru)
🏢 Cargill
📍 Bengaluru