Principal AWS Cloud Security Engineer / Cloud Security Architect
Position Summary
This is a hands-on architecture and engineering role within Cybersecurity Architecture (CSA). The role secures the AWS platform behind the IRM product estate, including Horizon, CRC & OCN (Masscomm), and Legacy Masscomm platforms.
You will design and implement the cloud security guardrails that allow IRM engineering teams to move faster with less risk: AWS account structure, landing zones, IAM and SCP controls, EKS and container security, network exposure reduction, secrets and encryption patterns, cloud logging, posture management, and infrastructure-as code guardrails.
This role reports through CSA, with dedicated day-to-day alignment to Cloud Ops, Dev Ops, platform engineering, and the product-security resources in PSOE.
Required Qualifications
Experience
Senior hands-on experience securing production AWS environments for client-facing or mission-critical workloads.
Proven experience with AWS Organizations, multi-account architecture, landing zones, SCPs, IAM, VPC networking, EKS / Kubernetes, KMS, secrets management, and cloud logging.
Practical experience turning cloud posture findings into remediated infrastructure and reusable patterns. Experience working with Dev Ops,
Cloud Ops, platform engineering, and product teams in delivery-oriented settings.
Technical Skills
Strong AWS architecture and security engineering skills.
Infrastructure-as-code and policy-as-code experience, preferably with Terraform or equivalent tooling. Working knowledge of CSPM / CNAPP concepts, container security, cloud detection, and cloud resilience. Ability to design controls that are automated, auditable, and usable by engineering teams.
Familiarity with CIS AWS Benchmarks, NIST CSF, NIST SP 800-53, and Zero Trust concepts.
Soft Skills and Behaviours
Practical architecture judgment: able to reduce real risk without creating review bottlenecks.
Strong communication with platform engineers, product leaders, Cyber Ops, GRC, and executives.
Comfortable operating through influence in a federated environment.
Bias toward reusable patterns, measurable remediation, and transparent ownership.
Certifications (Preferred)
AWS Security - Specialty, AWS Solutions Architect Qualified, or equivalent cloud-security credentials.
CISSP, CCSP, Kubernetes security, or infrastructure-security certifications are assets.
📌 Security Architect Bengaluru (India)
🏢 Tenarai
📍 India