16 Sep
|
Stella Technologies
|
Ahmedabad
16 Sep
Stella Technologies
Ahmedabad
Senior Cloud Security Engineer AWS
Department: IT / Cybersecurity
Reports To: Director of IT Infrastructure
Location: India – On-Site
Role Summary
One Park Financial is seeking a hands-on Senior Cloud Security Engineer to strengthen security
across our AWS infrastructure and support daily cybersecurity operations.
Your primary focus will be implementing AWS security controls, investigating cloud security events,
correcting misconfigurations and excessive permissions, and automating recurring security checks.
As part of our Cybersecurity team, you will collaborate with Infrastructure, DevOps, and
Development to reduce risk and introduce automated security checks into existing development
workflows. This is an engineering role: we value the ability to implement improvements and verify
results—not simply identify and report issues.
Key Responsibilities
• Secure AWS infrastructure: Assess and improve security across AWS accounts, identities,
networking, storage, and workloads. Address excessive permissions, exposed resources,
insecure configurations, and credential-management risks.
• Implement preventive controls: Work with DevOps to strengthen least-privilege access, role-
based authentication, account-level guardrails, encryption, and secrets management.
• Improve cloud monitoring: Configure and maintain security logging and detection capabilities
using services such as CloudTrail, GuardDuty, Security Hub, and related AWS tools.
• Investigate and respond: Analyze suspicious activity, credential misuse, unauthorized
changes, and cloud security incidents.
Perform authorized containment actions and escalate
critical events immediately.
• Drive remediation: Prioritize cloud vulnerabilities and security findings, coordinate fixes with
technical owners, track outstanding risks, and validate completed remediation.
• Support development security: Partner with DevOps to introduce secret detection,
dependency scanning, and other agreed security checks into repositories and CI/CD
workflows. Help evaluate findings and define remediation requirements; DevOps retains
ownership of pipeline implementation, and Development owns code fixes.
• Automate security checks: Build and maintain scripts or workflows for recurring configuration
reviews, access checks, monitoring validation, and reporting.
• Provide early-shift coverage: Review the shared security alert queue, verify monitoring
health, and investigate or escalate issues using established procedures. Maintain
investigation records, runbooks, and remediation evidence, and deliver a transparent daily handoff
to the Americas team.
Required Qualifications
• 5+ years of combined experience in cloud engineering, infrastructure, cybersecurity, or
related technical roles,
including demonstrated responsibility for securing production AWS
environments.
• Strong practical understanding of AWS IAM, least privilege, cloud networking, logging,
infrastructure hardening, and credential management.
• Hands-on experience investigating AWS security events and implementing or coordinating
corrective actions.
• Practical scripting ability in Python, Bash, or PowerShell. Expertise in all three is not
required.
• Working familiarity with Git and CI/CD workflows, along with the ability to collaborate
effectively with Infrastructure and DevOps teams.
• Strong troubleshooting, documentation, and professional English communication skills.
Ability to work independently, prioritize risk, and make controlled, well-documented changes.
Preferred Qualifications
• Experience with multi-account AWS environments, AWS Organizations, Service Control
Policies, and infrastructure as code.
• Experience introducing secret scanning, dependency scanning, or other automated security
checks into development workflows.
• Familiarity with enterprise identity, endpoint protection, or monitoring platforms such as Okta,
Microsoft Entra ID, Active Directory, Microsoft 365, Wazuh, Graylog, or WithSecure.
Equivalent platform experience is welcome; expertise in every listed tool is not expected.
• AWS Certified Security – Specialty or another relevant AWS/security certification.
Demonstrated hands-on capability is more important than certifications or familiarity with
every product in our environment.
📌 Cloud Security Engineer - Ahmedabad Location (WFO)
🏢 Stella Technologies
📍 Ahmedabad