Job Summary
We are seeking a highly skilled and motivated Cloud Security Engineer to
design, implement, and maintain secure infrastructure across our multi-cloud
environment. In this role, you will act as the subject matter expert for cloud
security, working closely with DevOps, Software Engineering, and IT teams to
embed security into our CI/CD pipelines (DevSecOps), secure cloud workloads,
and ensure compliance with global regulatory frameworks. The ideal candidate
has deep expertise in cloud architectures, automated compliance, and threat
mitigation strategies.
Key Roles & Responsibilities:
-
Architecture & Design:
Design, build, and deploy secure, scalable, and resilient cloud
infrastructures across public cloud platforms (AWS, OCI).
-
Identity & Access Management (IAM):
Design and manage robust cloud IAM policies, ensuring the principle of least
privilege is strictly enforced across all environments.
-
DevSecOps Integration:
Integrate security tools and automated vulnerability scanning (SAST/DAST,
SCA) directly into CI/CD pipelines. Implement Infrastructure as Code (IaC)
security scanning (CSPM).
-
Security Automation & Incident Response:
Develop automated scripts and workflows to detect, alert, and remediate
cloud security misconfigurations and threats in real-time. Assist the SOC
team with cloud-specific incident investigation and forensics.
-
Vulnerability & Threat Management:
Conduct regular cloud security assessments, threat modeling, and
configuration audits. Monitor and manage security alerts from CNAPP, CSPM,
and CWPP platforms.
-
Compliance & Governance:
Ensure cloud infrastructure meets regulatory standards (SOC 2, ISO 27001,
PCI-DSS, DPDP). Implement and monitor adherence to CIS Benchmarks.
-
Collaboration & Mentorship:
Partner with engineering teams to provide security guidance during the
software development lifecycle (SDLC). Conduct security awareness training
regarding cloud best practices for internal teams.
Key Requirements – Education & Certificates
Bachelor’s degree – BTech or equivalent.
Key Requirements - Experience & Skills
Technical
-
Experience:
3–5+ years of dedicated experience in cloud security engineering,
cybersecurity, or systems/DevOps engineering with a heavy focus on cloud
security.
-
Cloud Platform Expertise:
Hands-on experience securing at least one major cloud provider (AWS, Azure,
GCP), with a strong preference for multi-cloud experience.
-
Infrastructure as Code (IaC):
Proficiency with IaC tools like Terraform, CloudFormation, or Ansible, and
experience securing them.
-
Container & Orchestration Security:
Strong understanding of securing containerized workloads (Docker) and
orchestration platforms (Kubernetes/EKS/AKS/GKE).
-
Programming/Scripting:
Proficiency in at least one scripting or programming language (e.g., Python,
Bash, Go, PowerShell) for security automation.
-
Security Tools:
Experience with cloud security tools such as AWS Security Hub, Azure
Defender, OCI cloud guard, Aqua Security, or open-source equivalents.
-
Networking:
Deep understanding of cloud networking concepts (VPCs, VNet peering,
Firewalls, WAF, Load Balancers, VPNs, and Zero Trust architecture).
Nice to have
-
Exposure to ITIL Framework or working in an ITIL based environment.
-
Experience in hybrid infrastructure transformation or cloud migration
projects.
-
Experience with DevSecOps tools like GitLab CI, GitHub Actions, or Jenkins.
-
Familiarity with logging and monitoring tools (e.g., Splunk, Datadog, ELK
stack).
-
Relevant professional Cloud-Specific certifications: AWS Certified Solution
Associate or Oracle Certified Solution Associate.
Behavioral
-
Ownership and Accountability:
Takes full responsibility for cloud security.
-
Collaboration and Influence:
Works effectively across internal teams and external vendors.
-
Communication:
Communicates technical issues clearly to both technical and non-technical
audience.
-
Analytical Thinking:
Uses structured thinking and data-driven approach to solve problems, assess
risks and make recommendations.
-
Adaptability:
Thrives in dynamic environment.