About the Role
This role involves leading and building multi-cloud security programs, designing secure architectures with Zero Trust principles, and enhancing detection and monitoring capabilities.
Responsibilities
- Built and managed comprehensive cloud security programs across AWS, Azure, and GCP.
- Established baseline security standards, policies, and governance procedures.
- Designed, implemented, and validated secure cloud architectures applying Zero Trust principles.
- Leveraged CSPM tools and automated remediation workflows to detect and resolve cloud misconfigurations and vulnerabilities.
- Developed automated continuous monitoring and alerting systems.
- Strengthened cloud detection engineering capabilities by partnering with the SOC.
- Embedded security into the SDLC by partnering with Platform, DevOps, and Engineering teams.
- Promoted secure development practices and delivered shared security initiatives.
Requirements
- 6–10 years of hands-on experience designing and securing AWS environments.
- Strong knowledge of native AWS security tools (IAM, KMS, Config, GuardDuty, CloudTrail).
- Proven expertise architecting cloud identity solutions, including SSO/federation (Okta), RBAC, ABAC, and service-to-service authentication models.
- Skilled in provisioning secure infrastructure via Terraform, AWS CDK, or CloudFormation.
- Experience using Python and Bash to build custom security tooling and automated workflows.
- Hands-on experience securing containerized workloads (Docker, Kubernetes, AWS EKS).
- Experience integrated directly with modern CI/CD pipelines (GitLab CI, Jira).
- In-depth knowledge of translating frameworks (NIST CSF, CIS Benchmarks, ISO 27001, SOC 2) into cloud controls.
- Strong communication skills to influence stakeholders and drive security initiatives.
Skills
- AWS Security
- Azure Security
- GCP Security
- Zero Trust Architecture
- CSPM Tools (Wiz, AWS Security Hub)
- Automated Remediation
- Vulnerability Management
- Cloud Security Posture Management
- Detection Engineering
- Continuous Monitoring
- Security Information and Event Management (SIEM)
- Security Orchestration, Automation, and Response (SOAR)
- Secure Software Development Lifecycle (SSDLC)
- DevOps Security
- Identity and Access Management (IAM)
- Single Sign-On (SSO)
- Federation (Okta)
- Role-Based Access Control (RBAC)
- Attribute-Based Access Control (ABAC)
- Infrastructure as Code (IaC)
- Terraform
- AWS Cloud Development Kit (CDK)
- CloudFormation
- Python
- Bash
- Container Security
- Docker
- Kubernetes
- AWS Elastic Kubernetes Service (EKS)
- Continuous Integration/Continuous Deployment (CI/CD)
- GitLab CI
- Jira
- NIST CSF
- CIS Benchmarks
- ISO 27001
- SOC 2
- Cloud Governance
- Compliance Management
Experience Level
- 6-10 years
Education Level
- AWS Security/Architect certification
- CISSP certification
- CCSP certification
