Application & Cloud Security Lead

Jobtailor

Hyderabad

On-site

INR 3,000,000 - 5,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

S&P Global Energy Division is seeking an experienced security leader to drive application, cloud, and AI security across the organization. You will conduct architecture reviews, embed security in design and operations, and enforce secure coding practices while coordinating across engineering, product, and business teams.

You will oversee cloud security, assess AI risks, and report security posture through dashboards and executive briefings.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent professional experience.
  • 5–8+ years experience in cybersecurity, with a strong focus on application security, cloud security, security architecture, and/or technology risk management.
  • Experience conducting security architecture reviews for applications, APIs, cloud platforms, data platforms, and enterprise technology solutions.
  • Experience with DevSecOps, CI/CD security, container security, Kubernetes security, infrastructure‑as‑code scanning, secrets management, and software supply chain security.
  • Experience with cloud security tools such as CSPM, CWPP, CNAPP, SIEM, vulnerability management platforms, container scanners, and identity governance tools.
  • Familiar with AI security concepts such as prompt injection, model access control, sensitive data exposure, model monitoring, adversarial testing, AI red teaming, and third‑party AI risk.
  • Experience working with public cloud environments such as AWS, Azure, or Google Cloud Platform.
  • Experience partnering with cross‑functional stakeholders including technology, product, risk, compliance, privacy, legal, and business teams.
  • Strong written and verbal communication skills, with the ability to explain technical security risks to both technical and non‑technical audiences.
  • Ability to prioritise risks, influence remediation, and drive outcomes in a complex enterprise environment.
  • Relevant certifications such as CISSP, SABSA, CCSK, Cloud Vendor Certifications (e.g. AWS Certified Security — Specialty, AWS Certified Solution Architect, Google Professional Cloud Security Engineer) or equivalent credentials.

Responsibilities

  • Lead and coordinate application, cloud, and AI security initiatives across the Energy Division in alignment with cyber risk management objectives.
  • Conduct security architecture reviews for applications, APIs, cloud platforms, data flows, integrations, and AI-enabled solutions to identify risks and recommend secure design improvements.
  • Partner with engineering, product, architecture, cloud, and business teams to embed security requirements into solution design, development, deployment, and operations.
  • Enforce application security controls, including secure coding practices, vulnerability remediation, authentication, authorization, secrets management, dependency security, and software supply chain risk management.
  • Oversee cloud security control implementation across public cloud environments, including IAM, network security, encryption, logging, monitoring, workload protection, and secure configuration.
  • Review and assess AI/ML use cases for security risks, including data leakage, prompt injection, model exposure, access control, third‑party AI risk, and misuse scenarios.
  • Track, prioritize, and drive remediation of findings, exceptions, and risk acceptances with accountable technology owners.
  • Support cyber risk assessments, compliance reviews, audit requests, and security reporting related to Energy Division applications, cloud services, and AI-enabled platforms.
  • Develop and maintain metrics, dashboards, and executive‑level reporting to communicate security posture, risk trends, remediation progress, and key security initiatives.
  • Serve as a trusted security advisor and liaison between the Energy Division and Enterprise cybersecurity teams, promoting secure-by-design practices and consistent adoption of standards.

Skills

Application security
Cloud security
Security architecture
Technology risk management
DevSecOps
CI/CD security
Kubernetes security
Secure coding practices

Education

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field

Tools

CSPM
CWPP
CNAPP
SIEM
container scanners
identity governance tools

Job description

Responsibilities
  • Lead and coordinate application, cloud, and AI security initiatives across the S&P Global Energy Division in alignment with S&P Global's cyber risk management objectives.
  • Conduct security architecture reviews for applications, APIs, cloud platforms, data flows, integrations, and AI-enabled solutions to identify risks and recommend secure design improvements.
  • Partner with engineering, product, architecture, cloud, and business teams to embed security requirements into solution design, development, deployment, and operations.
  • Enforce application security controls, including secure coding practices, vulnerability remediation, authentication, authorization, secrets management, dependency security, and software supply chain risk management.
  • Oversee cloud security control implementation across public cloud environments, including identity and access management, network security, encryption, logging, monitoring, workload protection, and secure configuration.
  • Review and assess AI and machine learning use cases for security risks, including data leakage, prompt injection, model exposure, access control, third‑party AI risk, and misuse scenarios.
  • Track, prioritize, and drive remediation of application, cloud, and AI security findings, exceptions, and risk acceptances in partnership with accountable technology owners.
  • Support cyber risk assessments, compliance reviews, audit requests, and security reporting related to Energy Division applications, cloud services, and AI‑enabled platforms.
  • Develop and maintain metrics, dashboards, and executive‑level reporting to communicate security posture, risk trends, remediation progress, and key security initiatives.
  • Serve as a trusted security advisor and liaison between the Energy Division and Enterprise cybersecurity teams, promoting secure‑by‑design practices and consistent adoption of security standards.
Requirements
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent professional experience.
  • 5‑8+ years experience in cybersecurity, with a strong focus on application security, cloud security, security architecture, and/or technology risk management.
  • Experience conducting security architecture reviews for applications, APIs, cloud platforms, data platforms, and enterprise technology solutions.
  • Experience with DevSecOps, CI/CD security, container security, Kubernetes security, infrastructure‑as‑code scanning, secrets management, and software supply chain security.
  • Experience with cloud security tools such as CSPM, CWPP, CNAPP, SIEM, vulnerability management platforms, container scanners, and identity governance tools.
  • Familiar with AI security concepts such as prompt injection, model access control, sensitive data exposure, model monitoring, adversarial testing, AI red teaming, and third‑party AI risk.
  • Experience working with public cloud environments such as AWS, Azure, or Google Cloud Platform.
  • Experience partnering with cross‑functional stakeholders including technology, product, risk, compliance, privacy, legal, and business teams.
  • Strong written and verbal communication skills, with the ability to explain technical security risks to both technical and non‑technical audiences.
  • Ability to prioritise risks, influence remediation, and drive outcomes in a complex enterprise environment.
  • Relevant certifications such as CISSP, SABSA, CCSK, Cloud Vendor Certifications (e.g. AWS Certified Security — Specialty, AWS Certified Solution Architect, Google Professional Cloud Security Engineer) or equivalent credentials.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application & Cloud Security Lead
Application & Cloud Security Lead

S&P Global • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Health coverage
Generous leave
Continuous learning
+3
Application & Cloud Security Lead
Application & Cloud Security Lead

S&P Global • Hyderabad

On-site
INR 4,000,000 - 7,500,000
Health & Wellness
Flexible downtime
Continuous learning
+3
Application And Cloud Security Lead
Application And Cloud Security Lead

S&P Global • Gurugram District

On-site
INR 2,800,000 - 5,200,000
Health & Wellness
Flexible Downtime
Continuous Learning
+2
Security Engineering Manager
Security Engineering Manager

Smartstream • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Lead Security Engineer – DevSecOps
Lead Security Engineer – DevSecOps

Jobtailor • India

On-site
INR 4,000,000 - 6,500,000
Security Engineering Manager
Security Engineering Manager

Smartstream Limited • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Security Engineering Manager
Security Engineering Manager

SmartStream • India

On-site
INR 4,000,000 - 6,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
IT & Cloud Security Manager
IT & Cloud Security Manager

Spire Technologies And Solutions • Bengaluru

On-site
INR 3,000,000 - 5,400,000