Aws Cloud Engineer

PwC

Hyderabad, Bengaluru

Hybrid

INR 2,600,000 - 3,600,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PwC in Hyderabad is seeking a senior cloud security engineer to design and implement secure, multi-account AWS foundations using Infrastructure as Code. You will establish guardrails, govern multi-account structures with AWS Organizations, and enforce least-privilege access via IAM, SSO, and permission boundaries.

You will integrate CNAPP/CSPM tools, SIEM/SOAR integrations, and CI/CD security gates, automate remediation, and help ensure compliant, production-ready cloud environments across

Qualifications

  • AWS Certified Security or CISSP/CCSP with cloud security focus.
  • Experience designing secure multi-account AWS environments.
  • Proficiency with IaC tools (Terraform or CloudFormation).
  • Strong knowledge of IAM, SSO, SCPs/RCPs and policy controls.
  • Familiarity with CNAPP/CSPM/CIEM tooling and cloud compliance.

Responsibilities

  • Design and build secure, multi-account AWS foundations using IaC.
  • Govern multi-account structure with AWS Organizations and guardrails.
  • Implement least-privilege IAM and centralized SSO across accounts.
  • Automate remediation and integrate with SIEM/SOAR platforms.
  • Lead cloud security posture management and identity federation.
  • Ensure production-readiness artifacts and compliance alignment.

Skills

AWS Security
CISSP
CCSP
Cloud Governance
Policy-as-code
Multi-cloud security
IAM & SSO
CI/CD security

Tools

AWS Organizations
GuardDuty / Security Hub
KMS / Secrets Manager
OPA/Rego
SCPs/RCPs
Wiz / Prisma Cloud
EKS security posture
SIEM/SOAR (Splunk, Datadog)

Job description

Role & responsibilities
  • Design and build secure, multi-account AWS foundations using Infrastructure as Code (Terraform or CloudFormation), delivering reusable secure-by-default patterns rather than one-off configurations.
  • Stand up and govern multi-account structure with AWS Organizations, Control Tower or Landing Zone Accelerator, SCPs, and resource control policies (RCPs), enforcing guardrails through policy rather than manual review.
  • Implement least-privilege identity with IAM Identity Center, permission sets, IAM roles and policies, service-linked roles, and permission boundaries.
  • Implement centralized SSO using AWS IAM Identity Center for AWS access, including identity source integration and permission set assignment across accounts.
  • Implement workload identity federation and CI/CD OIDC (GitHub Actions OIDC) to eliminate long-lived cloud credentials in favor of short-lived, federated access.
  • Design and implement network security: VPC architecture, segmentation, security groups, NACLs, PrivateLink, Transit Gateway, and traffic controls.
  • Implement encryption defaults, key management, secrets management, and customer-managed keys where business, regulatory, or data classification requirements justify them (KMS, Secrets Manager, rotation).
  • Configure logging and detection: onboard CloudTrail, Config, and VPC Flow Logs; configure GuardDuty and Security Hub controls, aggregate findings, route alerts, and drive remediation.
  • Automate remediation using EventBridge and Lambda so common misconfigurations self-heal or open tracked tickets.
  • Own findings end to end: triage, ownership mapping, exception governance, remediation tracking, and evidence collection.
  • Integrate cloud security logs and findings with SIEM/SOAR platforms and support detection, triage, and remediation workflows.
  • Produce production-readiness artifacts: runbooks, rollback plans, monitoring, exception handling, and change management.
Preferred candidate profile
  • AWS Certified Security - Specialty, or AWS Solutions Architect (Associate or Professional). CISSP or CCSP as optional pluses.
  • CNAPP / CSPM / CIEM tooling (Wiz, Prisma Cloud, AWS Security Hub, or equivalent) with finding triage and remediation ownership.
  • Additional AWS security services: Macie, Detective, AWS Network Firewall, WAF, Shield, Route 53 Resolver DNS Firewall, and ECR image scanning.
  • Container and Kubernetes security: EKS security posture, image scanning, admission controls, workload identity, network policies, runtime visibility, and secrets management.
  • Policy-as-code: OPA/Rego, SCPs/RCPs, and CI/CD policy gates with exception workflows.
  • SIEM/SOAR integration (Splunk, Datadog, Sentinel, Chronicle, or equivalent).
  • Exposure to a second cloud (Azure or GCP) and multi-cloud security patterns.
  • Experience with AWS GovCloud and CMMC / NIST SP 800-171 delivery.
  • Understanding of different compliance requirements (HIPAA, PCI, etc.) and ability to regulate infrastructure deployment in line with those compliance requirements.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Architect (AWS & Ecosystem) | AWS Security
Senior Cloud Security Architect (AWS & Ecosystem) | AWS Security

Jero Technologies • Mumbai

On-site
INR 3,000,000 - 5,400,000
AWS Cloud Security Architect
AWS Cloud Security Architect

Shashwath Solution • Pune District

On-site
INR 1,200,000 - 1,800,000
AWS Cloud Security Architect
AWS Cloud Security Architect

Shashwath Solution • Dadri

On-site
INR 1,200,000 - 1,800,000
AWS cloud security
AWS cloud security

Wipro • Maharashtra

On-site
INR 2,400,000 - 4,200,000
Security Architect
Security Architect

Tenarai • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Aws Engineer
Aws Engineer

PwC • Hyderabad, Gurugram District, Bengaluru

Hybrid
INR 1,500,000 - 2,100,000
Cloud Security Architect
Cloud Security Architect

Liminal Custody • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Senior Cloud Security
Senior Cloud Security

Sourcebae • Mumbai

On-site
INR 4,000,000 - 6,500,000
Cloud Security Architect
Cloud Security Architect

Zain Group • Ernakulam

On-site
INR 1,500,000 - 2,500,000
Principal AWS Infrastructure & Security Architect
Principal AWS Infrastructure & Security Architect

HCLTech • Chennai District

On-site
INR 4,500,000 - 7,500,000