Cloud Security Architect Azure And Multi-Cloud 5 - 10 Years Job Location Mumbai

WNS

Mumbai

On-site

INR 1,800,000 - 3,000,000

Full time

13 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

WNS, part of Capgemini, seeks an experienced Lead Analyst - Information Security in Mumbai. The role focuses on cloud security reviews, architecture assurance, CSPM, and secure cloud development practices. Strong Azure hands-on experience is required, with AWS/GCP exposure as a plus.

Required 5–10+ years in Information Security, with 4–7+ years in cloud security architecture and security reviews. Will engage with risk leadership and DevOps to embed security across the SDLC and CI/CD pipelines.

Qualifications

  • 5-10+ years in Information Security with cloud focus.
  • 4-7+ years designing and reviewing cloud security architectures.
  • Experience with Azure, AWS and/or GCP environments.

Responsibilities

  • Conduct end-to-end security reviews of cloud tech solutions across Azure, AWS, M365, SaaS, PaaS and IaaS.
  • Evaluate security controls against threat models and risk assessments.
  • Lead CSPM reviews and CIEM across cloud workloads and containers.
  • Advise leadership on security architecture and secure SDLC/CI/CD practices.
  • Perform cloud compliance assessments (GDPR, HIPAA, PCI DSS, SOC 2).
  • Track vulnerabilities and coordinate timely remediation with teams.

Skills

Cloud Security Architecture
Azure Security
AWS/GCP Experience
CNAPP/CSPM/CIEM
IAM and Access Management
DevSecOps
IaC Security
Security Risk Assessment

Tools

Prisma Cloud
Wiz
Tenable
Lacework
Microsoft/Azure Security Tools
CrowdStrike Cloud Security

Job description

Job Description:

Company Description

WNS, part of Capgemini, is an Agentic AI-powered leader in intelligent operations and transformation, serving more than 700 clients across 10 industries, including Banking and Financial Services, Healthcare, Insurance, Shipping and Logistics, and Travel and Hospitality. We bring together deep domain excellence - WNS’ core differentiator - with AI-powered platforms and analytics to help businesses innovate, scale, adapt and build resilience in a world defined by disruption.Our purpose is clear: to enable lasting business value by designing intelligent, human-led solutions that deliver sustainable outcomes and a differentiated impact. With three global headquarters across four continents, operations in 13 countries, 65 delivery centers and more than 66,000 employees, WNS combines scale, expertise and execution to create meaningful, measurable impact.

Job Description

Position: Lead Analyst - Information Security

Location: Mumbai
Experience: 5-10+ years

Role Overview

We are looking for an experienced Information Security professional with strong expertise in Cloud Security, Cloud Architecture, and IT Infrastructure. The role will focus on end-to-end cloud security solution reviews, security architecture assurance, cloud security posture management, compliance, risk assessment, and secure cloud development practices.

Strong hands-on experience with Microsoft Azure is required. Experience across AWS/GCP and exposure to AI Security will be an added advantage.

Key Responsibilities
  • Conduct end-to-end security reviews of cloud technology solutions across Azure, AWS, M365, SaaS, PaaS and IaaS, ensuring security-by-design principles.
  • Perform technical assessments of on-premises and cloud solutions to identify misconfigurations, vulnerabilities, deviations from best practices, and potential attack vectors.
  • Evaluate cloud security solutions against threat models, risk assessments, and frameworks such as NIST CSF, CSA CCM, ISO 27001 and CIS Benchmarks.
  • Provide security architecture recommendations and guidance to Risk, Information Security and Enterprise IT leadership.
  • Lead Cloud Security Posture Management (CSPM) reviews using CNAPP platforms covering CSPM, CIEM, cloud workload and container security.
  • Conduct cloud compliance assessments against standards such as GDPR, HIPAA, PCI DSS and SOC 2.
  • Review cloud security policies, procedures, hardening standards and configurations against organizational and industry best practices.
  • Partner with Enterprise IT and DevOps teams to embed security across the SDLC and CI/CD pipelines.
  • Review Infrastructure as Code (IaC) templates and automation scripts and provide recommendations for secure implementation.
  • Participate in cloud attack path analysis and recommend preventative and detective security controls.
  • Track security vulnerabilities and misconfigurations and work with relevant teams to ensure timely remediation.
  • Contribute to the continuous improvement of cloud security governance frameworks and processes.
  • Provide subject matter expertise for cloud security incident response and forensic readiness.
Required Experience
  • 5-10+ years of progressive experience in Information Security, with 4-7+ years specifically focused on Cloud Security architecture, engineering and security reviews.
  • Strong hands-on experience with cloud security services across Microsoft Azure, AWS and/or GCP.
  • Strong IT Infrastructure and Cloud Security background.
  • Experience in security assessments, penetration testing and/or vulnerability management in cloud environments.
  • Proven experience designing and reviewing secure cloud architectures for complex enterprise environments.
Qualifications
Technical Skills
  • Strong understanding of IaaS, PaaS, SaaS and the Cloud Shared Responsibility Model.
  • Cloud security frameworks: NIST CSF, CSA CCM, ISO 27001, CIS Benchmarks and OWASP Cloud Top 10.
  • Hands‑on experience with CNAPP/CSPM/CIEM/CWP solutions such as Prisma Cloud, Wiz, Tenable, Lacework, Microsoft or CrowdStrike Cloud Security.
  • Strong Cloud IAM knowledge: Azure AD/Entra ID, AWS IAM, GCP IAM, Conditional Access, MFA, SSO, PIM/PAM.
  • Cloud Network Security: VPC/VNet, network segmentation, WAF, NGFW, security groups/NSGs, VPN and Private Link.
  • Data Security and Encryption: Azure Key Vault, AWS KMS, Google Cloud KMS and related cloud‑native security services.
  • Application Security: secure coding, API security, serverless security and DevSecOps.
  • IaC Security: Terraform, CloudFormation, ARM Templates, Bicep and Policy-as-Code.
  • Container Security: Docker, Kubernetes, admission controllers and network policies.
  • Strong understanding of cloud compliance and GRC processes.
Soft Skills
  • Strong analytical and problem‑solving capabilities with excellent attention to detail.
  • Ability to communicate complex security risks and concepts to both technical and non‑technical stakeholders.
  • Excellent written and verbal communication skills.
  • Ability to work independently and collaboratively across distributed teams while managing multiple priorities.
Certifications - Preferred
Cloud Security
  • (ISC)² CCSP
  • AWS Certified Security - Specialty
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Google Professional Cloud Security Engineer
  • Certificate of Cloud Security Knowledge (CCSK)
General Security
  • (ISC)² CISSP
  • CISM

Key Focus: Cloud Security Architecture | Azure | AWS/GCP | CSPM/CNAPP | IAM | Cloud Infrastructure Security | DevSecOps | IaC Security | Compliance & Governance | Cloud Risk & Attack Path Analysis

Requirements
Get your free, confidential resume review.
or drag and drop your file here.