We are looking for a Cloud Security Engineer who can own and continuously improve the security posture of a large-scale AWS environment.
This is a hands‑on build‑and‑operate role, not an advisory position. You will work closely with DevOps, Platform Engineering, Application teams, SOC, and the CISOs office to implement preventive security controls, detect cloud threats, secure Kubernetes workloads, and automate remediation.
Your expertise is your primary qualification, not your degree or certification. Your hands‑on experience, security engineering work, write‑ups, research, and publicly known contributions reflect your interests and approach to security.
What You Will Do:
AWS Cloud Security & CSPM
- Own and continuously improve the security posture of AWS environments.
- Deploy, configure, tune, and operate CSPM solutions such as AWS Security Hub, AWS Config, Wiz, Prisma Cloud, Orca, or similar platforms.
- Monitor AWS accounts for security misconfigurations, configuration drift, and policy violations.
- Triage cloud security findings and work with application/infrastructure teams to drive remediation to closure.
- Map cloud security controls against internal security policies and regulatory requirements, including SEBI CSCRF.
Proactive Security Guardrails
- Design and implement preventive controls using:
- AWS Organizations SCPs
- AWS Config Rules
- IAM policies and Permission Boundaries
- Policy-as-Code using OPA/Rego, Sentinel, or similar technologies.
- Build controls that prevent risky configurations from reaching production.
- Develop automated remediation for common cloud security issues such as:
- Public S3 buckets
- Open Security Groups
- Unencrypted storage
- Overly permissive IAM roles
- Automate cloud security operations using Python or Bash.
Cloud Threat Detection & Response
- Operate and improve cloud threat detection capabilities.
- Coordinate with CrowdStrike/XDR teams for security coverage and policy configuration.
- Work with SOC teams to ensure relevant cloud security logs are integrated into the SIEM.
- Tune security controls and detection mechanisms based on emerging threats.
- Participate in the investigation and response to critical cloud security incidents.
Kubernetes / EKS Security
- Secure production Amazon EKS/Kubernetes environments.
- Implement Kubernetes security controls including:
- RBAC
- Network Policies
- Pod Security Standards
- Admission Controls
- Container/Image Scanning
- Image Signing
- Secrets Management
- Runtime Threat Detection
- Apply security hardening based on CIS Kubernetes Benchmarks.
- Ensure container images and workloads meet security requirements before deployment.
Infrastructure & DevSecOps Security
- Review the security of Terraform and CloudFormation infrastructure.
- Integrate security controls into CI/CD pipelines.
- Identify and remediate infrastructure misconfigurations before production deployment.
- Work with DevOps and Platform Engineering teams to implement secure‑by‑default infrastructure.
- Maintain security controls and evidence required for VAPT, audits, and regulatory reviews.
What We Are Looking For
- 3-6 years of experience in Cloud Security / DevSecOps.
- Minimum 2+ years of hands‑on AWS security experience.
- Strong hands‑on experience with at least one CSPM platform such as:Wiz, Prisma Cloud, Orca, AWS Security Hub, AWS Config, or equivalent.
- Experience implementing AWS security guardrails using SCPs, Config Rules, IAM policies, Permission Boundaries, or Policy‑as‑Code.
- Hands‑on experience with an XDR/EDR platform such as:
CrowdStrike, SentinelOne, Microsoft Defender, or Palo Alto Cortex XDR.
- Strong understanding of:
- AWS IAM
- VPC & network security
- KMS & encryption
- CloudTrail
- VPC Flow Logs
- GuardDuty
- Practical experience securing AWS EKS/Kubernetes, including RBAC, Network Policies, Pod Security, and image security.
- Strong experience with Terraform and/or CloudFormation.
- Scripting experience in Python, Bash, or similar.
- Understanding of cloud security monitoring, incident response, and vulnerability remediation.
Good to Have
- AWS Certified Security Specialty
- Certified Kubernetes Security Specialist (CKS)
- Experience working in BFSI / FinTech / regulated environments
- Experience with SEBI CSCRF or similar cybersecurity regulatory frameworks.
- Experience with large-scale AWS environments and multi‑account AWS Organizations.