Cloud Security Consultant

Payatu BV

Gurugram District, Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Payatu BV is hiring a Cloud Security Engineer to own and continually improve the security posture of a large-scale AWS environment. This hands-on build-and-operate role collaborates with DevOps, Platform Engineering, application teams, SOC, and CISOs to implement preventive controls, detect cloud threats, secure Kubernetes workloads, and automate remediation.

The role emphasizes hands-on security engineering over degrees or certifications, valuing real security work, write-ups, research, and

Qualifications

  • Hands-on Cloud Security/DevSecOps experience.
  • Experience securing AWS EKS/Kubernetes workloads.
  • Proficiency with Terraform and/or CloudFormation.
  • Scripting ability in Python or Bash.
  • Experience with CSPM platforms (AWS Security Hub, Wiz, Prisma Cloud, Orca).
  • Knowledge of IAM, VPC security, encryption, and logging (CloudTrail, VPC Flow Logs, GuardDuty).

Responsibilities

  • Own and continuously improve security posture of AWS environments.
  • Deploy and operate CSPM and guardrails, including IAM policies and Config Rules.
  • Automate remediation for common cloud security issues (S3, SGs, encryption).
  • Coordinate with DevOps/Platform Eng and SOC for threat detection and response.
  • Triage findings and drive remediation to closure and audits.

Skills

Cloud security
DevSecOps
Python
Terraform
AWS
Kubernetes
RBAC
Network security
IAM
Config rules

Tools

AWS Security Hub
AWS Config
Wiz
Prisma Cloud
Orca

Job description

We are looking for a Cloud Security Engineer who can own and continuously improve the security posture of a large-scale AWS environment.

This is a hands‑on build‑and‑operate role, not an advisory position. You will work closely with DevOps, Platform Engineering, Application teams, SOC, and the CISOs office to implement preventive security controls, detect cloud threats, secure Kubernetes workloads, and automate remediation.

Your expertise is your primary qualification, not your degree or certification. Your hands‑on experience, security engineering work, write‑ups, research, and publicly known contributions reflect your interests and approach to security.

What You Will Do:
AWS Cloud Security & CSPM
  • Own and continuously improve the security posture of AWS environments.
  • Deploy, configure, tune, and operate CSPM solutions such as AWS Security Hub, AWS Config, Wiz, Prisma Cloud, Orca, or similar platforms.
  • Monitor AWS accounts for security misconfigurations, configuration drift, and policy violations.
  • Triage cloud security findings and work with application/infrastructure teams to drive remediation to closure.
  • Map cloud security controls against internal security policies and regulatory requirements, including SEBI CSCRF.
Proactive Security Guardrails
  • Design and implement preventive controls using:
    • AWS Organizations SCPs
    • AWS Config Rules
    • IAM policies and Permission Boundaries
    • Policy-as-Code using OPA/Rego, Sentinel, or similar technologies.
  • Build controls that prevent risky configurations from reaching production.
  • Develop automated remediation for common cloud security issues such as:
    • Public S3 buckets
    • Open Security Groups
    • Unencrypted storage
    • Overly permissive IAM roles
  • Automate cloud security operations using Python or Bash.
Cloud Threat Detection & Response
  • Operate and improve cloud threat detection capabilities.
  • Coordinate with CrowdStrike/XDR teams for security coverage and policy configuration.
  • Work with SOC teams to ensure relevant cloud security logs are integrated into the SIEM.
  • Tune security controls and detection mechanisms based on emerging threats.
  • Participate in the investigation and response to critical cloud security incidents.
Kubernetes / EKS Security
  • Secure production Amazon EKS/Kubernetes environments.
  • Implement Kubernetes security controls including:
    • RBAC
    • Network Policies
    • Pod Security Standards
    • Admission Controls
    • Container/Image Scanning
    • Image Signing
    • Secrets Management
    • Runtime Threat Detection
  • Apply security hardening based on CIS Kubernetes Benchmarks.
  • Ensure container images and workloads meet security requirements before deployment.
Infrastructure & DevSecOps Security
  • Review the security of Terraform and CloudFormation infrastructure.
  • Integrate security controls into CI/CD pipelines.
  • Identify and remediate infrastructure misconfigurations before production deployment.
  • Work with DevOps and Platform Engineering teams to implement secure‑by‑default infrastructure.
  • Maintain security controls and evidence required for VAPT, audits, and regulatory reviews.
What We Are Looking For
  • 3-6 years of experience in Cloud Security / DevSecOps.
  • Minimum 2+ years of hands‑on AWS security experience.
  • Strong hands‑on experience with at least one CSPM platform such as:Wiz, Prisma Cloud, Orca, AWS Security Hub, AWS Config, or equivalent.
  • Experience implementing AWS security guardrails using SCPs, Config Rules, IAM policies, Permission Boundaries, or Policy‑as‑Code.
  • Hands‑on experience with an XDR/EDR platform such as:
    CrowdStrike, SentinelOne, Microsoft Defender, or Palo Alto Cortex XDR.
  • Strong understanding of:
    • AWS IAM
    • VPC & network security
    • KMS & encryption
    • CloudTrail
    • VPC Flow Logs
    • GuardDuty
  • Practical experience securing AWS EKS/Kubernetes, including RBAC, Network Policies, Pod Security, and image security.
  • Strong experience with Terraform and/or CloudFormation.
  • Scripting experience in Python, Bash, or similar.
  • Understanding of cloud security monitoring, incident response, and vulnerability remediation.
Good to Have
  • AWS Certified Security Specialty
  • Certified Kubernetes Security Specialist (CKS)
  • Experience working in BFSI / FinTech / regulated environments
  • Experience with SEBI CSCRF or similar cybersecurity regulatory frameworks.
  • Experience with large-scale AWS environments and multi‑account AWS Organizations.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security Architect
Cloud Security Architect

Liminal Custody • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Cloud Security Engineer
Cloud Security Engineer

Juara IT Solutions • India

Remote
INR 1,200,000 - 1,800,000
Cloud Security Engineer
Cloud Security Engineer

Happiest Minds Technologies • Bengaluru

On-site
INR 2,500,000 - 4,200,000
DevSecOps Engineer
DevSecOps Engineer

Sutherland Global • Hyderabad

On-site
INR 1,800,000 - 2,600,000
Cloud Security Engineer
Cloud Security Engineer

Portway Solutions India Private Limited • Dadri

On-site
INR 1,500,000 - 2,100,000
Cloud Security Engineer
Cloud Security Engineer

JUARA IT SOLUTIONS • Chennai District

On-site
INR 1,800,000 - 2,400,000
Cloud Security Engineering Manager
Cloud Security Engineering Manager

Weekday AI (YC W21) • Bengaluru

On-site
INR 2,500,000 - 3,500,000
Senior Information Security Engineer (DevSecOps)
Senior Information Security Engineer (DevSecOps)

WLEN WorldJobs LLP • Bengaluru

On-site
INR 2,500,000 - 5,000,000
Security Architect
Security Architect

Workmates Core2Cloud Solution Pvt Ltd • Hyderabad

On-site
INR 1,800,000 - 2,500,000
Opportunities for career advancement
Collaborative work environment
Exposure to innovative technologies
Cloud Security Engineer- Immediate Joiners
Cloud Security Engineer- Immediate Joiners

Keka Inc. • Bengaluru

Remote
INR 1,200,000 - 1,800,000