Cloud Security Engineer

Sonata Software

Bengaluru

On-site

INR 2,800,000 - 4,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sonata Software is seeking a Cloud Security Operations Engineer to design, implement, and maintain robust security controls across AWS, Azure, and GCP. You will focus on data protection, incident management, and secure IaC practices in a collaborative information security team.

The role requires hands-on expertise in cloud security with a strong emphasis on CSPM, CNAPP, DLP, and secure network design. Join a dynamic environment driving cloud resilience across platforms.

Qualifications

  • 7–10 years of experience in cloud security engineering or equivalent.
  • Hands-on experience securing AWS, Azure, and GCP environments.
  • Proficient with CSPM/CNAPP platforms and cloud security controls.

Responsibilities

  • Design, implement and maintain cloud security controls across multi‑cloud environments.
  • Lead incident response and data protection initiatives with encryption and DLP.
  • Deploy secure IaC using Terraform, CloudFormation, and ARM templates.
  • Configure IAM, MFA/SSO, and least‑privilege access models.

Skills

CIS
CCM
CSPM/CNAPP

Job description

Job Title

Cloud Security Engineer

Location

Noida/Bangalore

Experience

7 – 10 years

Mandatory Skills

CIS, CCM, CSPM/CNAPP

Job Description

We are seeking a skilled and passionate Cloud Security Operations Engineer to join our dynamic Information Security team. In this role, you will be responsible for designing, implementing, and maintaining robust security controls across our public cloud environments, including AWS, Azure, and GCP. As a hands‑on technical expert, you will play a crucial role in enhancing our cloud security posture, with a primary focus on data protection and incident management. This position offers the opportunity to work in a collaborative environment where you will contribute to the security and resilience of our cloud infrastructure.

Job Responsibilities
  • Secure Architecture and Engineering
    • Design and deploy secure reference architectures across multi‑cloud environments.
    • Integrate security into Infrastructure‑as‑Code (IaC) using tools like Terraform, CloudFormation, and ARM Templates.
    • Implement cloud‑native security controls: VPCs, WAFs, DDoS, and endpoint protections.
    • Ensure data protection via encryption, KMS/HSM, and DLP policies.
  • Identity and Access Management (IAM)
    • Design, implement, and audit IAM policies, roles, service accounts, and federation models using least‑privilege principles.
    • Configure MFA, SSO, and PAM solutions for secure cloud access.
  • Monitoring, Detection, and Response
    • Configure and maintain cloud‑native security tools (e.g., AWS Security Hub, Microsoft Defender for Cloud, Google Security Command Center).
    • Integrate cloud logs with SIEM systems for threat detection.
    • Lead incident response efforts for cloud‑related security events.
    • Continuously monitor cloud environments using CSPM, CNAPP, and cloud‑native security tools to identify, prioritize, and remediate security misconfigurations and policy violations.
    • Track and manage cloud security findings through remediation workflows.
    • Partner with Cloud Platform, Infrastructure, and Application teams to coordinate remediation of identified security risks and vulnerabilities.
    • Conduct root cause analysis of recurring cloud security issues and recommend preventive controls and automation improvements.
  • Cloud Data Loss Prevention (DLP) Management
    • DLP Alert Triage and Investigation: Monitor, triage, and investigate all DLP alerts and events. Differentiate between policy violations, potential insider threats, and false positives, escalating confirmed incidents to the Incident Response team.
    • Tool Optimization and Tuning: Serve as the subject matter expert (SME) for Cloud DLP tools (e.g., Microsoft Purview, Google DLP, dedicated CASB solutions). Continuously tune policies and rulesets to minimize alert fatigue while maintaining high fidelity.
    • Reporting and Compliance: Generate regular reports on DLP effectiveness, policy violations, and risk trends for leadership and compliance/audit teams (e.g., SOC 2, HIPAA, GDPR).
    • Data Classification Integration: Collaborate with Governance, Risk, and Compliance (GRC) teams to ensure DLP policies align with the corporate data classification framework.
  • Automation and DevSecOps
    • Develop automation scripts (Python, PowerShell, Bash) and serverless functions (AWS Lambda, Azure Functions, Google Cloud Run).
  • Cloud Security Posture Management Compliance
    • Continuously assess AWS, Azure, and GCP environments using CSPM platforms to identify misconfigurations, excessive permissions, exposed resources, compliance gaps, and other security risks.
    • Develop, maintain, and enforce cloud security baselines aligned with industry standards, regulatory requirements, and organizational security policies.
    • Perform periodic cloud security assessments and audits using CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and internal security standards.
    • Drive remediation of findings identified through CSPM monitoring, security assessments, audits, compliance reviews, and risk assessments.
    • Support internal and external audits by providing cloud security evidence, compliance reporting, and remediation status updates.
  • Secure Access and Network Security Controls
    • Enforce secure access patterns by eliminating unnecessary public exposure and implementing private endpoints, bastion hosts, AWS Systems Manager Session Manager, and least‑privilege network segmentation.
    • Enforce private connectivity architectures by leveraging:
      • AWS PrivateLink
      • Azure Private Endpoints
      • Google Private Service Connect
    • Eliminate unnecessary public exposure of cloud workloads, services, and management interfaces.
    • Design and maintain least‑privilege network segmentation and cloud‑native firewall controls across multi‑cloud environments.
  • Cloud Workload Security and Hardening
    • Establish and maintain secure cloud operating system baselines using CIS Benchmarks and vendor‑recommended hardening standards.
    • Perform periodic reviews and validation of operating system, virtual machine, and container security configurations.
    • Collaborate with Infrastructure and Platform teams to implement hardened images and golden image standards.
    • Monitor and remediate deviations from approved OS hardening baselines.
Job Qualifications
  • Deep knowledge of at least one cloud platform (AWS, Azure, or GCP).
  • Proficiency in scripting: Python (preferred), PowerShell, Unix shell scripting.
  • Strong understanding of networking and cloud‑native network security.
  • Experience with CSPM/CNAPP platforms such as CloudGuard Dome9, Wiz, Prisma Cloud, Microsoft Defender for Cloud, or similar solutions.
  • Strong knowledge of CIS Benchmarks, CSA Cloud Controls Matrix (CCM), NIST, and industry cloud security best practices.
  • Familiarity with securing OS and containerized environments (Docker, Kubernetes).
  • Experience implementing secure cloud network architectures, private endpoints, bastion access patterns, and zero‑trust security principles.
  • Experience supporting cloud compliance, audit readiness, and regulatory assessments.
  • Qualifications Required Skills: BE/BTech/Degree/Master Degree.
Equal Opportunity / EEO Statement

Sonata Software is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity, age, religion, disability, sexual orientation, veteran status, marital status, or any other characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

JUARA IT SOLUTIONS • Chennai District

On-site
INR 1,800,000 - 2,400,000
Cloud Security Engineer
Cloud Security Engineer

ERM Placement Services • Bengaluru

On-site
INR 1,500,000 - 1,900,000
Cloud Security Engineer
Cloud Security Engineer

Nex-Gen Technologies LLC • Greater Noida

On-site
INR 800,000 - 1,000,000
Competitive salary
Incentives
Annual bonuses
Cloud security engineers
Cloud security engineers

Visionet Systems Inc. • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Cloud Consultant
Cloud Consultant

Sutherland • Hyderabad

On-site
INR 3,600,000 - 6,000,000
Lead Cloud Security Engineer
Lead Cloud Security Engineer

InMobi • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Cloud Security Operations Analyst
Cloud Security Operations Analyst

Zensar Technologies • Pune District

On-site
INR 1,200,000 - 1,800,000
Interesting Job Opportunity: Security Engineer - Cloud & Infrastructure Security
Interesting Job Opportunity: Security Engineer - Cloud & Infrastructure Security

SMC • Delhi

On-site
INR 1,500,000 - 2,500,000
Cloud Security & Compliance Specialist
Cloud Security & Compliance Specialist

Tsworks • Bengaluru Urban

On-site
INR 2,500,000 - 4,000,000
Cloud Associate
Cloud Associate

Value Point Systems Pvt Ltd • Bengaluru

On-site
INR 800,000 - 1,200,000