Rubiscape is deployed across a uniquelycomplex topology — public SaaS, customer BYOC (Bring Your Own Cloud), hybrid,on-premises, and fully air-gapped environments. As Cloud Security Engineer, youwill be responsible for securing this entire deployment surface: cloudinfrastructure hardening, identity and access governance in AWS/Azure/GCP,Kubernetes security, and CSPM. You Will work alongside platform infrastructureand DevSecOps teams to ensure that Rubiscape’s cloud posture meets the bar setby Fortune 500 and public sector customers who run mission-critical decisionson the platform.
Key Responsibilities
- Design and implement cloudsecurity architecture for Rubiscape’s AWS, Azure, and GCP deployments, coveringVPC design, IAM least-privilege, service control policies, and network securitygroups.
- Operate Cloud Security PostureManagement (CSPM) tooling (Wiz, Prisma Cloud, or AWS Security Hub); triagefindings, prioritise by risk, and drive remediation with infrastructure owners.
- Harden Kubernetes clusters(EKS, AKS, GKE) running Rubiscape’s studio workloads: enforce pod securitystandards, network policies, image signing, and runtime protection.
- Build and maintain automatedIaC security scanning (Checkov, tfsec) as a mandatory gate in Terraform andHelm chart pipelines.
- Design the BYOC customeronboarding security model — ensuring tenant isolation, key managementseparation, and audit log forwarding without exposing Rubiscape control-planecredentials.
- Define and validate cloudsecurity controls for ISO 27001, SOC 2, and CERT-IN cloud security guidelines;produce cloud-specific evidence packs for compliance audits.
- Respond to cloud securityincidents — containment, forensic investigation, root cause analysis, andpost-incident hardening recommendations.
Nice to Have
- Certifications: AWS SecuritySpecialty, CCSP, Google Professional Cloud Security Engineer, or CKS (CertifiedKubernetes Security Specialist).
- Experience designing securityfor BYOC or hybrid SaaS deployments where customer cloud accounts host vendorworkloads.
- Familiarity with eBPF-basedruntime security tooling (Falco, Cilium, Tetragon).
- Prior work in regulated cloudenvironments subject to CERT-IN, RBI Cloud Guidelines, or SEBI Cybersecurityframework.
About Rubiscape
Rubiscape is India’s leading DecisionIntelligence Platform, unifying data engineering, BI, machine learning, andagentic AI in a single governed platform. Built in Pune and trusted by Fortune500 enterprises across BFSI, manufacturing, healthcare, and government. 8international innovation patents. 10 Industry-Academia Labs & COEs. From BIto AI — One Platform. Every Decision.
Requirements
- 4+ years of cloud securityexperience with at least two of AWS, Azure, or GCP, including hands-on IAM,networking, and security services.
- Demonstrated expertise inKubernetes security: pod security, RBAC, network policies, secrets management(Vault/Sealed Secrets), and container image scanning.
- Proficiency with CSPM platformsand infrastructure-as-code security scanning tools.
- Experience designingmulti-tenant isolation architectures in cloud environments, includingcross-account strategies and customer-managed encryption keys (BYOK/HYOK).
- Scripting ability in Python orGo for security automation, custom policy enforcement, and cloud APIinteractions.