A leading tech company in Bengaluru is seeking a Cloud Security Engineer with 4–6 years of experience. The role involves improving cloud security configurations, assessing risks, and developing security frameworks for CI/CD pipelines. Candidates should have hands-on experience with Azure/AWS/GCP security practices and a degree in IT or related fields. Strong communication and independent working skills are essential. The role focuses on achieving continuous cloud security enhancements and supporting cloud architecture best practices.
Qualifications
4–6 years of experience in the cloud security domain.
Hands-on experience with Azure/AWS/GCP security services.
Strong understanding of virtualization and container orchestration.
Responsibilities
Perform risk assessments on cloud architecture.
Develop frameworks for securing CI/CD pipelines.
Work with engineering teams on security configurations.
Skills
Azure/AWS/GCP security best practices
Infrastructure automation tools (Terraform)
Virtualization and Docker
Network concepts and web-related protocols
Cloud-native authentication mechanisms
Security mindset and problem-solving
Attention to detail
Communication skills
Independent work skills
Education
Degree in Information Systems/IT/Computer Science/Engineering
Associate or Professional level Cloud certification
Job description
Responsibilities
The ideal candidate is familiar with information security industry best practices, modern automation tools, and cloud environments. We are looking for someone with a security mindset who "thinks like an attacker."
Work on cloud security posture management program (CSPM) and concentrate efforts on continuous improvement of the cloud security configurations aligned to global standards like NIST CSF, ISO 27001 ISO 31000 Cloud Security Alliance, etc.
Uplift and evolve detection policies on CSPM to optimize detection capabilities and draft technical standards for remediation of vulnerabilities identified on the cloud stack.
Work on the integrated vulnerability management dashboard to bring visibility to technical debt.
Evolve and mature the security stack to support a multi-cloud strategy in a high-density containerized environment.
Ability to refer to CIS benchmarks and customize hardening standards as per the evolution of the technology stack.
Engineer and uplift adoption of the Infra as a Code program in the pre-provisioning phase and PaaC (Policy as a Code) to continuous monitoring of risk configuration changes.
Perform a risk assessment of proposed and existing cloud architecture adhering to cloud security policies, procedures, and standards, recommending technical and administrative controls to mitigate identified risks.
Design and develop frameworks and solutions to secure CI/CD pipelines.
Work in synergy with infra/product engineering teams in defining baseline security configurations, building continuous visibility for detecting misconfigurations/vulnerabilities reported by CSPM, and maturing remediation practices.
Provide SME in the analysis, assessment, development, and evaluation of security solutions and architectures to secure applications, operating systems, databases, and networks.
Work with cloud vendors and external security researchers to resolve security gaps in InMobi's Cloud.
Develop, monitor, and manage cloud performance and hygiene metrics (KCI, KPI, KRI).
Prepare and deliver training and security awareness activities to the engineering teams.
Requirements
4–6 years of experience in the cloud security domain.
Hands‑on experience with Azure/AWS/GCP security best practices and services.
Strong knowledge of virtualization, Docker, containers, and their orchestration with challenges.
Strong understanding of network concepts and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols, TLS, and DDoS detection/prevention).
Hands‑on experience with the infrastructure automation tools like Terraform.
Knowledge of common and industry‑standard cloud‑native/cloud‑friendly authentication mechanisms (OAuth, OpenID, etc.).
Experience reviewing and understanding cloud architecture and security best practices.
Ability to work independently with little direction and/or supervision.
Superior communication skills with the ability to ask questions, escape roadblocks early, and interact effectively at multiple levels in the organization.
Keen attention to detail with the ability to correct on the fly and work independently.
Curiosity to learn & adopt emerging technologies.
Knowledge of Security Operations Centre / Incident Management (good to have, not mandatory).
Holds Associate or Professional level Cloud certification(s).
Degree in Information Systems, Information Technology, Computer Science, or Engineering from an accredited college or university.