Platform Security Engineer

CDK Global

Hyderabad

On-site

INR 300,000 - 520,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CDK Global is seeking a Platform Security Engineer to shape and secure our cloud and on-premise compute infrastructure, implementing robust security solutions for cloud environments and embracing infrastructure as code practices.

The role involves leading security governance, designing Zero Trust networking, and delivering automated security gates within CI/CD pipelines, while mentoring the Security CoE and driving measurable risk reduction across platforms.

Qualifications

  • 4+ years of experience in Infrastructure or Security Engineering with a deep architectural focus on Azure Enterprise environments.
  • Proven track record designing Zero Trust identity frameworks, leveraging Microsoft Entra ID (PIM, CA) and Workload Identity Federation at scale.
  • Strong ability to architect Security-by-Design patterns spanning IaC commits to runtime protection.

Responsibilities

  • Define and evangelize a multi-year cloud security roadmap aligning debt reduction with business velocity.
  • Partner with stakeholders to ensure security as a core architectural pillar in product development.
  • Lead the Security Center of Excellence (CoE) and align roadmaps with platform engineering goals.
  • Define KPIs to provide executive visibility and drive cross-functional accountability for platform risk.

Skills

Azure
Zero Trust
Terraform
IaC
Scripting
Policy-as-Code
GitHub Actions
Container Security
Kubernetes
Cloud Security

Tools

Bicep/ARM
AWS CloudFormation
OPA/Rego
Azure Policy
GitHub Actions
Azure DevOps

Job description

Job Description -
Platform Security Engineer

As a Platform Security Engineer, you will play a pivotal role in shaping and securing our cloud and on-premises compute infrastructure. You will be responsible for implementing and maintaining robust security solutions for our Cloud environments. This role requires a deep understanding of security principles, cloud technologies and infrastructure as code practices. As a Platform Security Engineer, you will participate in security reviews, design and develop innovative security solutions and tools to enhance our security posture and visibility.

Key Responsibilities:
Leadership & Technical Strategy
  • Architect the North Star: Define and evangelize the multi-year cloud security roadmap, aligning technical debt reduction with business velocity.
  • Strategic Influence: Partner with business stakeholders to ensure security is a core architectural pillar and a fundamental requirement in all product development.
  • CoE Leadership: Provide technical leadership to the Security Center of Excellence (CoE), aligning the Security Champions roadmap with platform engineering goals to ensure a consistent security posture across all environments.
  • Data-Driven Governance: Define high-level KPIs (e.g., MTTR, Policy Coverage, Identity Risk scores) to provide executive visibility and drive cross-functional accountability for platform risk.
Cloud Security Architecture & Engineering
  • Scalable Governance: Architect and govern multi-tenant cloud environments using standardized landing zone patterns (e.g., CAF or Control Tower). Establish global guardrails that balance developer velocity with enterprise security requirements.
  • Identity Governance: Architect a Zero Trust identity ecosystem centering on automated Conditional Access, Just-In-Time (JIT) elevation via Privileged Identity Management (PIM), and Workload Identity Federation to eliminate standing high-privileged access.
  • Zero Trust Networking: Oversee the transition to a Zero Trust network architecture. Implement deep-defense strategies including private connectivity, centralized egress/ingress control, and application-layer protection.
Policy-as-Code & IaC Governance
  • Scalable Guardrails: Transition from manual reviews to automated governance using Policy-as-Code (e.g., Azure Policy, OPA) to enforce "Security by Default" across the infrastructure lifecycle.
  • Standardized Modules: Develop and maintain a library of "Hardened" Infrastructure-as-Code (IaC) modules to provide pre-configured, compliant templates for common cloud services.
  • Drift Management: Implement automated detection and remediation systems to identify and resolve infrastructure drift across cloud subscriptions.
Automated Remediation and Orchestration
  • Autonomous Remediation: Design event-driven automation and SOAR playbooks to identify and remediate configuration drift and routine threats in real-time, enabling a "Self-Healing" infrastructure.
  • Shift-Left Architecture: Integrate automated security "gates" into CI/CD pipelines, including IaC scanning and container analysis, ensuring security feedback is delivered directly to engineers within their existing workflows.
  • Operational Efficiency: Develop custom automation and scripting to eliminate manual security tasks, focusing on reducing the "Mean Time to Remediate" (MTTR) for critical platform vulnerabilities.
Required Qualifications
Technical Architecture & Engineering
  • Advanced Cloud Mastery: 4+ years of experience in Infrastructure or Security Engineering, with a deep architectural focus on Azure Enterprise environments (Management Groups, ALZ, and complex networking).
  • Identity & Zero Trust Expert: Proven track record of designing and implementing Zero Trust identity frameworks, specifically leveraging Microsoft Entra ID (PIM, Conditional Access) and Workload Identity Federation at scale.
  • Systems Design: Strong ability to architect "Security-by-Design" patterns that solve for the entire lifecycle of a resource, from initial IaC commit to runtime protection.
Automation & Code Proficiency
  • Infrastructure as Code (IaC) Expert: Expert-level proficiency with Terraform (including module development and provider management) and cloud-native templates (Bicep/ARM/AWS CloudFormation).
  • Engineering Mindset: Proficiency in Python, Go, or PowerShell for building custom security tooling, automation, and API integrations. Experience with Policy-as-Code frameworks (e.g., OPA/Rego, Azure Policy) is highly preferred.
  • Pipeline Security: Hands-on experience architecting security gates and automated scanning within GitHub Actions or Azure DevOps pipelines.
Leadership & Strategic Impact
  • Strategic Influence: Experience leading large-scale technical initiatives that require cross-functional buy-in from CTO, Engineering, and Product stakeholders.
  • Mentorship & CoE: Demonstrated experience acting as a "Force Multiplier" by mentoring senior engineers and providing technical steering within a Security Center of Excellence (CoE).
  • Metric-Driven Governance: Ability to define and report on technical risk through data (MTTR, posture trends) to drive organizational accountability.
Desired Qualifications
  • Industry Frameworks: Deep familiarity with the Microsoft Cloud Adoption Framework (CAF) and Well-Architected Frameworks.
  • Container Security: Extensive experience securing Kubernetes (AKS/EKS) and containerized workloads, including service mesh and admission controllers.
  • Advanced Certification: Professional-level certifications such as AZ-500, SC-100 (Cybersecurity Architect), CISSP, or CCSP.
  • Security Platform Expertise: Experience architecting enterprise-scale CNAPP, XDR, or SOAR solutions (e.g., Palo Alto/Cortex, Microsoft Sentinel).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Platform Security Engineer
Platform Security Engineer

Promaynov Advisory Services Pvt. Ltd • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Staff Platform Security Engineer
Staff Platform Security Engineer

CDK Global • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Senior Cloud Security Engineer - DevSecOps
Senior Cloud Security Engineer - DevSecOps

NetConnectGlobal • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Platform Security
Platform Security

Metaphor Infotech Mumbai • Gurugram District, Bengaluru

Hybrid
INR 1,500,000 - 3,200,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

NetConnectGlobal • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Senior Azure Cloud Security Engineer
Senior Azure Cloud Security Engineer

Backbase • Hyderabad

On-site
INR 2,000,000 - 3,000,000
Cloud Security Architect
Cloud Security Architect

ZainTECH • Ernakulam

On-site
INR 1,500,000 - 2,000,000
Cloud Security Architect
Cloud Security Architect

Zain Group • Ernakulam

On-site
INR 1,500,000 - 2,500,000
Lead Cloud & Application Security Architect
Lead Cloud & Application Security Architect

JRD Systems • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Lead Engineer - Cloud IND
Lead Engineer - Cloud IND

OSB India • Bengaluru

On-site
INR 1,400,000 - 2,400,000