Staff Platform Security Engineer

CDK Global

Hyderabad

On-site

INR 4,000,000 - 7,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CDK Global in Hyderabad is seeking a Staff Platform Security Engineer to shape and secure our cloud and on-prem compute infrastructure. You will implement robust security solutions, participate in security reviews, and drive security posture initiatives across IaC and CI/CD pipelines.

The role emphasizes advanced Azure security, policy-as-code governance, and automated remediation, leveraging Terraform, OPA, and GitHub Actions to deliver a secure, scalable platform.

Qualifications

  • 13+ years of security engineering experience.
  • Deep knowledge of cloud security and Azure.
  • Experience with on-premises compute security patterns.

Responsibilities

  • Lead cloud security architecture and multi-year strategy.
  • Architect Zero Trust identity and network frameworks across cloud and on-prem environments.
  • Implement Policy-as-Code governance (Azure Policy, OPA) across infrastructure lifecycles.

Skills

Cloud Security
Azure

Tools

Terraform
Azure Policy
OPA/Rego
GitHub Actions
Azure DevOps

Job description

We have an excellent opportunity for Staff Platform Security Engineer. Below are details of the position:


Job Description:

Role: Staff Platform Security Engineer

Key Skills: Cloud Security, Azure

Exp: 13 to 17 Year

Location: Hyderabad

Work Mode: Work From Office


Job Description Summary

Position Summary

As a Staff Platform Security Engineer, you will play a pivotal role in shaping and securing our cloud and on-premises compute infrastructure. You will be responsible for implementing and maintaining robust security solutions for our Cloud environments. This role requires a deep understanding of security principles, cloud technologies and infrastructure as code practices. As a Platform Security Engineer, you will participate in security reviews, design and develop innovative security solutions and tools to enhance our security posture and visibility.


Responsibilities
Leadership & Technical Strategy
  • Architect the North Star: Define and establish the multi-year cloud security roadmap, aligning technical debt reduction with business velocity.
  • Strategic Influence: Partner with business stakeholders to ensure security is a core architectural pillar and a fundamental requirement in all product development.
  • CoE Leadership: Provide technical leadership to the Security Center of Excellence (CoE), aligning the Security Champions roadmap with platform engineering goals to ensure a consistent security posture across all environments.
  • Data-Driven Governance: Define high-level KPIs (e.g., MTTR, Policy Coverage, Identity Risk scores) to provide executive visibility and drive cross-functional accountability for platform risk.

Cloud Security Architecture & Engineering
  • Scalable Governance: Architect and govern multi-tenant cloud environments using standardized landing zone patterns (e.g., CAF or Control Tower). Establish global guardrails that balance developer velocity with enterprise security requirements.
  • Identity Governance: Architect a Zero Trust identity ecosystem centering on automated Conditional Access, Just-In-Time (JIT) elevation via Privileged Identity Management (PIM), and Workload Identity Federation to eliminate standing high-privileged access.
  • Zero Trust Networking: Oversee the transition to a Zero Trust network architecture. Implement deep-defense strategies including private connectivity, centralized egress/ingress control, and application-layer protection.

Policy-as-Code & IaC Governance
  • Scalable Guardrails: Transition from manual reviews to automated governance using Policy-as-Code (e.g., Azure Policy, OPA) to enforce "Security by Default" across the infrastructure lifecycle.
  • Standardized Modules: Develop and maintain a library of "Hardened" Infrastructure-as-Code (IaC) modules to provide pre-configured, compliant templates for common cloud services.
  • Drift Management: Implement automated detection and remediation systems to identify and resolve infrastructure drift across cloud subscriptions.

Automated Remediation and Orchestration
  • Autonomous Remediation: Design event-driven automation and SOAR playbooks to identify and remediate configuration drift and routine threats in real-time, enabling a "Self-Healing" infrastructure.
  • Shift-Left Architecture: Integrate automated security "gates" into CI/CD pipelines, including IaC scanning and container analysis, ensuring security feedback is delivered directly to engineers within their existing workflows.
  • Operational Efficiency: Develop custom automation and scripting to eliminate manual security tasks, focusing on reducing the "Mean Time to Remediate" (MTTR) for critical platform vulnerabilities.

Preferred Qualifications
Technical Architecture & Engineering
  • Advanced Cloud Mastery: 8+ years of experience in Infrastructure or Security Engineering, with a deep architectural focus on Azure Enterprise environments (Management Groups, ALZ, and complex networking).
  • Identity & Zero Trust Expert: Proven track record of designing and implementing Zero Trust identity frameworks, specifically leveraging Microsoft Entra ID (PIM, Conditional Access) and Workload Identity Federation at scale.
  • Systems Design: Strong ability to architect "Security-by-Design" patterns that solve for the entire lifecycle of a resource, from initial IaC commit to runtime protection.

Automation & Code Proficiency
  • Infrastructure as Code (IaC) Expert: Expert-level proficiency with Terraform (including module development and provider management) and cloud-native templates (Bicep/ARM/AWS CloudFormation).
  • Engineering Mindset: Proficiency in Python, Go, or PowerShell for building custom security tooling, automation, and API integrations. Experience with Policy-as-Code frameworks (e.g., OPA/Rego, Azure Policy) is highly preferred.
  • Pipeline Security: Hands-on experience architecting security gates and automated scanning within GitHub Actions or Azure DevOps pipelines.

Leadership & Strategic Impact
  • Strategic Influence: Experience leading large-scale technical initiatives that require cross-functional alignment across technical and non-technical stakeholders to align security goals with business priorities.
  • Mentorship & CoE: Demonstrated experience by mentoring senior engineers and providing technical steering within a Security Center of Excellence (CoE).
  • Metric-Driven Governance: Ability to define and report on technical risk through data (MTTR, posture trends) to drive organizational accountability.

Desired Qualifications
  • Industry Frameworks: Deep familiarity with the Microsoft Cloud Adoption Framework (CAF) and Well-Architected Frameworks.
  • Container Security: Extensive experience securing Kubernetes (AKS/EKS) and containerized workloads, including service mesh and admission controllers.
  • Advanced Certification: Professional-level certifications such as AZ-500, SC-100 (Cybersecurity Architect), CISSP, or CCSP.
  • Security Platform Expertise: Experience architecting enterprise-scale CNAPP, XDR, or SOAR solutions (e.g., Palo Alto/Cortex, Microsoft Sentinel).

Best Regards,

Harshad


Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Platform Security Engineer
Platform Security Engineer

CDK Global • Hyderabad

On-site
INR 300,000 - 520,000
Platform Security Engineer
Platform Security Engineer

Promaynov Advisory Services Pvt. Ltd • Bengaluru

On-site
INR 1,800,000 - 2,400,000
AZURE Platform Security AM
AZURE Platform Security AM

Freelancer • Gurugram District, Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
Senior Azure Cloud Security Engineer
Senior Azure Cloud Security Engineer

Backbase • Hyderabad

On-site
INR 2,000,000 - 3,000,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

NetConnectGlobal • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Senior Cloud Security Engineer - DevSecOps
Senior Cloud Security Engineer - DevSecOps

NetConnectGlobal • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Platform Security
Platform Security

Metaphor Infotech Mumbai • Gurugram District, Bengaluru

Hybrid
INR 1,500,000 - 3,200,000
Senior Azure Security Engineer
Senior Azure Security Engineer

YO IT Consulting • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Staff Engineer, Security Architecture
Staff Engineer, Security Architecture

Automation Anywhere • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Senior Security Engineer
Senior Security Engineer

42gears Mobility Systems • Bengaluru

On-site
INR 2,500,000 - 5,500,000