HamburgerMenu
hirist

Job Description

Description:

About The Role

We are seeking a dedicated Cloud Security Engineer to fortify our cloud infrastructure and application stack against emerging threats.

This role is responsible for implementing security-as-code principles, ensuring compliance, and integrating robust security controls into our CI/CD pipelines and cloud environments (primarily on GCP or AWS).

Key Responsibilities:

- Cloud Security Architecture: Design and implement security best practices and policies across the cloud environment, focusing on identity and access management (IAM), network security, and data protection.

- Security Automation (DevSecOps): Integrate security tools and processes (SAST, DAST, SCA) into the CI/CD pipeline to automate security testing and vulnerability detection early in the development lifecycle.

- Vulnerability & Threat Management: Conduct regular security assessments, penetration testing, and vulnerability scans.

- Analyze and remediate security findings across infrastructure and application code.

- Compliance & Audit: Ensure the cloud environment adheres to industry standards and regulatory requirements (e.g., ISO 27001, SOC 2, PCI DSS).

- Incident Response: Participate in security incident response planning and execution, including forensic analysis and post-mortem reporting.

Technical Skills (Must-Have):

- Cloud Platform: Expert experience with security services on at least one major cloud provider (GCP Security Command Center, AWS Security Hub/GuardDuty/WAF).

- Identity & Access Management (IAM): Deep expertise in configuring and auditing IAM roles, policies, and federated identity models.

- Infrastructure as Code (IaC) Security: Experience securing infrastructure definitions using Terraform or CloudFormation, including policy-as-code tools (e.g., Open Policy Agent - OPA).

- Network Security: Strong understanding of cloud networking security components (VPC, Security Groups, Network ACLs, VPNs, Firewalls).

- Container Security: Experience securing Docker containers and Kubernetes clusters (e.g., RBAC, Pod Security Policies).

- Scripting: Proficiency in Python or Go for security automation tasks.

Qualifications:

- Bachelor's degree in Computer Science, Cyber Security, or a related field.

- 5+ years of experience in information security, with at least 3 years focused on cloud security.

- Relevant professional certifications (e.g., CCSP, AWS Security Specialty, GCP Professional Cloud Security Engineer) are highly desirable


info-icon

Did you find something suspicious?