Posted on: 23/06/2026
Role Overview :
We are seeking a skilled Cloud Security Professional to strengthen and secure cloud-native environments through DevSecOps practices, infrastructure security, automation, and continuous monitoring.
The ideal candidate will have hands-on experience with cloud platforms, CI/CD security, Kubernetes, Infrastructure as Code (IaC), and cloud security frameworks.
This role will be responsible for implementing security controls across cloud environments, integrating security into the software development lifecycle, automating compliance processes, and proactively identifying and mitigating security risks.
Key Responsibilities :
- Design, implement, and maintain security controls across cloud environments including AWS, Azure, and GCP.
- Ensure cloud infrastructure adheres to organizational security policies, industry standards, and regulatory requirements.
- Conduct security assessments, risk analyses, and vulnerability reviews for cloud workloads and services.
- Support implementation of cloud security best practices and zero-trust principles.
- Integrate security controls into CI/CD pipelines and software delivery processes.
- Build and manage DevSecOps pipelines using tools such as:
1. GitHub Actions
2. Jenkins
3. AWS CodeDeploy
4. Similar CI/CD platforms
- Support secure deployment models including blue-green and rolling deployment strategies.
- Implement automated security testing and compliance checks within development workflows.
- Develop and maintain Infrastructure as Code (IaC) templates using Terraform for multi-cloud environments.
- Ensure security best practices are embedded into infrastructure provisioning and deployment processes.
- Perform IaC code reviews and security validations before production deployments.
- Deploy and manage cloud security tools including:
1. AWS Security Hub
2. Microsoft Defender for Cloud (Azure Security Center)
3. GCP Security Command Center
- Integrate telemetry, security events, and logs into SIEM platforms for centralized monitoring and incident detection.
- Support threat detection, incident response, and forensic investigations.
- Implement and manage application security controls including:
1. Static Application Security Testing (SAST)
2. Dynamic Application Security Testing (DAST)
3. Container Security Scanning
4. Dependency and Vulnerability Management
- Collaborate with development teams to remediate identified vulnerabilities and security risks.
- Develop automation scripts and security tooling using Python and Shell scripting.
- Automate security monitoring, compliance validation, reporting, and remediation workflows.
- Improve operational efficiency through security automation initiatives.
- Support compliance initiatives aligned with:
1. ISO 27001
2. ISO 27002
3. Cloud Security Best Practices
4. Internal Security Policies
- Participate in audits, risk assessments, and security governance activities.
- Maintain documentation for security controls, configurations, and operational procedures.
Required Skills & Experience:
- 2-7 years of experience in Cloud Security, DevSecOps, Cybersecurity Engineering, or Infrastructure Security.
- Strong hands-on experience with:
1. AWS, Azure, and/or GCP
2. Kubernetes
3. Terraform
4. CI/CD Pipelines
5. DevSecOps Practices
- Experience implementing and managing cloud security solutions.
- Hands-on experience with SAST, DAST, vulnerability management, and security monitoring tools.
- Experience integrating security telemetry with SIEM platforms.
- Strong scripting skills in Python and Shell.
- Understanding of cloud networking, identity management, and security architecture.
- Knowledge of ISO 27001, ISO 27002, and security governance frameworks.
Preferred Qualifications:
- Certifications such as:
1. CCSK
2. CCSP
3. AWS Security Specialty
4. Azure Security Engineer Associate
5. GCP Professional Cloud Security Engineer
- Experience with OpenStack, VMware, or hybrid cloud environments.
- Exposure to container security, runtime security, and cloud-native security platforms.
- Familiarity with SOC operations, threat hunting, and incident response processes.
Did you find something suspicious?
Posted by
Recruiter
HR at Contactx Resource Management
Last Active: NA as recruiter has posted this job through third party tool.
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1647443