Accepting Applications
Full-time
On-site
LinkedIn
Posted 1 month ago
2 views
0 applications
Job Description
Tips: Provide a summary of the role, what success in the position looks like, and how this role fits into the organization overall.
Responsibilities
- [
Cloud Security Architecture
Design and enforce secure cloud architecture across AWS/Azure
- Harden configurations for core services (EC2/VMs, S3/Blob, RDS, VPC/VNet, Load Balancers)
- Lead security reviews for new systems and changes
- Implement Zero Trust principles and network security controls
- Threat Detection \& Incident Response
Build and maintain monitoring, alerting, and SIEM integrations
- Detect, investigate, and respond to cloud security incidents
- Conduct threat modeling and proactive risk assessments
- Improve incident response playbooks and post‑incident reviews
- IAM \& Secrets Management
Own IAM strategy across AWS IAM / Azure AD
- Enforce least‑privilege, RBAC, and role governance
- Manage secrets, certificates, and key lifecycle (Vault, AWS Secrets Manager, Azure Key Vault)
- Compliance \& Auditing
Ensure adherence to CIS Benchmarks, OWASP, SOC 2, ISO 27001
- Conduct vulnerability assessments and configuration audits
- Produce audit‑ready documentation and posture reports
- Security in CI/CD (DevSecOps)
Integrate SAST, DAST, and dependency scanning into pipelines
- Collaborate on secure pipeline design and container security (Docker, Kubernetes)
- Contribute to IaC security reviews (Terraform)
- Collaboration
Partner with Dev, QA, DevOps, and Product teams to shift security left
- Champion secure coding standards and developer awareness
- Document security policies, controls, and architecture decisions
Qualifications
- 8–10+ years in Cloud Security, DevSecOps, or security‑focused infrastructure roles
- Hands‑on expertise with AWS/Azure security services (GuardDuty, Security Hub, Azure Defender)
- Strong IAM, secrets management, and access control knowledge
- Experience with SIEM tools, threat detection, and incident response
- Working knowledge of CI/CD pipelines and security tooling
- Familiarity with Docker/Kubernetes security (scanning, runtime protection, policies)
- Knowledge of compliance frameworks (SOC 2, ISO 27001, CIS Benchmarks, OWASP)
- Networking/security fundamentals: Zero Trust, firewalls, DNS, SSL/TLS
- Terraform security reviews; Git workflows and secure development practices