Experience
10 - 16 yrs
Salary (CTC)
₹20L - ₹35L
Job Location
Noida, India
Vacancy
1
Designation
Cloud Security Engineer
Job Type
Not specified
Job Description
Role Summary
Executes hands-on security assessments and guardrail implementation across Customer's AWS accounts performing automated scanning, manual validation, findings documentation, and the development, testing, and phased deployment of SCPs, RCPs, AWS Config Rules, and CI/CD pipeline guardrails.
Key Responsibilities
- Run automated scans — Wiz, CIS, AWS-native tools (Security Hub, Config, Inspector)
- Review IAM policies, roles, keys, trust relationships, and federation patterns
- Assess VPCs, Security Groups, NACLs, internet exposure, and network architecture
- Review data security — S3, EBS, RDS, DynamoDB, KMS, Secrets Manager
- Evaluate compute, container, and serverless security posture
- Validate Wiz findings across Medium and Low severities with manual context
- Assess logging — CloudTrail, GuardDuty, Config, CloudWatch, VPC Flow Logs
- Develop guardrails as code — SCPs, RCPs, AWS Config Rules (managed + custom Lambda-backed), IaC policy-as-code, CI/CD pipeline gates
- Deploy and validate guardrails in sandbox / non-production accounts; capture test evidence
- Support phased production deployment, exception handling, and stabilisation
- Document findings, evidence, and guardrail deployment artefacts
- Support compliance mapping to NIST 800-53, CIS, FSBP, and SOC 2
- Assist in Technical Report, Risk Register, and Guardrail Implementation Report preparation
Required Skills
- 5–8+ years AWS cloud security and engineering experience
- Hands-on IAM, VPC, S3, EC2, Lambda, EKS, ECR, RDS, DynamoDB, KMS
- Experience with Wiz or other CSPM tools (alert triage and validation)
- AWS CLI, SDK, Python/Bash scripting for security analysis and automation
- SCP / RCP / AWS Config Rule development (managed + custom Lambda-backed)
- IaC policy-as-code implementation — Checkov, tfsec, cfn-nag, OPA
- CI/CD pipeline guardrail implementation — CodePipeline, GitHub Actions, Jenkins
- EventBridge / SSM Automation / Lambda-based detective response
- CIS Benchmark v3.0 and NIST 800-53 knowledge
- Network architecture, exposure review, and Security Group rule analysis
- Container security — EKS, ECR image scanning, Pod security standards
- Sandbox testing, drift management, and guardrail-as-code repository management
- Technical findings documentation and evidence-based reporting
- Hands-on Security Hub, GuardDuty, AWS Config (delegated admin model)
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
