Requirements
- Bachelor's degree in Computer Science, Information Security, or Cybersecurity
- 6+ years in information security with cloud security focus
- 3+ years conducting cloud security assessments and architecture reviews
- Proven multi-cloud experience (AWS, Azure, GCP) in production environments
- AWS: Security Hub, GuardDuty, IAM Access Analyzer, KMS, CloudTrail
- Azure: Defender for Cloud, Sentinel, Azure Policy, Key Vault
- GCP: Security Command Center, Cloud Armor, IAM, Cloud KMS
- Tools: Prisma Cloud, Wiz, Pacu, ScoutSuite, Prowler, Terraform
- Cloud penetration testing and threat modeling
- Mandatory Certifications
- CISSP or CCSP
- AWS Security Specialty, Azure Security Engineer, OR GCP Professional Cloud Security Engineer
- CREST CRT/CCT (Cloud/Infrastructure) or equivalent
- Preferred: Kubernetes security certification (CKS/CKAD)
- Senior-level stakeholder communication and presentation skills
- Strategic cloud security roadmap development
- Cross-functional collaboration with DevOps and Platform Engineering teams
What the job involves
- Lead cloud security assessments and architecture reviews across AWS, Azure, and GCP. Validate security implementations, provide expert guidance on cloud security posture, and support enterprise cloud transformation initiatives
- Lead security architecture reviews for cloud-native and hybrid solutions
- Execute cloud security assessments across AWS, Azure, and GCP environments
- Validate designs against NIST CSF, CIS Benchmarks, and CSA CCM
- Conduct cloud penetration testing following CREST/CHECK methodologies
- Assess container/Kubernetes security, serverless and microservices implementations
- Validate IaC security controls and CI/CD pipeline security
- Lead compliance assessments: ISO 27017/27018, SOC 2, GDPR, NIS2, DORA
- Assess cloud governance frameworks and CSPM implementations
- Coordinate cloud security audits with internal/external teams
- Assess cloud IAM architectures and privileged access management
- Validate encryption, key management, and data residency controls
- Review SSO, MFA, and least privilege implementations