Location: Remote – India
Job Type: Full-Time

Role Overview

We are looking for a Cloud Security Engineer to join our global infrastructure team. This role is primarily responsible for securing our AWS and Azure environments — network architecture, access control, threat monitoring, compliance, and application-level security — with secondary involvement in cloud provisioning and DevOps support to ensure security is embedded across the deployment lifecycle.

Key Responsibilities

Cloud-Level Security (Primary)
  • Design, manage, and secure VPC/VNet architecture — subnets (public/private), route tables, NAT gateways, peering, and network segmentation.
  • Configure and audit security groups, NACLs, and firewall rules to enforce least-privilege network access.
  • Manage identity and access controls (IAM roles, policies, service principals) across AWS and Azure.
  • Monitor cloud environments for security threats, misconfigurations, and anomalous activity using CloudWatch, Azure Monitor, and SIEM/security dashboards.
  • Secure cloud-based databases (Snowflake, PostgreSQL, MySQL) — encryption at rest/in transit, access management, audit logging.
  • Manage secrets, keys, and certificates (KMS, Key Vault, Secrets Manager).
  • Ensure resources follow security baselines, compliance standards (e.g., CIS benchmarks), and governance policies.
  • Conduct root cause analysis for security incidents and maintain incident response runbooks.
  • Manage backup, recovery, and disaster-resilience posture for critical workloads.
  • Maintain security documentation, network diagrams, and operational playbooks.
Application-Level Security (Primary)
  • Review application architecture for security gaps (authentication, authorization, data exposure).
  • Support secure API design — token management, rate limiting, input validation at the gateway/WAF level.
  • Configure and manage WAF rules to protect against common exploits (OWASP Top 10).
  • Support vulnerability scanning and patch management for application-layer components.
  • Collaborate with dev teams on secure coding practices and dependency/vulnerability checks in CI/CD pipelines.
Cloud Services & DevOps (Secondary)
  • Support provisioning of compute, storage, and networking resources in AWS and Azure with security-first configurations.
  • Automate secure deployments and configuration using Terraform or CloudFormation, including VPC/subnet as code.
  • Support CI/CD workflows with DevOps teams, embedding security checks (SAST/DAST, secrets scanning) into the pipeline.
  • Support scaling and capacity planning for production and staging environments.

Preferred Qualifications

  • 3+ years of hands-on experience in cloud security or cloud administration/engineering with a security focus.
  • Strong working knowledge of AWS and/or Azure security services (IAM, VPC/VNet, security groups/NACLs, WAF, monitoring, logging).
  • Experience designing or managing network architecture (subnets, routing, peering, segmentation).
  • Experience securing databases in cloud environments (Snowflake, PostgreSQL, MySQL).
  • Proficiency in Terraform/CloudFormation with attention to secure IaC practices.
  • Familiarity with application security concepts (OWASP Top 10, WAF, API security).
  • Familiarity with cloud monitoring and threat detection tools.
  • Scripting skills in Python, Bash, or PowerShell for security automation.

Soft Skills

  • Strong troubleshooting and incident-response mindset.
  • Effective communicator in remote and cross-functional teams.
  • Detail-oriented with a proactive, risk-aware approach.
  • Ability to prioritize under pressure in a fast-changing environment.