Start Date
Immediate
Expiry Date
27 Nov, 26
Salary
0.0
Posted On
29 Aug, 26
Experience
0 year(s) or above
Remote Job
Yes
Telecommute
Yes
Sponsor Visa
Yes
Skills
Industry
Information Technology & Services
Key Responsibilities & Accountabilities:
Design, implement, and manage secure cloud architectures across AWS and Azure
environments, adhering to industry best practices, security frameworks, and enterprise
governance standards.
• Manage AWS Control Tower and Landing Zone Accelerator environments, including account
governance, Service Control Policies (SCPs), Guardrails, AWS Config Rules, and AWS
Organizations security controls.
• Design and implement Azure Landing Zones, Management Groups, Azure Policy, Azure
Blueprints, and enterprise governance frameworks.
• Implement, configure, and manage cloud-native security services, including:
◦ AWS: GuardDuty, Security Hub, Inspector, Macie, IAM Access Analyzer, AWS Config,
CloudTrail, AWS WAF, Shield, Firewall Manager, KMS, and Secrets Manager.
◦ Azure: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Firewall, Azure DDoS
Protection, Azure Key Vault, Azure Policy, Microsoft Entra ID (Azure AD), and Microsoft
Defender for Identity.
• Define and manage operational processes for cloud security monitoring, alert triage,
incident response, ticketing, and remediation through SIEM/SOAR platforms such as
Microsoft Sentinel, Elastic SIEM, and Microsoft Defender XDR, and ITSM platforms
including Jira and ServiceNow.
• Provision and manage cloud infrastructure hands-on using Infrastructure as Code (IaC) with
Terraform, AWS CloudFormation, Azure ARM Templates, or Bicep.
• Implement IaC security controls by integrating automated security scanning, policy
validation, compliance checks, and infrastructure misconfiguration detection into CI/CD
pipelines using industry-standard tools and best practices.
• Conduct cloud security incident investigations, forensic analysis, and Root Cause Analysis
(RCA), working closely with engineering teams to implement permanent corrective actions.
• Perform vulnerability management across cloud infrastructure, virtual machines,
containers, Kubernetes clusters, serverless workloads, storage services, databases, and
cloud-native applications.
• Implement cloud identity and access security using AWS IAM, IAM Identity Center,
Microsoft Entra ID, Privileged Identity Management (PIM), Role-Based Access Control
(RBAC), Conditional Access, Multi-Factor Authentication (MFA), and Zero Trust security
principles.
• Design and secure cloud networking components including VPC/VNet, Security Groups,
NSGs, NACLs, Transit Gateway, Azure Virtual WAN, Private Link, VPN, Direct Connect,
ExpressRoute, Application Load Balancers, and Network Load Balancers.
• Develop and maintain cloud security dashboards, KPIs/KRIs, operational runbooks,
architecture diagrams, compliance reports, and standard operating procedures.
Certifications (preferred)
• AWS Certified Security — Specialty
• Microsoft Certified: Azure Security Engineer Associate (AZ-500)
• Certified Cloud Security Professional (CCSP)
• GIAC Cloud Security Automation (GCSA)
• Certified Kubernetes Security Specialist (CKS) or Certified Kubernetes Administrator (CKA)
How To Apply:
Incase you would like to apply to this job directly from the source, please click here