Cloud Security Engineer
Cloud Security Engineer
Overview
Reports To: Delivery Manger
You will play a critical role in ensuring the security and compliance of our cloud infrastructure and services. You will work closely with cross-functional teams to design, implement, and monitor security controls and best practices across cloud platforms such as AWS, Azure, and GCP. Proficiency in using Terraform for infrastructure automation is also required.
RESPONSIBILITIES
1. Design and implement secure cloud architectures, ensuring the confidentiality, integrity, and availability of systems and data.
2. Develop and maintain security policies, standards, and guidelines for cloud environments, aligning with industry best practices and compliance requirements.
3. Implement and configure security controls, including but not limited to identity and access management (IAM), network security groups, encryption mechanisms, and secure storage solutions.
4. Conduct regular security assessments and audits of cloud infrastructure, identifying vulnerabilities and recommending remediation measures.
5. Monitor cloud environments for security incidents, conducting threat analysis, and implementing incident response procedures.
6. Collaborate with development and operations teams to integrate security into the software development lifecycle (SDLC) and infrastructure deployment processes.
7. Automate security tasks and processes using tools like Terraform and scripting languages.
8. Stay up-to-date with the latest security threats, vulnerabilities, and industry trends in cloud computing and infrastructure security.
9. Provide security guidance and recommendations to cross-functional teams and stakeholders.
10. Participate in security incident response activities, including investigation, containment, and resolution.
11. Conduct security training and awareness programs for employees to promote a security-conscious culture.
12. Document security architecture, configurations, and processes for knowledge sharing and compliance purposes.
13. Collaborate with external auditors and regulatory bodies for security compliance assessments.
REQUIRED
- 2+ years of experience
- Bachelors/Master’s Degree in Computer Science, IT or similar
MUST HAVE
1. Strong experience in cloud security, with expertise in at least one major cloud platform: AWS, Azure, or GCP. Knowledge of multiple platforms is a plus.
2. Proficiency in infrastructure automation using Terraform.
3. In-depth understanding of cloud security concepts, principles, and best practices.
4. Familiarity with security frameworks and standards such as CIS benchmarks, NIST, and ISO 27001.
5. Experience implementing and configuring security controls within cloud environments.
6. Knowledge of identity and access management (IAM) concepts and technologies.
7. Solid understanding of encryption, key management, and secure storage solutions in the cloud.
8. Familiarity with cloud-native security tools and services (e.g., AWS Security Hub, Azure Security Center, GCP Security Command Center).
9. Ability to analyze security logs and identify security incidents and anomalies.
10. Excellent problem-solving and troubleshooting skills, with a keen attention to detail.
11. Ability to work collaboratively in a team environment and manage multiple priorities.
NICE TO HAVE
-
- Excellent understanding on Airline/Aviation Industry.
- Multi Cloud Experience