Implement and manage security controls across AWS, Azure, and/or GCP environments.
Configure cloud-native security capabilities covering IAM, network security, encryption, secrets management, logging, monitoring, and threat detection.
Implement least-privilege IAM, RBAC/ABAC, workload identity, federation, service-account governance, PAM, and Just-in-Time privileged access.
Configure and manage CNAPP, CSPM, and CWPP platforms such as Wiz, Prisma Cloud, Orca Security, Aqua Security, or equivalent.
Identify and remediate cloud security vulnerabilities, configuration issues, and security-control gaps.
Secure container and Kubernetes environments including Kubernetes, Docker, EKS, AKS, and GKE.
Develop cloud security controls and guardrails using Terraform, CloudFormation, Infrastructure-as-Code, and Policy-as-Code.
Build automated security and remediation solutions using Python, PowerShell, Bash, or similar scripting technologies.
Integrate security scanning, policies, and controls into CI/CD and DevSecOps pipelines.
Implement Zero Trust, network segmentation, private connectivity, firewall, WAF, and workload security controls.
Implement encryption, KMS, secrets management, and data-protection controls.
Perform cloud security assessments, threat modeling, configuration reviews, and technical remediation.
Integrate cloud security telemetry with SIEM/SOAR solutions such as Splunk, Microsoft Sentinel, Cortex XSOAR, or equivalent.
Collaborate with Cloud, DevOps, Platform Engineering, Application, and Security teams to deliver scalable security solutions.
8+ years of overall IT/Security experience with strong recent hands-on experience in Cloud Security Engineering.
Strong expertise in at least one major cloud platform: AWS, Azure, or GCP.
Hands-on experience implementing IAM, PAM, RBAC, workload identity, federation, and least-privilege security.
Experience with cloud-native security technologies such as:
AWS: IAM, Security Hub, GuardDuty, KMS, Secrets Manager
Azure: Microsoft Defender for Cloud, Entra ID/PIM, Azure Policy
GCP: Security Command Center, Organization Policies, Workload Identity, VPC Service Controls
Hands-on experience with Wiz, Prisma Cloud, Orca Security, Aqua Security, or comparable CNAPP/CSPM/CWPP platforms.
Strong experience with Terraform and Infrastructure-as-Code.
Experience securing Kubernetes and containerized workloads, including EKS, AKS, and/or GKE.
Experience with DevSecOps, CI/CD security, vulnerability remediation, and Policy-as-Code.
Working knowledge of Python, PowerShell, Bash, or similar scripting languages for security automation.
Strong understanding of Zero Trust, cloud network security, encryption, secrets management, threat modeling, and security architecture.
Knowledge of security frameworks and standards such as NIST, CIS Benchmarks, SOC 2, ISO 27001, and/or FedRAMP.