Sr. Security Engineer
Sr. Security Engineer
We’re looking for a security-minded individual with strong cloud engineering and security experience to enhance the security posture of our cloud infrastructure and products. The ideal candidate should have hands-on experience with open-source cloud security tools, scripting and development of custom security solutions integrated with DevSecOps pipelines.
Required Skills
-
5+ years of experience working with cloud infrastructure security.
-
Strong working knowledge and demonstrated experience with Azure / AWS / GCP and a thorough understanding of cloud and network security including security hardening, cloud resources configurations, Run time protection (EDR) and Vulnerability Management
-
Experience with open-source cloud security tools like Trivy, Falco, kube-bench, Cloud Custodian.
-
Hands-on experience in developing tools / solutions on top of open-source cloud security tools to enhance cloud security posture.
-
Strong scripting experience using Python, Shell, PowerShell. for security automation, tool customization, and cloud resource monitoring.
-
Experience with deployment of security tools (DevSecOps) in CI/CD pipelines to secure containers, infrastructure (IaC) and cloud workloads.
-
Experience with cloud security tools like CSPM (Cloud Security Posture Management), CWPP (Cloud Workload Protection Platform), CNAPP (Cloud-Native Application Protection Platform).
-
Hands-on experience with infrastructure as code (IaC) tools like Terraform, CloudFormation, ARM templates, etc.
-
Strong analytical and problem-solving skills.
-
Self-starter with a proactive mindset towards cloud security improvements.
Roles & Responsibilities
-
Develop and Enhance Cloud Security Tools: Design, develop, and customize cloud security solutions to ensure a strong cloud security posture.
-
Integrate Security in DevSecOps Pipelines: Automate and integrate security tools in CI/CD pipelines to enable continuous security validation for containers, infrastructure (IaC), and cloud workloads.
-
Cloud Security Monitoring and Remediation: Continuously monitor cloud infrastructure to identify security vulnerabilities/gaps and ensure timely remediation of gaps.
-
Optimize and Fine-tune Security Tools: Enhance the efficiency of deployed security tools by fine-tuning configurations, reducing false positives, and ensuring maximum protection.
-
Collaborate and Define Security Standards: Work closely with stakeholders to implement cloud security standards, ensuring secure deployment of infrastructure and applications
Education and Experience-
-
5+ years of relevant Cloud security experience
-
Cloud Security certifications related to Azure/AWS/GCP desired or preferred
Role: Cloud Security Engineer
Industry Type: E-commerce
Department: IT & Information Security
Employment Type: Full Time, Permanent