Job Description: Cloud Security Subject Matter Expert (SME)
Work Location - Thane
Role Summary
We are seeking a highly skilled Cloud Security SME to lead and strengthen security across our multi-cloud environment (AWS, Azure, OCI, GCP). The role involves designing, implementing, and governing cloud security controls aligned with industry standards, ensuring secure cloud adoption, continuous monitoring, and compliance readiness.
Key Responsibilities
Cloud Security Architecture & Governance
- Design and implement secure cloud architecture frameworks across AWS, Azure, and GCP.
- Define and enforce cloud security policies, standards, and baselines aligned with ISO 27001, NIST CSF, CIS Benchmarks, and Zero Trust principles.
- Establish secure landing zones and guardrails for multi-cloud deployments.
- Track Cloud Security Score and enhance Cloud Security Posture.
Risk Management & Compliance
- Conduct cloud risk assessments, threat modeling, and gap analysis.
- Ensure compliance with regulatory frameworks (DPDP, GDPR, ISO 27001, SOC 2).
- Support internal/external audits with evidence, controls mapping, and remediation tracking.
Identity & Access Management (IAM)
- Implement and manage identity security controls (RBAC, ABAC, least privilege, MFA).
- Integrate enterprise IAM solutions (e.g., Azure AD, Okta, AWS IAM).
- Monitor privileged access and enforce Zero Trust access models.
Cloud Security Controls Implementation
- Configure and manage:
- Cloud-native security tools (AWS Security Hub, Azure Defender, GCP Security Command Center)
- CASB / SASE solutions (e.g., Netskope, Zscaler)
- Cloud WAF, API security, network segmentation
- Implement data protection controls including encryption (at rest/in transit), DLP, tokenization.
Vulnerability & Configuration Management
- Conduct cloud vulnerability assessments & misconfiguration reviews.
- Ensure remediation of findings aligned with CIS benchmarks and cloud best practices.
Required Qualifications
- Education: B.E / B.Tech in Computer Science, IT, Cyber Security, or related field.
- Experience: Minimum 4+ years in cloud security or related domains.
Required Skills & Expertise
- Hands-on experience in multi cloud platforms (AWS, Azure, OCI, GCP).
- Strong understanding of:
- Cloud networking (VPC, NSG, routing, peering)
- Cloud IAM and identity federation
- Encryption and key management (KMS, HSM)
- Experience with:
- Cloud Security Posture Management (CSPM) tools
- Container security (Docker, Kubernetes security basics)
Pay: ₹500,000.00 - ₹700,000.00 per year
Work Location: In person