| Chennai, Tamil NaduBangalore, Karnataka
Job Summary
The Senior Cloud Security & DevSecOps Engineer is responsible for embedding security into cloud native and CI/CD environments and performing structured threat modeling using STRIDE and PASTA frameworks. The role works closely with application, platform, and cloud engineering teams to ensure secure by design architectures across AWS, Azure, and GCP environments, enabling risk reduction early in the SDLC.
Key Responsibilities
**Cloud Security Engineering**
- Design and implement security controls for AWS, Azure, and/or GCP environments
- Secure cloud identity and access using least privilege IAM models
- Implement logging, monitoring, and encryption controls aligned to enterprise cloud security standards
### **DevSecOps & CI/CD Security**
- Integrate security controls into CI/CD pipelines (GitHub, GitLab, Azure DevOps, Jenkins)
- Implement container and Kubernetes security, including image scanning, runtime controls, secrets management, and RBAC
- Enable shift left security through policy as code and automated security checks
### **Threat Modeling & Secure Architecture**
- Perform threat modeling using STRIDE and/or PASTA frameworks for web, API, microservices, and cloud native architectures
- Identify trust boundaries, attack vectors, and risk scenarios early in design phases
- Translate threat models into actionable security requirements and mitigations
### **Secure SDLC & Risk Management**
- Support secure SDLC practices, including architecture reviews and design sign off
- Guide remediation of design level and implementation level security risks
- Contribute to security documentation, architecture diagrams, and compliance artifacts
### **Stakeholder Collaboration**
- Act as a security advisor to engineering, architecture, and program teams
- Support customer interactions, audits, and RFP driven security inputs when required
- Contribute to capability building, reusable security patterns, and best practices
Skill Requirements
**Technical Skills**
- Cloud Security (AWS / Azure / GCP)
- Identity & Access Management (IAM)
- DevSecOps and CI/CD Security
- Container & Kubernetes Security
- Threat Modeling (STRIDE / PASTA)
- Secure SDLC Practices
### **Tools & Technologies**
- CI/CD: GitHub Actions, GitLab CI, Azure DevOps, Jenkins
- Containers: Docker, Kubernetes
- Cloud IAM, Network Security, Encryption, Secrets Management
Other Requirements
## **Required Qualifications**
- Bachelor’s degree in Engineering, Computer Science, or related field
- 7–8 years of hands on experience in Cloud Security, Application Security, or DevSecOps roles
- Proven experience conducting threat modeling for complex systems
***
## **Preferred / Desirable Skills**
- Experience with CSPM / CWPP or cloud security tooling
- Exposure to SAST, DAST, and SCA tools
- Knowledge of security standards such as ISO 27001, NIST, or customer security baselines
- Experience working with regulated or enterprise customers
***
## **Certifications (Preferred)**
- AWS / Azure / GCP Security Certifications
- CSSLP, CKS, or equivalent security certifications
- Threat Modeling or Secure Architecture certifications
***
## **Behavioral Competencies**
- Strong analytical and risk assessment skills
- Ability to work closely with engineering teams
- Clear communication of security risks and mitigation strategies
- Customer focused and audit aware mindset
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-