1. Role Summary
The AWS Cloud Security Specialist will support the CISO function by designing, implementing, operating, and governing cloud security controls across the organisation’s AWS environment. The role ensures compliance with RBI Cyber Security Framework for NBFCs, RBI IT Governance & IT Outsourcing guidelines, CERT‑In Directions, and ISO/IEC 27001:2022.
This position will work closely with Cloud Engineering, DevOps, IT Infrastructure, Security Operations, and Internal Audit to strengthen cloud security posture and ensure regulatory compliance.
2. Key Responsibilities
A. AWS Cloud Security Architecture & Governance
· Design and review secure AWS architectures as per RBI and ISO 27001 security principles.
· Define and enforce AWS security guardrails via:
o AWS Organizations
o SCPs (Service Control Policies)
o IAM best practices
o Network segmentation policies
· Maintain cloud security governance frameworks aligned with RBI’s cybersecurity expectations for NBFCs.
· Review cloud deployments (serverless, EC2, EKS, RDS, S3, API Gateway, Lambda, IAM, VPC, etc.) for security risks.
B. Regulatory Compliance (RBI, CERT-In, NBFC Guidelines)
· Implement and monitor cloud controls aligned with:
o RBI Cyber Security Framework for NBFCs
o RBI Guidelines on IT Governance, Outsourcing of IT Services, Data Localisation, Cloud Adoption
o CERT‑In Directions (logging, data retention, incident reporting within timelines)
o ISO 27001:2022 Annex A controls related to cloud technologies
· Ensure compliance with logs retention & time synchronization as per CERT‑In 2022 mandate.
· Maintain documentation and evidence for regulatory audits and inspections.
C. Cloud Security Operations
· Implement and manage AWS native security tools:
o AWS Security Hub, GuardDuty, Inspector
o AWS CloudTrail, Config, Macie
o AWS WAF & Shield
· Monitor cloud infrastructure for misconfigurations, vulnerabilities, and threats.
· Ensure encryption (KMS), key rotation, certificate management, and secrets management practices.
· Oversee identity and access management (IAM) governance and privileges reviews.
D. Cloud Risk Management
· Conduct cloud-specific risk assessments and threat modelling.
· Identify, quantify, and maintain risks in Risk Register.
· Review VPC, firewall, routing, API access, and cloud-native applications for potential exposures.
· Evaluate and approve cloud onboarding requests and change assessments.
E. Incident Response & CERT‑In Compliance
· Coordinate AWS cloud security incidents with SOC and CERT‑In.
· Ensure incident logs and evidence meet CERT‑In 6-hour reporting requirement.
· Perform forensics readiness for cloud workloads (including snapshots, log retention, event correlation).
· Conduct cloud-specific incident response drills and tabletop exercises.
F. Cloud Security Policies, Standards & Documentation
· Develop and maintain cloud security policies, SOPs, baselines aligned with:
o ISO 27001:2022
o NIST CSF (optional)
o CIS AWS Benchmarks
o RBI/NBFC guidelines
· Ensure cloud onboarding checklists, architecture review templates, and hardening guides are documented and updated.
G. Third-Party & Cloud Vendor Security
· Conduct cloud vendor security assessments for AWS-native and marketplace solutions.
· Ensure compliance with RBI Outsourcing of IT Services guidelines.
· Review SOC2/ISO27001/security posture of cloud service providers and partners.
H. ISMS Implementation for Cloud (ISO 27001:2022)
· Support migration of cloud controls into the ISMS framework.
· Conduct internal audits for cloud controls.
· Ensure compliance mapping for Annex A cloud‑relevant controls (e.g., A.5, A.8, A.12, A.14).
3. Required Skills & Competencies
Technical Skills
· Strong knowledge of AWS foundational and advanced security services.
· Experience with cloud-native security, DevSecOps pipelines, and CI/CD security.
· Understanding of:
o Zero Trust principles
o Cloud workload protection (CWPP)
o Cloud security posture management (CSPM)
· Hands-on experience with AWS CLI, IAM, VPC, KMS, CloudFormation/Terraform.
· Knowledge of log retention requirements as per CERT‑In 2022 directive.
· Familiarity with container security (ECS/EKS), API security, and serverless security.
Regulatory & Compliance Skills
· Good understanding of RBI cybersecurity circulars for NBFCs.
· Familiarity with CERT‑In incident reporting and compliance norms.
· Strong working knowledge of ISO 27001:2022 controls.
Behavioural Skills
· Strong problem-solving and analytical ability.
· Excellent documentation and presentation skills.
· Ability to work with engineering teams and senior stakeholders.
· High ownership, attention to detail, and proactive approach.
4. Qualifications
Education
· Bachelor’s degree in computer science / IT / Engineering or equivalent.
Preferred Certifications
· AWS Certified Security – Specialty
· AWS Certified Solutions Architect (Associate/Professional)
· ISO 27001 Lead Auditor / Implementer
· CISA / CISM / CCSP (preferred)
· Security+ or other cloud security certifications
5. Experience
· 4–12 years of experience in cloud security roles.
· Minimum 2+ years hands-on AWS cloud security exposure.
· Experience in a bank, NBFC, fintech, cloud-driven enterprise, or other regulated environments preferred.
Pay: ₹800,000.00 - ₹1,000,000.00 per year
Work Location: In person